Agent skill

API Proxy Safety

by doccker in doccker/cc-use-exp

网关/代理/WAF/CDN 中间件的安全关键词匹配实现规范,防止纯子串匹配误判正常响应内容中的技术术语(如 Cloudflare、502、error)

Custom licenceAuto-check passed

Install API Proxy Safety

skills CLI
$ npx skills add doccker/cc-use-exp --skill api-proxy-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install doccker/cc-use-exp api-proxy-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/doccker/cc-use-exp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/api-proxy-safety .claude/skills/api-proxy-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-proxy-safety
GitHub stars
1.1k
Token cost
~1.1k tokens
SKILL.md length
234 words
Files
1
Skills in repo
67
Repo updated
First seen
Licence
Custom licence

At a glance

网关/代理/WAF/CDN 中间件的安全关键词匹配实现规范,防止纯子串匹配误判正常响应内容中的技术术语(如 Cloudflare、502、error)

  • SKILL.md covers 核心问题, 解决方案:强/弱特征拆分 + 分层判定, 不同场景的匹配策略 and 隐含缺陷判定, plus 2 more sections
  • Calls just

What it does

API Proxy Safety is an agent skill from doccker/cc-use-exp. 网关/代理/WAF/CDN 中间件的安全关键词匹配实现规范,防止纯子串匹配误判正常响应内容中的技术术语(如 Cloudflare、502、error)

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Cloudflare. The repository describes itself as: ⛔ No longer maintained → dev-agent-kit/recipes 让 Claude Code、Antigravity、Gemini CLI、Codex、Cursor 开箱即用的分层配置模板,总结十多年的日常开发经验.

Example prompts

  • “/api-proxy-safety”

What it can do on your machine

Read from SKILL.md and the folder at commit 64470cb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Proxy Safety loads about 1.1k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 234 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 234 words (~1,074 tokens).

name
api-proxy-safety
version
v1.0
paths
**/*proxy*, **/*gateway*, **/*waf*, **/*middleware*, **/*interceptor*, **/*filter*, **/*openapi*, **/*nginx*, **/*openresty*, **/*rewrite*, **/*redirect*…

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/api-proxy-safety of doccker/cc-use-exp.

Open the folder on GitHubat commit 64470cb

Compare with similar skills

API Proxy Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Proxy Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Proxy Safety this skilldoccker/cc-use-exp1.1k—~1.1kAutomated safety check: PassCustom licence
Cloudflare Browser Renderingcloudflare/moltworker9.9k—~742Automated safety check: PassApache-2.0
Turnstile Spincloudflare/skills3k4 repos~7.2kAutomated safety check: NotesApache-2.0
Star Office UI Setupringhyacinth/Star-Office-UI7.5k—~1.3kAutomated safety check: PassMIT
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0

Similar skills

  • Cloudflare Browser Rendering

    cloudflare/moltworker

    Official

    Drives headless Chrome through Cloudflare Browser Rendering over a CDP WebSocket to take screenshots, navigate and scrape pages, and record multi-page videos.

    9.9k GitHub stars~742 tokensUpdated 5 mo ago
    Productivity & AutomationAuto-check passed
  • Turnstile Spin

    cloudflare/skills

    Official

    Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.

    3k GitHub starsUsed in 4 repos~7.2k tokens
    Frontend & DesignAuto-check: notes
  • Star Office UI Setup

    ringhyacinth/Star-Office-UI

    Sets up Star Office UI, a pixel-art office dashboard that shows AI agent states, lets other agents join and can be opened from a phone or a public link.

    7.5k GitHub stars~1.3k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • Nextjs On Cloudflare

    cloudflare/skills

    Official

    Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.

