Agent skill

Domain Mask

by adobe in adobe/skills

Mask a URL behind a custom domain for demos and recordings. An agent skill from adobe/skills.

Apache-2.0Auto-check: notesDevOps & Cloud

Install Domain Mask

skills CLI
$ npx skills add adobe/skills --skill domain-mask -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install adobe/skills domain-mask --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/web/skills/domain-mask .claude/skills/domain-mask && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
domain-mask
GitHub stars
196
Token cost
~739 tokens
SKILL.md length
260 words
Files
5 (incl. scripts)
Skills in repo
65
Repo updated
First seen
Licence
Apache-2.0

At a glance

Mask a URL behind a custom domain for demos and recordings. An agent skill from adobe/skills.

  • Works in 4 steps: Gather inputs → Check prerequisites → Start the proxy → …
  • Mask URL for demo
  • SKILL.md covers Prerequisites, Script Location, Workflow and Limitations
  • Runs JavaScript scripts from its folder; calls brew and node; reaches main--mysite--org.aem.page and gabrielwalt.github.io

What it does

Domain Mask is an agent skill from adobe/skills. Mask a URL behind a custom domain for demos and recordings. Adds a trusted HTTPS reverse proxy so the browser shows a clean display domain with a green padlock while serving content from the real target URL. Handles /etc/hosts, mkcert certificates, and cleanup automatically. Triggers on: "domain mask", "mask domain", "mock domain", "proxy URL", "demo URL", "fake domain", "demo proxy", "mask URL for demo", "domain-mask".

Its SKILL.md is about 740 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `.releaserc.json`, `evals/evals.json` and `package.json`). Compatibility notes: macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification).

It sits in DevOps & Cloud, covering Cloud networking. The repository describes itself as: Adobe Skills for Agents. The licence is Apache-2.0.

When your agent uses it

  • Mask URL for demo
  • Tasks that involve Cloud networking

Example prompts

  • “domain mask”
  • “mask domain”
  • “mock domain”
  • “/domain-mask”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification).

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather inputs
  2. Check prerequisites
  3. Start the proxy
  4. Confirm cleanup

What it can do on your machine

Read from SKILL.md and the folder at commit 985c436. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • brew
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • main--mysite--org.aem.page
    • gabrielwalt.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification).

    From compatibility in the SKILL.md frontmatter.

Context cost

Domain Mask loads about 739 tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 260 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~739

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:4
    ibility: macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification).
  • NoteRuns commands with sudoSKILL.md:26
    - sudo access (for port 443 and /etc/hosts)
  • NoteRuns commands with sudoSKILL.md:63
    sudo node "$DOMAIN_MASK" <display-domain> <target-url>
  • NoteRuns commands with sudoSKILL.md:86
    sudo sed -i '' '/<display-domain>/d' /etc/hosts
  • NoteRuns commands with sudoSKILL.md:92
    - Requires sudo (privileged port 443 + hosts file)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from adobe/skills at commit 985c436, republished under its Apache-2.0 licence (© adobe). 260 words, ~739 tokens.

Download SKILL.mdSave it as .claude/skills/domain-mask/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
domain-mask
description
Mask a URL behind a custom domain for demos and recordings. Adds a trusted HTTPS reverse proxy so the browser shows a clean display domain with a green padlock while serving content from the real target URL. Handles /etc/hosts, mkcert certificates, and cleanup automatically. Triggers on: "domain mask", "mask domain", "mock domain", "proxy URL", "demo URL", "fake domain", "demo proxy", "mask URL for demo", "domain-mask".
compatibility
macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification).
license
Apache-2.0

domain-mask

Mask a URL behind a custom domain for demos and recordings. Opens an HTTPS reverse proxy so the browser address bar shows a clean domain (e.g., wknd.adventures) while content is served from the real URL (e.g., https://main--mysite--org.aem.page). Trusted certificate via mkcert — no browser warnings.

Prerequisites

  • Node 22+
  • mkcert (brew install mkcert && mkcert -install)
  • sudo access (for port 443 and /etc/hosts)

Script Location

bash
if [[ -n "${CLAUDE_SKILL_DIR:-}" ]]; then
  DOMAIN_MASK="${CLAUDE_SKILL_DIR}/scripts/domain-mask.mjs"
else
  DOMAIN_MASK="$(find ~/.claude -path "*/domain-mask/scripts/domain-mask.mjs" \
    -type f 2>/dev/null | head -1)"
fi
if [[ -z "$DOMAIN_MASK" || ! -f "$DOMAIN_MASK" ]]; then
  echo "Error: domain-mask.mjs not found." >&2
fi

Workflow

Step 1: Gather inputs

Ask the user for two values (or extract from their message):

  • Display domain — the domain to show in the browser (e.g., wknd.adventures)
  • Target URL — the real URL to proxy (e.g., https://gabrielwalt.github.io)
Step 2: Check prerequisites
bash
which mkcert || echo "Install mkcert: brew install mkcert && mkcert -install"

If mkcert is missing, tell the user to install it and run mkcert -install once to set up the local CA.

