Token导航 LogoToken导航TokenDH.com
开发操作浏览器clawhub未标认证来源可访问clear审计通过

httphttp 开发

Agent Skill

http 用于补充开发相关能力,适合在 OpenClaw 中需要让 Agent 承接开发相关任务时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

123,696

周安装

5,154

GitHub Stars

4

下载量

41,232
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:http(http 开发)
来源仓库:https://github.com/ivangdavila/http
安装命令:
openclaw skills install http
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install http

简介

指导正确使用 HTTP 方法、状态码、标头与缓存的开发技能。

  • 适用于 API 设计与 Web 服务开发场景。
  • 帮助构建符合规范的请求与响应流程。http 属于开发类 Skill,可作为该场景下的辅助能力补充。
  • 不涉及实际网络调用,侧重知识辅助。适用宿主包括 OpenClaw,接入前应确认版本、权限和运行环境要求。
  • 建议结合实际项目需求理解最佳实践。

SKILL.md

name
HTTP
description
Use HTTP correctly with proper methods, status codes, headers, and caching.
metadata
{"clawdbot":{"emoji":"🌐","os":["linux","darwin","win32"]}}

Redirects (Often Confused)

  • 307 vs 308: both preserve method; 307 temporary, 308 permanent—use these for POST/PUT redirects
  • 301/302 may change POST to GET (browser behavior)—don't use for API redirects with body
  • Include Location header with absolute URL—relative may fail in older clients
  • Redirect loops: limit to 5-10 follows; infinite loops crash clients

Caching Combinations

  • Cache-Control: no-store for sensitive data—never written to disk
  • no-cache still caches but revalidates every time—not "don't cache"
  • private, max-age=0, must-revalidate for user-specific, always-fresh content
  • public, max-age=31536000, immutable for versioned static assets
  • Vary: Accept-Encoding, Authorization when response depends on these headers—forgetting Vary breaks caching

Conditional Requests

  • ETag + If-None-Match: prefer for APIs—content hash based
  • Strong vs weak ETags: "abc" vs W/"abc"—weak allows semantically equivalent responses
  • If-Match for optimistic locking: fail update if resource changed since read
  • 412 Precondition Failed when If-Match fails—not 409 Conflict

CORS Preflight Triggers

  • Custom headers (anything not Accept, Accept-Language, Content-Language, Content-Type simple values)
  • Content-Type other than: application/x-www-form-urlencoded, multipart/form-data, text/plain
  • PUT, DELETE, PATCH methods—even to same origin if other conditions met
  • ReadableStream body—triggers preflight
  • Preflight cached per Access-Control-Max-Age—set to 86400 to reduce OPTIONS spam

Security Headers (Always Set)

  • Strict-Transport-Security: max-age=31536000; includeSubDomains—HSTS, once set can't easily undo
  • X-Content-Type-Options: nosniff—prevents MIME sniffing attacks
  • X-Frame-Options: DENY or SAMEORIGIN—prevents clickjacking
  • Content-Security-Policy—complex but essential; start with report-only mode

Range Requests

  • Accept-Ranges: bytes signals support—clients can request partial content
  • Range: bytes=0-1023 requests first 1024 bytes; bytes=-500 requests last 500
  • Return 206 Partial Content with Content-Range: bytes 0-1023/5000
  • 416 Range Not Satisfiable if range invalid—include Content-Range: bytes */5000

Error Response Best Practices

  • Structured JSON errors: {"error": {"code": "VALIDATION_FAILED", "message": "...", "details": [...]}}
  • Include request ID in error response—enables log correlation
  • Don't leak stack traces in production—log server-side, return generic message
  • 409 Conflict for business rule violations (duplicate email, insufficient funds)—not just 400

Retry Patterns

  • Retry only idempotent methods by default—GET, PUT, DELETE, HEAD
  • POST retry needs idempotency key—Idempotency-Key: <client-generated-uuid>
  • Exponential backoff: 1s, 2s, 4s, 8s... with jitter—prevents thundering herd
  • Respect Retry-After header—can be seconds or HTTP date
  • Set reasonable timeout (30s typical)—don't wait forever

Headers Often Forgotten

  • Vary: must include headers that affect response—CORS without Vary: Origin breaks
  • Content-Disposition: attachment; filename="report.pdf" for downloads
  • X-Request-ID: generate if not present, propagate to downstream services
  • Accept-Language for localized responses—respect with graceful fallback

Connection Behavior

  • HTTP/1.1 without Content-Length or chunked = connection close after response
  • Transfer-Encoding: chunked for streaming—can't set Content-Length
  • HTTP/2 is binary, multiplexed—no head-of-line blocking at HTTP level
  • WebSocket upgrade: GET with Connection: Upgrade, Upgrade: websocket

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

73.78%
按下载量换算30,421

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

未展示

权限和风险

操作浏览器

该 Skill 可能涉及浏览器控制能力,使用时可能读取或操作网页内容,需要在受控环境中确认权限边界。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills