add-tavily-tool skill
Add Tavily Search and Extract as keyless remote MCP tools for selected NanoClaw agent groups. Use when installing Tavily web search or URL extraction without an API key.
Is the add-tavily-tool skill safe?
Clean: nothing in its files matched our rules. We read 4 files in the folder on 2026-09-28.
No findings.
Install the add-tavily-tool skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/nanocoai/nanoclaw.git /tmp/nanoclaw mkdir -p ~/.claude/skills cp -r /tmp/nanoclaw/.claude/skills/add-tavily-tool ~/.claude/skills/add-tavily-tool
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Add Tavily Tool
Install the pinned mcp-remote bridge in the agent image and register Tavily's remote MCP server for each selected agent group. The MCP server supplies its tool descriptions and input schemas at runtime.
The registered server exposes:
- mcptavilytavily_search
- mcptavilytavily_extract
The registration is provider-agnostic: any provider with MCP support picks it up (Claude, OpenCode, and Codex all do). Groups on the Claude provider already have the built-in WebSearch and WebFetch tools (container/agent-runner/src/providers/claude.ts), so the skill adds the most for groups on other providers, and for Tavily's structured extraction anywhere.
Phase 1: Pre-flight
Check whether the bridge is already in the image manifest, then list the groups:
grep -n '"mcp-remote"' container/cli-tools.json || true
ncl groups listAsk which agent groups should receive Tavily. If mcp-remote is already present at a pinned version, reuse the existing entry instead of adding a second one.
Phase 2: Install the MCP bridge
Add this object to the top-level array in container/cli-tools.json when an entry named mcp-remote is not already present:
{
"name": "mcp-remote",
"version": "0.1.38"
}Keep the JSON valid and limit the entry to the two fields shown; this package does not require a native build-script opt-in.
Copy the dependency guard into the host test tree:
cp .claude/skills/add-tavily-tool/tavily-manifest.test.ts src/tavily-manifest.test.tsBuild the image and run the guard:
./container/build.sh
pnpm exec vitest run src/tavily-manifest.test.tsThe manifest is the only source-backed integration point. Per-group MCP registration is runtime state stored through ncl, so it has no in-tree line for a registration test to guard.
Phase 3: Register Tavily
config add-mcp-server and groups restart are approval-gated. Run from inside a container they return approval-pending immediately; that is not an error. Wait for the admin's approval and the follow-up system message before moving on to Phase 4.
For each selected , register one server named tavily:
ncl groups config add-mcp-server \
--id <group-id> \
--name tavily \
--command mcp-remote \
--args '["https://mcp.tavily.com/mcp/","--transport","http-only","--enable-proxy","--header","X-Tavily-Access-Mode:keyless","--header","X-Client-Name:nanoclaw","--ignore-tool","tavily_crawl","--ignore-tool","tavily_map","--ignore-tool","tavily_research"]' \
--env '{}'The keyless header enables Tavily's IP-based allowance. The client-name header attributes calls to NanoClaw. The tool filters leave only Search and Extract available.
Restart each selected group:
ncl groups restart \
--id <group-id> \
--message "Tavily Search and Extract are installed. Run one Tavily search with max_results 1 and report whether it succeeds."Phase 4: Verify
Confirm the stored configuration contains one tavily server with both headers:
ncl groups config get --id <group-id>Then check the selected agent's test response. The call must use mcptavilytavily_search. Tavily Crawl, Map, and Research must not appear in the Tavily namespace.
Phase 5: Install the upgrade path
The keyless allowance is shared by every group on the host, so it can run out. Install standing instructions so the agent offers the paid-key upgrade at that moment instead of dead-ending. For each selected group:
- Resolve the OneCLI dashboard URL the user's browser can reach:
docker inspect onecli --format '{{range .Config.Env}}{{println .}}{{end}}' | grep '^APP_URL='If the value is a loopback or container-bridge address (127.0.0.1, 172.17.0.1, host.docker.internal), ask the operator which URL they open the OneCLI dashboard at, suggesting http://127.0.0.1:10254 as the default. A public or tailnet APP_URL needs no question.
HTTP 200. If it does not (older OneCLI without the prefill route), replace step 2 of the template with: "Ask an operator to run, on the host: onecli secrets create --name tavily --type generic --host-pattern mcp.tavily.com --header-name Authorization --value-format 'Bearer {value}' --file ".
- Gate the deeplink: curl -fs /connections/custom must return
upgrade-instructions.md with the resolved URL and write the block into groups//instructions.prepend.md: replace an existing <!-- tavily-upgrade:start --> to <!-- tavily-upgrade:end --> block in place, append otherwise. Do not write into groups//CLAUDE.md; it is regenerated at spawn and appended blocks are lost.