Step 3: Start the proxy
bash
sudo node "$DOMAIN_MASK" <display-domain> <target-url>

The script handles everything automatically:

  1. Adds 127.0.0.1 <display-domain> to /etc/hosts
  2. Generates a trusted HTTPS certificate via mkcert
  3. Starts an HTTPS reverse proxy on port 443
  4. Prints the URL to open

Tell the user:

  • Open https://<display-domain> in their browser
  • The address bar will show the display domain with a green padlock
  • Press Ctrl+C when done — the script removes the hosts entry and cleans up temp certs automatically
Step 4: Confirm cleanup

After the user stops the proxy, verify cleanup succeeded by checking the script output. If it reports a warning about /etc/hosts cleanup, help the user remove the entry manually:

bash
sudo sed -i '' '/<display-domain>/d' /etc/hosts

Limitations

  • macOS only (/etc/hosts path, brew install mkcert)
  • Requires sudo (privileged port 443 + hosts file)
  • One display domain per invocation
  • Does not rewrite URLs inside HTML/CSS/JS response bodies

© adobe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in plugins/web/skills/domain-mask of adobe/skills.

  • SKILL.md
  • .releaserc.json
  • evals/evals.json
  • package.json
  • scripts/domain-mask.mjs

Open the folder on GitHubat commit 985c436

Compare with similar skills

Domain Mask next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Domain Mask compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Domain Mask this skilladobe/skills196—~739Automated safety check: NotesApache-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0
Nginx To Higress Migrationhigress-group/higress9.5k—~3.9kAutomated safety check: PassApache-2.0
Bfe Rd Workflowbfenetworks/bfe6.3k—~1.3kAutomated safety check: PassApache-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0
NGINX Ingress Policy CRD Guidenginx/kubernetes-ingress5.1k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Bfe Rd Workflow

    bfenetworks/bfe

    引导用户在 bfe 代码库中完成一次完整的功能研发流程,包括需求对齐、文档修改、代码实现、集成测试与回归验证. An agent skill from bfenetworks/bfe.

    6.3k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • NGINX Ingress Policy CRD Guide

    nginx/kubernetes-ingress

    Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.

    5.1k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • ArvanCloud API Operator

    erfnzdeh/arvancloud-agent-skill

    Drives ArvanCloud's REST APIs for CDN, DNS, cloud servers, object storage and more, with helper scripts for calls, account inventory and certificates.

    135 GitHub stars~3.9k tokensUpdated 10 days ago
    DevOps & CloudAuto-check passed

More from adobe/skills

All 65 skills in this repo
  • Scaffolds, implements, deploys and debugs Adobe Runtime actions in App Builder projects, with templates for webhooks, events, database CRUD, sequences and Asset Compute workers.

    196 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Launches Chrome with an unpacked extension over CDP, opens its sidepanel, popup or options page, and hands over to cdp-connect for clicks, typing and screenshots.

    196 GitHub stars~952 tokensUpdated yesterday
    Auto-check passed
  • Extracts icons, metadata, text, forms, videos and social links from any web page with playwright-cli, with SVG icon classification and cleanup.

    196 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Page Langs

    adobe/skills

    Detect all languages used on a webpage — both declared (html@lang, hreflang alternate links, nested lang= attributes, meta content-language) and actually present in the body text (Google CLD3 via…

    196 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Page Prep

    adobe/skills

    Prepare any webpage for clean interaction by detecting and removing disruptive overlays (cookie banners, GDPR consent, modals, popups, newsletter signups, paywalls, login walls).

    196 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Page Reduce

    adobe/skills

    Reduce a webpage to a structural skeleton with semantic tokens.

    196 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Domain Mask

What does Domain Mask do?

Mask a URL behind a custom domain for demos and recordings. An agent skill from adobe/skills. Domain Mask is an agent skill from adobe/skills. Mask a URL behind a custom domain for demos and recordings.

When should I use Domain Mask?

Domain Mask fits situations like: mask URL for demo; tasks that involve Cloud networking.

How do I install Domain Mask in Claude Code?

Run `npx skills add adobe/skills --skill domain-mask -a claude-code`. Or copy the skill folder (plugins/web/skills/domain-mask in adobe/skills) into .claude/skills/domain-mask in your project. Claude Code loads it when a task matches its description.

How do I install Domain Mask in Codex?

Run `npx skills add adobe/skills --skill domain-mask -a codex`. Or copy the skill folder (plugins/web/skills/domain-mask in adobe/skills) into .agents/skills/domain-mask in your project. Codex loads it when a task matches its description.

Can I use Domain Mask in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add adobe/skills --skill domain-mask -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/domain-mask, .gemini/skills/domain-mask, .github/skills/domain-mask and .opencode/skills/domain-mask in your project.

What does Domain Mask need to run?

Going by SKILL.md and its folder, Domain Mask needs JavaScript for the scripts in its folder and the command-line tools its instructions call (brew and node). Our summary lists: Node.js. Compatibility (from SKILL.md): macOS only. Requires mkcert and sudo (for port 443 and /etc/hosts modification)..

Does Domain Mask access the network?

SKILL.md names 2 domains. In commands or code: main--mysite--org.aem.page and gabrielwalt.github.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Domain Mask safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Domain Mask use?

Domain Mask is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Domain Mask use?

About 739 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Domain Mask?

Skills that share tags, products or a category with Domain Mask: Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), Bfe Rd Workflow (bfenetworks/bfe, 6.3k stars) and NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Domain Mask?

adobe (a GitHub organization) maintains it in adobe/skills, which has 196 GitHub stars. The repository holds 65 skills in this directory. The repository was last updated on October 7, 2026.

Source: adobe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.