Skip to content

fix: ClawHub skill install — use /download ZIP endpoint - #1060

Merged
teknium1 merged 1 commit into
mainfrom
hermes/hermes-4b9773d6
Mar 12, 2026
Merged

teknium1 merged 1 commit into
mainfrom
hermes/hermes-4b9773d6

Conversation

@teknium1

Copy link
Copy Markdown
Collaborator

Problem

hermes skills install steipete/nano-banana-pro (and all other ClawHub skills) fails with:

ClawHub fetch for nano-banana-pro resolved version 1.0.1 but no inline/raw file content was available
Error: Could not fetch 'steipete/nano-banana-pro' from any source.

Root Cause

The ClawHub API v1 version endpoint (/api/v1/skills/{slug}/versions/{version}) only returns file metadata (path, size, sha256, contentType) — it never includes inline content or download URLs. Our _extract_files() method was looking for content or rawUrl fields that don't exist in the response.

Additionally, _extract_files() was looking at version_data.get('files') but the API nests files under version_data['version']['files'].

Fix

Use the /api/v1/download?slug=X&version=Y endpoint (same as the official npx clawhub CLI) to download skills as ZIP bundles and extract files in-memory.

Changes:

  • New _download_zip() method — downloads ZIP from /api/v1/download, extracts text files in-memory
    • Retry on 429 rate limiting with Retry-After header support (download endpoint has stricter 20 req/min limit)
    • Path sanitization (.. traversal prevention) and binary file filtering (500KB cap)
  • Fallback preserved — if ZIP download fails, still tries the version metadata endpoint for inline/raw content
  • Fixed nested lookup — also checks version_data['version']['files'] in the fallback path

Testing

  • Verified hermes skills install steipete/nano-banana-pro now succeeds (downloads ZIP, extracts SKILL.md + scripts)
  • All 48 skills_hub tests pass
  • Full test suite: 3135 passed, 4 pre-existing failures (unrelated)

The ClawHub API v1 version endpoint only returns file metadata
(path, size, sha256, contentType) without inline content or download
URLs. Our code was looking for inline content in the metadata, which
never existed, causing all ClawHub installs to fail with:
'no inline/raw file content was available'

Fix: Use the /api/v1/download endpoint (same as the official clawhub
CLI) to download skills as ZIP bundles and extract files in-memory.

Changes:
- Add _download_zip() method that downloads and extracts ZIP bundles
- Retry on 429 rate limiting with Retry-After header support
- Path sanitization and binary file filtering for security
- Keep _extract_files() as a fallback for inline/raw content
- Also fix nested file lookup (version_data.version.files)
@teknium1
teknium1 merged commit 5c54128 into main Mar 12, 2026
1 check passed
angelburgosrosado pushed a commit to angelburgosrosado/hermes-agent that referenced this pull request Apr 27, 2026
…#1060)

The ClawHub API v1 version endpoint only returns file metadata
(path, size, sha256, contentType) without inline content or download
URLs. Our code was looking for inline content in the metadata, which
never existed, causing all ClawHub installs to fail with:
'no inline/raw file content was available'

Fix: Use the /api/v1/download endpoint (same as the official clawhub
CLI) to download skills as ZIP bundles and extract files in-memory.

Changes:
- Add _download_zip() method that downloads and extracts ZIP bundles
- Retry on 429 rate limiting with Retry-After header support
- Path sanitization and binary file filtering for security
- Keep _extract_files() as a fallback for inline/raw content
- Also fix nested file lookup (version_data.version.files)
02356abc pushed a commit to 02356abc/hermes-agent that referenced this pull request May 14, 2026
…#1060)

The ClawHub API v1 version endpoint only returns file metadata
(path, size, sha256, contentType) without inline content or download
URLs. Our code was looking for inline content in the metadata, which
never existed, causing all ClawHub installs to fail with:
'no inline/raw file content was available'

Fix: Use the /api/v1/download endpoint (same as the official clawhub
CLI) to download skills as ZIP bundles and extract files in-memory.

Changes:
- Add _download_zip() method that downloads and extracts ZIP bundles
- Retry on 429 rate limiting with Retry-After header support
- Path sanitization and binary file filtering for security
- Keep _extract_files() as a fallback for inline/raw content
- Also fix nested file lookup (version_data.version.files)
waefrebeorn pushed a commit to waefrebeorn/slermes that referenced this pull request Jul 2, 2026
…#1060)

The ClawHub API v1 version endpoint only returns file metadata
(path, size, sha256, contentType) without inline content or download
URLs. Our code was looking for inline content in the metadata, which
never existed, causing all ClawHub installs to fail with:
'no inline/raw file content was available'

Fix: Use the /api/v1/download endpoint (same as the official clawhub
CLI) to download skills as ZIP bundles and extract files in-memory.

Changes:
- Add _download_zip() method that downloads and extracts ZIP bundles
- Retry on 429 rate limiting with Retry-After header support
- Path sanitization and binary file filtering for security
- Keep _extract_files() as a fallback for inline/raw content
- Also fix nested file lookup (version_data.version.files)
melon-xf added a commit to melon-xf/hermes-agent that referenced this pull request Sep 3, 2026
…#1060)

The ClawHub API v1 version endpoint only returns file metadata
(path, size, sha256, contentType) without inline content or download
URLs. Our code was looking for inline content in the metadata, which
never existed, causing all ClawHub installs to fail with:
'no inline/raw file content was available'

Fix: Use the /api/v1/download endpoint (same as the official clawhub
CLI) to download skills as ZIP bundles and extract files in-memory.

Changes:
- Add _download_zip() method that downloads and extracts ZIP bundles
- Retry on 429 rate limiting with Retry-After header support
- Path sanitization and binary file filtering for security
- Keep _extract_files() as a fallback for inline/raw content
- Also fix nested file lookup (version_data.version.files)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant