A diagnostic tool for testing if HTTP endpoints correctly enforce rate limiting and provide standard throttling headers.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install rate-limit-validator
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install rate-limit-validator using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Rate Limit Validator is a specialized utility designed to verify the effectiveness of rate-limiting configurations on any HTTP endpoint. Unlike tools that implement throttling, this skill within the Openclaw Skills ecosystem acts as a validator to ensure your API gateways, middleware, or web servers are correctly defending against burst traffic. It provides developers with the peace of mind that their infrastructure will behave as expected under load by simulating high-frequency requests.
By analyzing response patterns and specific HTTP headers, the Rate Limit Validator identifies whether a system is truly resilient or if it lacks necessary protections. This is a critical step in a professional development workflow, ensuring that your services adhere to specific security policies and threat model mitigations.
To use this tool within the Openclaw Skills framework, ensure you have the necessary dependencies installed on your local machine.
# Ensure curl is available
sudo apt-get install curl
# Run the validator script with your target URL
./rate-limit-validator.sh http://your-api-endpoint.com 50
The skill utilizes a temporary file structure to process request results before generating a summary. The data organization follows this structure:
| Attribute | Description |
|---|---|
| Target | The HTTP/HTTPS endpoint being tested |
| Total Requests | The number of attempts made during the burst test |
| HTTP 429 Count | Number of requests successfully throttled by the server |
| Header Presence | Boolean flags for Retry-After and X-RateLimit headers |
| Final Result | A pass/fail assessment of rate-limiting status |
Loading
A security auditing tool designed to detect exposed credentials, improper file permissions, and git contamination within AI agent environments.

Register sovereign domains like .badass and .forever as ERC-721 NFTs on Ethereum mainnet using Impervious Domains contracts.

An automated workflow to scrape Facebook posts, rewrite them with AI, generate custom visuals, and publish to Facebook Pages.

A bridge utility that converts Markdown files into fully editable Google Docs by automating the DOCX conversion and Drive upload workflow.

A lightweight, bidirectional LAN file sharing solution that allows AI agents and users to exchange files over a local network without internet access.

A temporary email management utility for automating signup flows and message polling through the Vortex API.








































