Agent skill

Portal Expose

by gosuda in gosuda/portal-tunnel

Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint…

MITAuto-check passedFrontend & Design

Install Portal Expose

skills CLI
$ npx skills add gosuda/portal-tunnel --skill portal-expose -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gosuda/portal-tunnel portal-expose --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gosuda/portal-tunnel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/portal-deploy/skills/portal-expose .claude/skills/portal-expose && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
portal-expose
GitHub stars
304
Token cost
~4.3k tokens
SKILL.md length
2,453 words
Files
7 (incl. references)
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint…

  • Works in 7 steps: Inspect the Project → Verify the Local Service → Check Portal → …
  • The user asks to deploy
  • SKILL.md covers Choose the Mode, Workflow, Loopback Relay Variant and Failure Rules
  • Calls curl

What it does

Portal Expose is an agent skill from gosuda/portal-tunnel. Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint and report its lifecycle. This is the app side of Portal, the same flow as the quick-start form on a relay website (install, run one portal expose command built from the app settings, open the public URL). Use when the user asks to deploy, publish, share, tunnel, expose, or connect a local app to Portal or to a specific…

Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `references/game-hosting.md` and `references/portal-cli.md`).

It sits in Frontend & Design, covering Static sites and blogs. It works with x402. The repository describes itself as: Publishes localhost services to the agentic web through self-hostable, trustless relays. The licence is MIT.

When your agent uses it

  • The user asks to deploy
  • Connect a local app to Portal
  • A specific relay
  • Create a public preview

Example prompts

  • “/portal-expose”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Inspect the Project
  2. Verify the Local Service
  3. Check Portal
  4. Build the Command or Agent Config
  5. Start and Observe the Tunnel
  6. Verify the Public Endpoint
  7. Hand Off the Result

What it can do on your machine

Read from SKILL.md and the folder at commit 6f49ccb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Portal Expose loads about 4.3k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 244 tokens; SKILL.md has 2,453 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~244
When it runs · the whole SKILL.md, loaded when a task matches
~4.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gosuda/portal-tunnel at commit 6f49ccb, republished under its MIT licence (© gosuda). 2,453 words, ~4,329 tokens.

Download SKILL.mdSave it as .claude/skills/portal-expose/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
portal-expose
description
Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint and report its lifecycle. This is the app side of Portal, the same flow as the quick-start form on a relay website (install, run one portal expose command built from the app settings, open the public URL). Use when the user asks to deploy, publish, share, tunnel, expose, or connect a local app to Portal or to a specific relay, create a public preview, add a paid route, configure x402, needs an HTTPS URL on a phone or another device because a browser feature such as microphone, camera, geolocation, or PWA install refuses to work over a LAN http address, or wants a Go app to embed the Portal SDK. Do not use for deploying a Portal relay, generic cloud hosting, publishing this plugin, or reaching a service that someone else already published (portal-connect).
license
MIT

Expose an App with Portal

Portal publishes a service that is already running on the user's machine. It does not build the app or move it to a cloud host. Treat a successful tunnel as dependent on both the local app and the Portal process or agent remaining available. This is the app side of Portal: every relay website offers the same three steps (paste what to share, run one install-and-expose command built from the app settings, open the public URL), and this skill performs those steps for the app with verification around them. Any other program that reaches the published URL needs nothing from Portal.

Run the workflow in order. Open a reference only when that branch is taken: references/x402.md for a paid route, references/safety-and-verification.md for an authenticated, sensitive/high-risk, or non-HTTP service, references/game-hosting.md for a game server, references/portal-cli.md when choosing persistent-agent configuration or checking a flag, references/sdk-embed.md only for a Go app that should run the tunnel inside its own process. Use the installed portal CLI for flags.

