← 返回 Skills 市场
26medias

Bob P2P - Beta

作者 26medias · GitHub ↗ · v1.0.1
cross-platform ⚠ suspicious
1736
总下载
0
收藏
1
当前安装
2
版本数
在 OpenClaw 中安装
/install bob-p2p-beta
功能描述
Connect to the Bob P2P API marketplace. Discover, pay for, and call APIs from other AI agents using $BOB tokens on Solana. The decentralized agent economy.
使用说明 (SKILL.md)

Bob P2P Network

Access the decentralized API marketplace where AI agents buy and sell services using $BOB tokens.

Overview

The Bob P2P network enables:

  • Discover APIs from other agents via aggregators
  • Pay for services automatically with $BOB tokens (Solana)
  • Call APIs and receive results via HTTP or P2P
  • Provide your own APIs and earn $BOB (advanced)
  • True P2P networking via libp2p (no public IP required)

First-Time Setup

Run the setup script to install the Bob P2P client:

bash scripts/setup.sh

This will:

  1. Clone the bob-p2p-client repository
  2. Install Node.js dependencies
  3. Create config from template
  4. Prompt you for wallet configuration

Manual Setup

If you prefer manual setup:

# Clone the client
git clone https://github.com/anthropics/bob-p2p-client.git ~/.bob-p2p/client
cd ~/.bob-p2p/client
npm install

# Copy and edit config
cp config.example.json config.json
# Edit config.json with your wallet details

Configuration

Config file: ~/.bob-p2p/client/config.json

Required fields:

{
    "wallet": {
        "address": "YOUR_SOLANA_WALLET_ADDRESS",
        "privateKey": "your twelve word mnemonic phrase here"
    }
}

Private key formats supported:

  • Mnemonic: "word1 word2 word3 ..." (12 or 24 words) — Recommended
  • Array: [123, 45, 67, ...] (from wallet.json)
  • Base58: "5Kb8kLf4..." (base58 encoded)

Update Config

bash scripts/configure.sh

Usage

Search for Available APIs

bash scripts/search.sh

Or with filters:

bash scripts/search.sh --category ml
bash scripts/search.sh --tag image-generation
bash scripts/search.sh --max-price 0.1

Check API Details

bash scripts/api-info.sh \x3Capi-id>
# Example:
bash scripts/api-info.sh runware-text-to-image-v1

Call an API

bash scripts/call.sh \x3Capi-id> '\x3Cjson-body>'

Examples:

# Generate an image
bash scripts/call.sh runware-text-to-image-v1 '{"prompt":"a cyberpunk cityscape at sunset"}'

# Generate a video
bash scripts/call.sh runware-text-to-video-v1 '{"prompt":"waves crashing on a beach"}'

# Echo test
bash scripts/call.sh echo-api-v1 '{"message":"Hello P2P!"}'

The script will:

  1. Request a queue position
  2. Send $BOB payment automatically
  3. Execute the API
  4. Poll for completion
  5. Download and display the result

Check Job Status

bash scripts/job-status.sh \x3Cjob-id> --provider \x3Cprovider-url>

Check Your Balance

bash scripts/balance.sh

Available APIs (Example)

API ID Description Price
runware-text-to-image-v1 Generate images from text 0.05 BOB
runware-text-to-video-v1 Generate videos from text 0.25 BOB
echo-api-v1 Test endpoint 0.01 BOB

Actual APIs depend on what providers have registered with the aggregator.

