Kubeshark KFL2 Filter Reference
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
Mask a URL behind a custom domain for demos and recordings. An agent skill from adobe/skills.
$ npx skills add adobe/skills --skill domain-mask -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install adobe/skills domain-mask --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/web/skills/domain-mask .claude/skills/domain-mask && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "domain-mask" agent skill from https://github.com/adobe/skills/tree/main/plugins/web/skills/domain-mask into .claude/skills/domain-mask/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domain-mask", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/adobe/skills/tree/main/plugins/web/skills/domain-maskType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add adobe/skills --skill domain-mask -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install adobe/skills domain-mask --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/web/skills/domain-mask .agents/skills/domain-mask && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "domain-mask" agent skill from https://github.com/adobe/skills/tree/main/plugins/web/skills/domain-mask into .agents/skills/domain-mask/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domain-mask", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add adobe/skills --skill domain-mask -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install adobe/skills domain-mask --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/web/skills/domain-mask .cursor/skills/domain-mask && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "domain-mask" agent skill from https://github.com/adobe/skills/tree/main/plugins/web/skills/domain-mask into .cursor/skills/domain-mask/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domain-mask", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/adobe/skills.git --path plugins/web/skills/domain-mask--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add adobe/skills --skill domain-mask -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install adobe/skills domain-mask --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/web/skills/domain-mask .gemini/skills/domain-mask && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "domain-mask" agent skill from https://github.com/adobe/skills/tree/main/plugins/web/skills/domain-mask into .gemini/skills/domain-mask/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domain-mask", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install adobe/skills domain-maskInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add adobe/skills --skill domain-mask -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/web/skills/domain-mask .github/skills/domain-mask && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "domain-mask" agent skill from https://github.com/adobe/skills/tree/main/plugins/web/skills/domain-mask into .github/skills/domain-mask/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domain-mask", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add adobe/skills --skill domain-mask -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install adobe/skills domain-mask --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/web/skills/domain-mask .opencode/skills/domain-mask && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "domain-mask" agent skill from https://github.com/adobe/skills/tree/main/plugins/web/skills/domain-mask into .opencode/skills/domain-mask/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "domain-mask", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
domain-maskMask a URL behind a custom domain for demos and recordings. An agent skill from adobe/skills.
Domain Mask is an agent skill from adobe/skills. Mask a URL behind a custom domain for demos and recordings. Adds a trusted HTTPS reverse proxy so the browser shows a clean display domain with a green padlock while serving content from the real target URL. Handles /etc/hosts, mkcert certificates, and cleanup automatically. Triggers on: "domain mask", "mask domain", "mock domain", "proxy URL", "demo URL", "fake domain", "demo proxy", "mask URL for demo", "domain-mask".
Its SKILL.md is about 740 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `.releaserc.json`, `evals/evals.json` and `package.json`). Compatibility notes: macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification).
It sits in DevOps & Cloud, covering Cloud networking. The repository describes itself as: Adobe Skills for Agents. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 985c436. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
brewnodeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
main--mysite--org.aem.pagegabrielwalt.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification).
From compatibility in the SKILL.md frontmatter.
Domain Mask loads about 739 tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 260 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ibility: macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification).- sudo access (for port 443 and /etc/hosts)sudo node "$DOMAIN_MASK" <display-domain> <target-url>sudo sed -i '' '/<display-domain>/d' /etc/hosts- Requires sudo (privileged port 443 + hosts file)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from adobe/skills at commit 985c436, republished under its Apache-2.0 licence (© adobe). 260 words, ~739 tokens.
.claude/skills/domain-mask/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Mask a URL behind a custom domain for demos and recordings. Opens an
HTTPS reverse proxy so the browser address bar shows a clean domain
(e.g., wknd.adventures) while content is served from the real URL
(e.g., https://main--mysite--org.aem.page). Trusted certificate via
mkcert — no browser warnings.
brew install mkcert && mkcert -install)if [[ -n "${CLAUDE_SKILL_DIR:-}" ]]; then
DOMAIN_MASK="${CLAUDE_SKILL_DIR}/scripts/domain-mask.mjs"
else
DOMAIN_MASK="$(find ~/.claude -path "*/domain-mask/scripts/domain-mask.mjs" \
-type f 2>/dev/null | head -1)"
fi
if [[ -z "$DOMAIN_MASK" || ! -f "$DOMAIN_MASK" ]]; then
echo "Error: domain-mask.mjs not found." >&2
fiAsk the user for two values (or extract from their message):
wknd.adventures)https://gabrielwalt.github.io)which mkcert || echo "Install mkcert: brew install mkcert && mkcert -install"If mkcert is missing, tell the user to install it and run mkcert -install
once to set up the local CA.