Choose the Mode

Use the smallest mode that satisfies the request:

  • Temporary web preview: portal expose <target>.
  • Connect the app to a relay the user picked, as its website's quick start does: install Portal from the official GitHub installer if it is missing, then portal expose <target> --name <name> --relays <relay-url>, with --discovery=false when only that relay should carry the app.
  • Trusted static directory or HTML entry: portal expose --serve <path>.
  • Multiple local HTTP services under one URL: repeat --http-route.
  • Paid HTTP path: routed HTTP with an explicit x402 payment contract; never enable payment implicitly.
  • Durable tunnel that should survive terminal or login restarts: an explicit portal agent config and managed service.
  • Session-owned durable tunnel without an OS service: portal agent run --foreground.
  • Game server (Minecraft, Terraria, Palworld, or any dedicated game server): always start from references/game-hosting.md — raw TCP/UDP transport has different prerequisites and verification than HTTP.
  • Go app that should carry the tunnel in-process instead of running the CLI next to it: references/sdk-embed.md. The CLI stays the default even for Go; embedding is for users who ask for it.

Default to a temporary preview when the user says only "share", "preview", or "deploy locally". Do not install an OS service unless the user asks for a persistent, managed, or restart-surviving tunnel and accepts that portal agent run without --foreground installs a per-user launchd or systemd unit.

Workflow

1. Inspect the Project
  • Read the applicable repository instructions before running or changing anything.
  • Determine the app directory, start command, expected protocol, loopback target, and a meaningful health path.
  • Prefer declared scripts and documented ports over guessing from process lists.
  • Do not expose a port merely because it is listening. Tie it to the requested app.
  • If the project is already running, preserve its process. If it is not running and deployment was requested, start it with the project's normal command and retain the terminal/session handle.

Ask one concise question only when the target, desired lifetime, or transport cannot be discovered safely. An explicit request to deploy, publish, expose, tunnel, or share authorizes creating the public tunnel for the named app; it does not authorize exposing adjacent services.

For x402, do not guess the protected path, payment methods, amount, network, recipient, or network-specific asset. Collect any missing consequential value before building the command or config. Treat an omitted method list as charging every method on the route and confirm that scope when it was not explicit.

2. Verify the Local Service
  • Wait for the app's real readiness signal, not only for the process to exist.
  • Make a bounded local request to the selected target. For HTTP, record the URL and status. For TCP/UDP, use a protocol-appropriate check that does not mutate application data.
  • Stop before opening a tunnel if the local health check fails.
  • Warn and require explicit direction before exposing databases, container daemons, debug consoles, unauthenticated admin panels, or services containing sensitive data.
  • Before opening the tunnel, say that the public hostname is enumerable through each participating relay's GET /api/state unless the user asked for --hide, and that relays which enable their directory page show it there too.
3. Check Portal
  • Run portal version when portal is available.
  • If Portal is missing, present the official GitHub installer and request approval before running it because installation writes outside the project. A relay also serves an installer at <relay>/api/install.sh (install.ps1 on Windows), but the relay then supplies the script, the binary, and the checksum together, so nothing in that download is verified independently of the relay. Use it only when the user explicitly prefers it, and before running the installed binary compare its SHA-256 with the checksums.txt or .sha256 asset of the matching GitHub release, fetched from github.com rather than from the relay. Never run an installer from a relay the user did not choose or from a third-party URL.
  • Do not assume a hard-coded latest release or stale flags. Use the installed Portal version as the compatibility baseline.
4. Build the Command or Agent Config
  • Use loopback targets such as 127.0.0.1:<port> unless the project explicitly needs another address.
  • Use the user's requested name. Otherwise derive a DNS-label-safe name from the app and pass it explicitly, so the public URL https://<name>.<relay-host>/ is known before the tunnel starts; the relay website always emits --name for the same reason. --name applies only when the identity file is created. An existing --identity-path keeps its saved name and silently ignores the flag, so use one identity file per public name.
  • For portal expose, always pass an absolute --identity-path outside the repository. The CLI default is identity.json in the process working directory and that file contains private key material. For portal agent, omit identity_path so the agent stores identity under its state directory; if you set the field, use an absolute path outside the repository.
  • Never print or commit identity JSON, control tokens, facilitator tokens, or wallet secrets.
  • With a user-selected relay on portal expose, pass --relays <https-url> --discovery=false. In persistent mode those flags are not accepted on portal agent run; put relays = ["https://..."] and discovery = false on the [[tunnels]] entry instead.
  • Map the app's settings onto the command the way the relay quick-start form does: a port or host:port is the positional target; an http(s):// URL contributes its host and port; a directory or HTML file becomes --serve <path>; a thumbnail URL, description, tags, or owner that the app or user defines go to --thumbnail, --description, --tags, --owner, all of which are public metadata; a datagram service adds --udp, with --udp-addr when the UDP port differs from the target.
  • The MITM self-probe runs against every relay whose tenant TLS stack exports keying material. Without --ban-mitm / ban_mitm = true, a suspected TLS termination is only logged and the tunnel keeps serving; do not claim the default path blocks a relay. Add --ban-mitm only when the user wants fail-closed handling; it then refuses relays that cannot export keying material instead of serving unprotected. --cache opts out of the probe entirely because it deliberately lets the relay terminate TLS, and it cannot be combined with --ban-mitm.
  • Never add TCP, UDP, payment, --cache, --cache-ttl, or --overlay flags that the user did not request; --cache hands the relay the static files and browser TLS termination. Public metadata flags are fine when their values come from the app's own settings or from the user; do not invent them. --hide is the exception for listing: mention the default public listing, then add --hide or hide = true only when the user wants the tunnel unlisted.
  • For a paid route, follow references/x402.md. Keep payment policy on the smallest requested path, use an explicit network, and never place wallet or facilitator secrets in a command, log, committed file, or final response.