    3k GitHub starsUsed in 2 repos~678 tokens
    DevOps & CloudAuto-check passed

More from doccker/cc-use-exp

All 67 skills in this repo
  • API Design Safety

    doccker/cc-use-exp

    当设计或修改 REST API 响应结构、处理 API 返回值,或生成 Excel/CSV/PDF/对账文件等下游产物时触发。防止 API 设计缺陷导致的字段错位、类型歧义,以及生成产物时关键字段缺失但静默成功的问题。

    1.1k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Cc Code Quality Principles

    doccker/cc-use-exp

    当编写新模块、设计接口、重构代码或代码审查时触发。提供经典模块化六原则检查清单(大小适中/调用深度/扇入扇出/边界清晰/作用域内聚/可预测性),适用于 PR/Review/新模块设计场景。

    1.1k GitHub stars~816 tokensUpdated 1 mo ago
    Auto-check passed
  • Cc Review

    doccker/cc-use-exp

    结构化代码审查工作流,适用于显式 quick/full/security review;不负责普通实现或 bug 修复流程。

    1.1k GitHub stars~541 tokensUpdated 1 mo ago
    Auto-check passed
  • Cc Streaming Export Safety

    doccker/cc-use-exp

    当实现用户驱动的大文件导出或批量序列化(Excel/CSV/JSON/JSONL/PDF,数据量未知或超过 1 万行/10 MB)时触发;普通小文件下载、静态资源下载、非导出 Writer/Report 类不触发。防止 OOM、临时文件残留、同步导出阻塞 HTTP 线程和表格公式注入。

    1.1k GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Code Quality Principles

    doccker/cc-use-exp

    当编写新模块、设计接口、重构代码或代码审查时触发。提供经典模块化六原则检查清单(大小适中/调用深度/扇入扇出/边界清晰/作用域内聚/可预测性),适用于 PR/Review/新模块设计场景。

    1.1k GitHub stars~803 tokensUpdated 1 mo ago
    Auto-check passed
  • External System Debugging

    doccker/cc-use-exp

    涉及浏览器、编辑器、CDN/WAF、IM 平台、操作系统剪贴板、第三方 SaaS 等"外部黑盒系统"的代码编写或 bug 调试时触发。强制先抓真实环境数据再推理,避免连续 2 轮"凭代码推理"的修复 no-op。关键词:粘贴/复制异常、跨平台显示不一致、第三方 API 怪结果、CDN/WAF 拦截、本地复现失败、HTML→MD 转换丢属性。

    1.1k GitHub stars~823 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about API Proxy Safety

What does API Proxy Safety do?

网关/代理/WAF/CDN 中间件的安全关键词匹配实现规范,防止纯子串匹配误判正常响应内容中的技术术语(如 Cloudflare、502、error). API Proxy Safety is an agent skill from doccker/cc-use-exp.

How do I install API Proxy Safety in Claude Code?

Run `npx skills add doccker/cc-use-exp --skill api-proxy-safety -a claude-code`. Or copy the skill folder (.claude/skills/api-proxy-safety in doccker/cc-use-exp) into .claude/skills/api-proxy-safety in your project. Claude Code loads it when a task matches its description.

How do I install API Proxy Safety in Codex?

Run `npx skills add doccker/cc-use-exp --skill api-proxy-safety -a codex`. Or copy the skill folder (.claude/skills/api-proxy-safety in doccker/cc-use-exp) into .agents/skills/api-proxy-safety in your project. Codex loads it when a task matches its description.

Can I use API Proxy Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add doccker/cc-use-exp --skill api-proxy-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-proxy-safety, .gemini/skills/api-proxy-safety, .github/skills/api-proxy-safety and .opencode/skills/api-proxy-safety in your project.

What does API Proxy Safety need to run?

Going by SKILL.md and its folder, API Proxy Safety needs the command-line tools its instructions call (just).

Does API Proxy Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Proxy Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Proxy Safety use?

API Proxy Safety has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does API Proxy Safety use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Proxy Safety?

Skills that share tags, products or a category with API Proxy Safety: Cloudflare Browser Rendering (cloudflare/moltworker, 9.9k stars), Turnstile Spin (cloudflare/skills, 3k stars), Star Office UI Setup (ringhyacinth/Star-Office-UI, 7.5k stars) and Cloudflare (hodgef/apiker, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Proxy Safety?

doccker (a GitHub user) maintains it in doccker/cc-use-exp, which has 1,063 GitHub stars. The repository holds 67 skills in this directory. The repository was last updated on August 26, 2026.

Source: doccker/cc-use-exp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.