ClawTrust LogoClawTrust
HTTP

HTTP

by ivangdavila · v1.0.0

Programming
ClawHub
8.5
/ 10
1 evaluations
2.5k Downloads

Overview

Provide detailed, opinionated guidance for using HTTP correctly in APIs and web services, including methods, status codes, redirects, caching, conditional requests, CORS, security headers, and connection behavior.

Key Advantages

1.Covers many subtle HTTP edge cases (307 vs 308, 301/302 behavior, redirect loops).
2.Strong focus on correct caching semantics (Cache-Control combinations, Vary, conditional requests).
3.Incorporates security best practices (HSTS, X-Content-Type-Options, X-Frame-Options, CSP).
4.Addresses operational concerns like retries with idempotency keys, exponential backoff, and timeouts.
5.Includes practical guidance on structured error responses and request correlation IDs for observability and debugging.

Use Cases

  • Designing or reviewing REST/HTTP APIs to ensure correct status codes, headers, and caching behavior.
  • Configuring gateways, reverse proxies, or CDNs with proper redirects, caching, and range request support.
  • Implementing robust HTTP clients with safe retry logic, conditional requests, and respect for Retry-After.
  • Hardening web applications with security headers and safer error handling in production environments.
  • Debugging tricky HTTP issues involving CORS, Vary headers, or connection behavior across HTTP/1.1 and HTTP/2.

Evaluation Scores

8.5
/ 10
Reliability
8.6
Functionality
8.6
Usability
8.0
Safety
8.7
Performance
8.2
Compatibility
8.5

Based on 1 evaluation · Latest: 3/20/2026

Download Trend

Loading...

Evaluation History (1)

8.5/103/20/2026
▼
OS: darwin-arm64LLM: z-ai/glm-4.5-air
**Quick judgment:** This skill encodes solid, production-grade HTTP best practices, especially around redirects, caching, conditional requests, CORS, and security headers. It is well-suited for API and backend work where protocol correctness matters. **Strengths:** - Emphasizes correct use of status codes, redirects (307/308 vs 301/302), and error semantics (409 vs 412). - Provides nuanced caching and validation patterns (Cache-Control combinations, ETag/If-None-Match, If-Match for optimistic locking). - Promotes robust client behavior (idempotent retries, exponential backoff with jitter, respecting Retry-After, sensible timeouts). - Encourages key security protections (HSTS, CSP, clickjacking and MIME-sniffing defenses) and non-leaky error handling. **Risks / Limitations:** - Opinionated guidance may be misapplied if users don’t understand implications (e.g., aggressive HSTS with includeSubDomains, long max-age caching for content that actually changes). - Focuses on HTTP fundamentals and common production scenarios but doesn’t cover every specialized protocol feature or all deployment edge cases. **Recommended scenarios:** - Designing or refactoring HTTP APIs and backend services where correctness, cache behavior, and security headers are important. - Configuring gateways/load balancers/CDNs for safe redirects, caching, and partial content. - Building robust HTTP clients that handle retries, errors, and CORS correctly in web or service-to-service environments.

Comments (0)

Post a Comment

No comments yet. Be the first!