sudo node "$DOMAIN_MASK" <display-domain> <target-url>The script handles everything automatically:
127.0.0.1 <display-domain> to /etc/hostsTell the user:
https://<display-domain> in their browserAfter the user stops the proxy, verify cleanup succeeded by checking the script output. If it reports a warning about /etc/hosts cleanup, help the user remove the entry manually:
sudo sed -i '' '/<display-domain>/d' /etc/hosts/etc/hosts path, brew install mkcert)© adobe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts) in plugins/web/skills/domain-mask of adobe/skills.
Open the folder on GitHubat commit 985c436
Domain Mask next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Domain Mask this skilladobe/skills | 196 | — | ~739 | Automated safety check: Notes | Apache-2.0 | |
| Kubeshark KFL2 Filter Referencekubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Nginx To Higress Migrationhigress-group/higress | 9.5k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Bfe Rd Workflowbfenetworks/bfe | 6.3k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress | 5.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| NGINX Ingress Policy CRD Guidenginx/kubernetes-ingress | 5.1k | — | ~2k | Automated safety check: Pass | Apache-2.0 |
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
higress-group/higress
Migrate from ingress-nginx to Higress in Kubernetes environments.
bfenetworks/bfe
引导用户在 bfe 代码库中完成一次完整的功能研发流程,包括需求对齐、文档修改、代码实现、集成测试与回归验证. An agent skill from bfenetworks/bfe.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
nginx/kubernetes-ingress
Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.
erfnzdeh/arvancloud-agent-skill
Drives ArvanCloud's REST APIs for CDN, DNS, cloud servers, object storage and more, with helper scripts for calls, account inventory and certificates.
adobe/skills
Scaffolds, implements, deploys and debugs Adobe Runtime actions in App Builder projects, with templates for webhooks, events, database CRUD, sequences and Asset Compute workers.
adobe/skills
Launches Chrome with an unpacked extension over CDP, opens its sidepanel, popup or options page, and hands over to cdp-connect for clicks, typing and screenshots.
adobe/skills
Extracts icons, metadata, text, forms, videos and social links from any web page with playwright-cli, with SVG icon classification and cleanup.
adobe/skills
Detect all languages used on a webpage — both declared (html@lang, hreflang alternate links, nested lang= attributes, meta content-language) and actually present in the body text (Google CLD3 via…
adobe/skills
Prepare any webpage for clean interaction by detecting and removing disruptive overlays (cookie banners, GDPR consent, modals, popups, newsletter signups, paywalls, login walls).
adobe/skills
Reduce a webpage to a structural skeleton with semantic tokens.
Categories
Mask a URL behind a custom domain for demos and recordings. An agent skill from adobe/skills. Domain Mask is an agent skill from adobe/skills. Mask a URL behind a custom domain for demos and recordings.
Domain Mask fits situations like: mask URL for demo; tasks that involve Cloud networking.
Run `npx skills add adobe/skills --skill domain-mask -a claude-code`. Or copy the skill folder (plugins/web/skills/domain-mask in adobe/skills) into .claude/skills/domain-mask in your project. Claude Code loads it when a task matches its description.
Run `npx skills add adobe/skills --skill domain-mask -a codex`. Or copy the skill folder (plugins/web/skills/domain-mask in adobe/skills) into .agents/skills/domain-mask in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add adobe/skills --skill domain-mask -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/domain-mask, .gemini/skills/domain-mask, .github/skills/domain-mask and .opencode/skills/domain-mask in your project.
Going by SKILL.md and its folder, Domain Mask needs JavaScript for the scripts in its folder and the command-line tools its instructions call (brew and node). Our summary lists: Node.js. Compatibility (from SKILL.md): macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification)..
SKILL.md names 2 domains. In commands or code: main--mysite--org.aem.page and gabrielwalt.github.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Domain Mask is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 739 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Domain Mask: Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), Bfe Rd Workflow (bfenetworks/bfe, 6.3k stars) and NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
adobe (a GitHub organization) maintains it in adobe/skills, which has 196 GitHub stars. The repository holds 65 skills in this directory. The repository was last updated on October 7, 2026.
Source: adobe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.