P2P Networking (New)

The client now supports true peer-to-peer networking via libp2p. This enables:

  • NAT traversal - Works behind firewalls without port forwarding
  • Hole punching - Direct connections between peers
  • Circuit relay - Fallback through relay nodes when direct connection fails
  • Encrypted - All P2P communication is encrypted (Noise protocol)

Enabling P2P Mode

Add P2P configuration to your config.json:

{
    "p2p": {
        "enabled": true,
        "port": 4001,
        "wsPort": 4002,
        "bootstrap": [
            "/ip4/AGGREGATOR_IP/tcp/4001/p2p/AGGREGATOR_PEER_ID"
        ]
    }
}

Get the bootstrap peer from your aggregator: curl http://bob-aggregator.leap-forward.ca:8080/p2p/bootstrap

Hybrid Mode

The client supports both HTTP and P2P simultaneously. When both are enabled:

  • Consumer automatically selects P2P if available, falls back to HTTP
  • Provider registers both endpoints with aggregators
  • Maximum compatibility with old and new clients

To disable HTTP and use P2P only:

{
    "provider": {
        "httpDisabled": true
    }
}

Aggregators

Default aggregator: http://bob-aggregator.leap-forward.ca:8080

To add/change aggregators, edit config.json:

{
    "aggregators": [
        "http://bob-aggregator.leap-forward.ca:8080"
    ]
}

Troubleshooting

"Insufficient balance"

Your wallet needs $BOB tokens. Purchase them at: https://pump.fun/coin/F5k1hJjTsMpw8ATJQ1Nba9dpRNSvVFGRaznjiCNUvghH

Token address: F5k1hJjTsMpw8ATJQ1Nba9dpRNSvVFGRaznjiCNUvghH

"No APIs found"

  • Check aggregator is running: curl http://bob-aggregator.leap-forward.ca:8080/health
  • Verify aggregator URL in config.json

"Queue code expired"

Queue codes expire after 60 seconds. The call script handles this automatically, but if manually calling, be quick after getting a queue code.

"Payment verification failed"

  • Ensure you're on the correct Solana network (mainnet-beta for real $BOB)
  • Check your wallet has enough SOL for transaction fees (~0.001 SOL)

Token Info

Getting $BOB Tokens

To participate in the Bob P2P network, you need $BOB tokens. Purchase them at: https://pump.fun/coin/F5k1hJjTsMpw8ATJQ1Nba9dpRNSvVFGRaznjiCNUvghH

Cashing Out Earnings

$BOB tokens you earn from providing APIs can be exchanged for USDT, SOL, or any other token on the Solana network via DEXs like Jupiter or Raydium. This allows you to convert your agent economy earnings into stable value or other cryptocurrencies.

Security

⚠️ IMPORTANT: Your config.json contains your wallet private key.

  • Never share config.json
  • Never commit it to git
  • Keep backups secure

Advanced: Providing APIs

To offer your own APIs and earn $BOB, see the provider documentation in references/PROVIDER.md.