- Substitute {{ONECLIDASHBOARDURL}} in
dialog loads with host mcp.tavily.com prefilled. If they supplied a public URL while APP_URL was a loopback address, suggest setting the public URL in the OneCLI dashboard (Settings, Instance) so future links stay stable.
- Have the operator open the composed deeplink once and confirm the create
- Restart each selected group: ncl groups restart --id .
Keyless limit
If Tavily returns HTTP 429 or monthlycapreachedbonuseligible, the keyless allowance is exhausted. With Phase 5 installed the agent offers the upgrade on its own: the user creates a free API key and stores it through the prefilled dashboard link; the key lands in the OneCLI vault and the gateway injects it into the bridge's requests. The agent then re-registers the server without the X-Tavily-Access-Mode:keyless header and restarts the group. The agent never sees the key.
Troubleshooting
restart it.
- command not found: mcp-remote: rebuild the image, then restart the group.
- Tavily tools are absent: verify the group has a tavily MCP entry, then
exhausted; see Keyless limit for the OneCLI upgrade path.
- Crawl, Map, or Research appears: restore all three --ignore-tool pairs.
- 429 or monthlycapreachedbonuseligible: the keyless allowance is
groups//instructions.prepend.md contains the tavily-upgrade block (Phase 5) and restart the group. A session that already discussed the limit keeps reasoning from that history; /clear starts a clean one.
- The agent reports exhaustion but never offers the upgrade: check that
Removal
See REMOVE.md for the idempotent removal procedure.
References
- Tavily Remote MCP
- mcp-remote
More skills from nanocoai/nanoclaw
- Aadd-anydocAdd local office-document-to-Markdown conversion to NanoClaw agent containers with the pinned Firecrawl AnyDoc CLI. Use when agents need to read attached Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, or text-based PDF files without uploading them to a hosted parser.
- Aadd-atomic-chat-toolAdd Atomic Chat MCP server so the container agent can call local models served by the Atomic Chat desktop app via its OpenAI-compatible API.
- Fadd-clidashAdd clidash — a zero-dependency, read-only web dashboard that derives its tabs and tables at runtime from any CLI that lists resources as JSON. Ships pre-wired for NanoClaw's ncl CLI (agent groups, sessions, channels, users, roles), plus message-activity charts, a log tail, and a read-only file viewer for group skills/CLAUDE.md/profiles.
- Aadd-codexUse Codex (OpenAI's codex app-server) as a full agent provider — planning, tool orchestration, MCP tools, server-side history, session resume — alongside or instead of Claude. ChatGPT subscription or OpenAI API key, vault-only via the selected gateway. Per-group via `ncl groups config update --provider codex`. Distinct from using OpenAI as an MCP tool (where Claude remains the planner).
- Aadd-dashboardAdd a monitoring dashboard to NanoClaw. Installs @nanoco/nanoclaw-dashboard and a pusher that sends periodic JSON snapshots.
- Aadd-deltachatAdd DeltaChat channel integration via @deltachat/stdio-rpc-server. Native adapter — no Chat SDK bridge. Email-based messaging with end-to-end encryption.
- Cadd-dialAdd Dial channel integration — a real phone number for SMS and AI voice calls via the Dial platform (getdial.ai). Native adapter — no Chat SDK bridge.
- Aadd-dial-numberAdd another phone number to an existing Dial channel — a second (or third) public line for the agent, so one NanoClaw install answers SMS and AI voice calls on multiple numbers. Use when Dial is already installed and the operator wants an additional number (e.g. a personal line plus a support line). Requires the Dial channel to already be installed (see /add-dial).
- Aadd-dial-toolGive chosen NanoClaw agents a real phone number as a container tool — the `dial` CLI baked into the agent image plus OneCLI credential injection for api.getdial.ai, scoped per agent, so the agents you pick can send SMS, place AI voice calls, and receive verification codes from inside the sandbox. Independent of the Dial channel; idempotent; re-run to change which agents may use it. Use when the user wants agents to text, call, or run `dial …` from a chat, without wiring Dial as a messaging channel.
- Aadd-discordAdd Discord bot channel integration via Chat SDK.
- Aadd-emacsAdd Emacs as a channel. Opens an interactive chat buffer and org-mode integration so you can talk to NanoClaw from within Emacs (Doom, Spacemacs, or vanilla). Local HTTP bridge — no bot token or external service needed.
- Aadd-gchatAdd Google Chat channel integration via Chat SDK.