Latest
v0.1.0
Permissions
network: any public host (private, loopback and link-local addresses are blocked)
SHA-256
sha256-dc32fb14596c444ce7352bb60ee69cad82b9296514ad0321740959adf65b6c57
Verification
passed (sha256, size, package, metadata, provenance, source)
Install
splice add @splice/http --accept-permissions

@splice/http

HTTP client for agents: GET and POST to public http(s) URLs with a timeout, a response size limit and structured results.

Permissions: network: ["*"] — any public host. Installing needs --accept-permissions. The Splice sandbox refuses every non-public target, whatever URL the tool is given:

  • loopback and localhost (127.0.0.0/8, ::1, *.localhost),
  • private networks (10/8, 172.16/12, 192.168/16, fc00::/7), CGNAT (100.64/10),
  • link-local incl. cloud metadata (169.254.0.0/16, e.g. 169.254.169.254, fe80::/10),
  • multicast, reserved, documentation and IPv4-mapped/NAT64/6to4 ranges,
  • host names that resolve to any of the above, and
  • redirects to any of the above (every redirect hop is checked again).

No file system access and no environment variables: the tool cannot read or send local secrets.

When should an agent use this skill?

  • Fetch a public JSON API or web page (http.get).
  • Submit data to a public API that needs no credentials (http.post).

Not for authenticated APIs: Authorization and Cookie headers cannot be sent (by design).

Tools

http.get

InputTypeRequiredNotes
urlstringyesabsolute http(s) URL, max 2048 chars, no user:pass@
headersobjectnoonly accept, accept-language, if-none-match, if-modified-since, user-agent
timeoutMsinteger 100–15000nodefault 10000, for the complete response
maxBytesinteger 1–524288nodefault 262144; larger responses fail
responseTypeauto | json | textnodefault auto

http.post

Same as get, plus exactly one body: json (any value, sent as application/json) or text (string, max 1,000,000 chars) with optional contentType.

Output (both)

{
  "url": "https://…final URL…", "status": 200, "statusText": "OK", "ok": true, "redirected": false,
  "headers": { "content-type": "application/json", "etag": "…" },
  "bodyType": "json", "json": { … }, "bytes": 1234
}
  • bodyType: json (parsed into json), text (text), base64 (non-text content, base64) or empty.
  • Returned headers are limited to content-type, content-length, etag, last-modified, cache-control, date, location, retry-after. Set-Cookie is never returned.
  • HTTP error statuses (4xx/5xx) are results with ok: false, not failures.

Errors

Message prefixMeaning
INVALID_URL:not an absolute http(s) URL, or contains credentials
TIMEOUT:no complete response within timeoutMs
RESPONSE_TOO_LARGE:body larger than maxBytes
NETWORK_ERROR:DNS failure, connection refused, TLS error, too many redirects
INVALID_JSON_RESPONSE:responseType: "json" but the body is not JSON
INVALID_INPUT:both json and text given
runtime PERMISSION_DENIEDthe target is not a public address (see above)

Examples

splice run http.get url=https://api.github.com/repos/spliceloom/splice-artifacts
splice run http.post --input '{"url":"https://httpbin.org/post","json":{"hello":"splice"}}'

See examples/. Compose with @splice/json (json.pick) to keep only the fields you need.

Limitations

The private-address check resolves DNS before connecting; the connection itself resolves again, so a hostile DNS server answering differently within milliseconds (DNS rebinding) is not fully prevented. The network guard runs inside the tool process (Node.js has no network permission flag); see the Splice permissions documentation.