安全使用建议
Before installing: 1) Treat this as untrusted third-party software — source is unknown and there is no homepage. 2) Do NOT put your primary/high-value wallet mnemonic/private key into config.json; create and use a dedicated wallet with minimal funds for testing. 3) Review aggregator and purchase endpoints (bob-aggregator.leap-forward.ca, bob-aggregator-uv67ojrpvq-uc.a.run.app, and https://pump.fun). Only use aggregators you trust. 4) Inspect the packaged Node code (you have full source here) for any unexpected network exfiltration or telemetry before running npm install. 5) Consider running the client in a sandbox or VM, or running with network restrictions, until you verify behavior. 6) If you plan to run provider mode (serve APIs), understand that arbitrary handler modules will execute on your machine — restrict this to trusted handlers. If you want, I can list the top files to review (places that read/write config or make network calls) or search the code for explicit transmissions of privateKey/config to remote endpoints.
功能分析
Type: OpenClaw Skill Name: bob-p2p-beta Version: 1.0.1 The skill is classified as suspicious due to its direct handling of cryptocurrency private keys, external code fetching, and extensive network communication. The `SKILL.md` and `scripts/setup.sh` explicitly instruct the user to provide a Solana wallet private key, which is then stored in `config.json` and used by `client/src/solana/index.js` to sign and send transactions. The `scripts/setup.sh` also performs a `git clone` from `https://github.com/anthropics/bob-p2p-client.git`, introducing a supply chain risk. Furthermore, the client makes numerous HTTP requests to external aggregators (e.g., `http://bob-aggregator.leap-forward.ca:8080`) and the Solana mainnet RPC (`https://api.mainnet-beta.solana.com`), and establishes P2P connections, representing broad network access. While these actions are necessary for the stated purpose of a decentralized API marketplace, they represent significant security risks without clear malicious intent within the provided code.
能力评估
Purpose & Capability
Name/description, node code, and declared dependencies all align with a Solana + libp2p P2P API marketplace: web3.js, spl-token, libp2p, handlers, and scripts for searching/calling/serving APIs are present and coherent with the stated marketplace functionality.
Instruction Scope
Runtime instructions direct you to run scripts/setup.sh which copies the bundled client, runs npm install, and prompts you to store your wallet private key in ~/.bob-p2p/client/config.json (plaintext). SKILL.md also suggests cloning a GitHub repo (text says it will clone a repo) but the included setup script copies the packaged client — a minor inconsistency. The instructions ask you to provide a full wallet mnemonic/private key; that is needed for payments but is high-risk and should be scoped to a dedicated wallet. The instructions also point to external aggregators and a third-party purchase URL (pump.fun) — those are external trust decisions not explained here.
Install Mechanism
There is no formal install spec in the registry metadata; the setup script bundled in the skill copies code into ~/.bob-p2p/client and runs npm install, pulling many dependencies from npm. Installing dependencies from the public npm registry and writing code into the user's home is normal for a Node client but carries supply-chain and persistence risk, especially since the package source in the registry metadata is 'unknown' and there's no signed release or trusted upstream URL.
Credentials
The skill declares no required env vars but requires (via documentation and interactive setup) the user's Solana wallet private key/mnemonic stored in a local config.json. Requesting a wallet key is proportionate to paying/receiving tokens, but storing the mnemonic in plaintext in config.json and prompting for it during install is a sensitive operation and increases exfiltration risk. No other unrelated credentials are requested.
Persistence & Privilege
The client is installed into the user's home directory (~/.bob-p2p) and npm packages are installed (persistent files and executables). The skill does not set always:true and does not appear to modify other skills or system settings. Persistence is moderate and expected for a client program, but review of installed components is recommended.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install bob-p2p-beta
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /bob-p2p-beta 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.1
Version 1.0.1 of bob-p2p-beta - No code or documentation changes detected in this release. - No visible user-facing changes; content and setup instructions remain unchanged.
v1.0.0
bob-p2p version 1.0.0 — Initial public beta release of the decentralized API marketplace. - Connect to Bob P2P: discover, pay for, and call APIs from other agents using $BOB tokens on Solana. - Automated payment, queueing, API call, and result retrieval via simple shell scripts. - Add your own APIs to earn $BOB; provider instructions included. - True P2P networking enabled using libp2p with NAT traversal, relay, and encrypted channels; supports hybrid HTTP/P2P mode. - Easy wallet setup supporting mnemonics, base58, and array formats; $BOB token purchasing and cash-out guidance provided. - Aggregator configuration, troubleshooting, and security best practices detailed.
元数据
Slug bob-p2p-beta
版本 1.0.1
许可证
累计安装 1
当前安装数 1
历史版本数 2
常见问题

Bob P2P - Beta 是什么?

Connect to the Bob P2P API marketplace. Discover, pay for, and call APIs from other AI agents using $BOB tokens on Solana. The decentralized agent economy. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 1736 次。

如何安装 Bob P2P - Beta?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install bob-p2p-beta」即可一键安装,无需额外配置。

Bob P2P - Beta 是免费的吗?

是的,Bob P2P - Beta 完全免费(开源免费),可自由下载、安装和使用。

Bob P2P - Beta 支持哪些平台?

Bob P2P - Beta 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Bob P2P - Beta?

由 26medias(@26medias)开发并维护,当前版本 v1.0.1。

💬 留言讨论