Before executing, show the exact public target and any important exposure consequence when it is not already obvious from the user's request.

5. Start and Observe the Tunnel
  • Run a temporary portal expose in a foreground PTY or managed long-running command session. Do not hide it behind an untracked nohup process.
  • For persistent mode, inspect any existing agent config and running service first. run, restart, and stop are service-wide: they affect every [[tunnels]] entry that the selected service owns. Reuse and merge the existing config when the same agent should keep other tunnels. An isolated second agent needs its own config, service_name, state_dir, and loopback control_addr. Changing only service_name still shares the default state directory and 127.0.0.1:4018. Do not stop or replace an agent that already owns unrelated tunnels.
  • Create or update only the selected agent config, then start it with portal agent run --config <path> after the user accepts OS-service installation (portal agent run requires the file to exist; it never creates one), or portal agent run --foreground --config <path> when the current session should own the process. --foreground opens the interactive dashboard when stdin and stdout are TTYs. Run that command in a non-TTY managed session so logs stay capturable and the TUI does not start.
  • Do not run portal agent dashboard. It is an interactive TUI. Give the user that command in the handoff.
  • Capture bounded output. Redact tokens, identity material, signed payloads, and credentials.
  • HTTP tunnels are ready on a log event with field public_url. The message still starts with service ready at. Relay https:// values in listener_relays / added_relays are not ready. Raw TCP/UDP tunnels log raw transport endpoints allocated with tcp_addr and/or udp_addr instead. Do not wait for an HTTPS URL on a raw transport. A later line starting relay no longer active for retracts a URL; re-verify before handoff if you see one.
Show full SKILL.md (862 more words)Show less
6. Verify the Public Endpoint
  • Confirm the lease the way the relay website does: GET <relay>/api/state lists the hostname with ready > 0 once the tunnel can serve; ready at zero means registered but not yet connected.
  • For HTTP, make a bounded HTTPS request to every public URL being handed off. A deliberately authenticated app may return 401 or 403; explain that as reachable but protected. Treat unexpected 5xx, TLS errors, or a Portal error page as a failed deployment.
  • For each paid route, make an unpaid request with a protected method and require 402 Payment Required plus a payment-requirements header. Compare the returned network, asset, recipient, amount, and resource with the requested policy. Verify the method scope by requesting an intentionally unprotected method when one exists. Never spend funds merely to verify configuration.
  • For raw TCP or UDP, protocol-probe the allocated tcp_addr/udp_addr without mutating application data. A successful local port open is not enough.
  • When a browser-capable tool is available and the app has UI, load the primary page and check for an obvious render or runtime failure. Do not log in or submit data unless the user requested it.
  • Re-check the local health endpoint if the public request fails so the handoff distinguishes app failure from tunnel or relay failure.
7. Hand Off the Result

Report:

  • Deployment mode and exact local target.
  • Public URL or allocated raw endpoint, and the verified status.
  • Whether the tunnel is listed on public relays or hidden with --hide.
  • Whether MITM handling is detect-only or --ban-mitm.
  • For x402, the protected paths and methods, human amount, network, public recipient, facilitator mode, and whether the unpaid 402 challenge was verified. State explicitly when settlement was not tested.
  • The identity path and that it must stay out of version control.
  • The app and Portal process/session or OS-service ownership.
  • The exact stop or restart command, and whether that command affects other tunnels on the same agent.
  • Anything that remains temporary, unavailable, or unverified.

Do not call the result permanent when the local machine, app process, or foreground tunnel must remain running.

If Portal-specific friction materially affected the task, report one sanitized sentence (command, expected versus actual). Do not initiate GitHub feedback handling, write feedback files, or query extra relays unless the user explicitly requests that follow-up.

Loopback Relay Variant

Use this variant only when the user asks to expose through a relay running on this machine. The relay must already be running; the client never starts one. Do not consult or fall back to the public registry in this mode.

  • Run the client and the relay from the same Portal checkout or release. This pairing is for local development and test harnesses only; production users expose through their relay's public deployment. A mixed pair (for example an installed release against a worktree relay) can register hostnames the relay's SNI router never matches, and the tunnel can stall while the client retries.
  • Point the client at the relay's canonical SNI origin: portal expose <loopback-target> --name <name> --identity-path <absolute-path-outside-repo> --relays https://127.0.0.1:<sni-port> --discovery=false. When port 443 is unavailable, start the same-tree relay with relay-server --portal-url https://127.0.0.1:<port>; SNI_PORT follows the PORTAL_URL port, so pass --sni-port only when the bind port differs from the public one. The SNI router is the relay's single ingress: it serves the root host's Admin/API handler in-process.
  • Treat the tunnel as ready only when the log prints the line starting service ready at carrying public_url. Listener or added-relay https:// URLs in the same output describe relay listeners, not tenant readiness.
  • Verify the emitted public_url itself with one bounded request. *.localhost often resolves to ::1 first, so use curl -sk --ipv4 --connect-timeout 5 --max-time 15 -o /dev/null -w '%{http_code}' <public-url> and accept the app's real status (401 or 403 means reachable and protected).
  • Stop and report instead of improvising when a required fact is missing: no relay admin URL or port, no identity path outside the repository, or no service ready at line within a bounded wait. Do not substitute registry relays or start extra relays to unblock the run.

Failure Rules

  • Local app unhealthy: stop before exposing it and report the failing check.
  • Portal absent and installation not approved: provide the official command without executing it.
  • No ready public URL or allocated raw endpoint: keep the bounded diagnostic output and report the relay/tunnel failure.
  • Paid route returns anything other than the expected 402 challenge: do not describe it as protected or hand it off as ready. Stop only the tunnel created by this workflow, preserve bounded diagnostics, and report the policy mismatch.
  • MITM self-probe warning without --ban-mitm: report the warning and offer --ban-mitm; do not claim the relay was blocked. A self-probe timed out or self-probe failed line is not a detection; report passthrough as unverified.
  • Requested name unavailable: offer an auto-generated or alternative name; do not silently hijack another identity.
  • --name had no effect: the identity file already existed and supplied its saved name. Point --identity-path at a new file for a new name.
  • Existing agent owns other tunnels: do not stop or replace it to publish this app.
  • Cancellation: stop only processes started by this workflow, unless the user explicitly asks to stop an existing app or agent.

© gosuda, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/portal-deploy/skills/portal-expose of gosuda/portal-tunnel.

  • SKILL.md
  • agents/openai.yaml
  • references/game-hosting.md
  • references/portal-cli.md
  • references/safety-and-verification.md
  • references/sdk-embed.md
  • references/x402.md

Open the folder on GitHubat commit 6f49ccb

Compare with similar skills

Portal Expose next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Portal Expose compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Portal Expose this skillgosuda/portal-tunnel304—~4.3kAutomated safety check: PassMIT
Run402LeoYeAI/openclaw-master-skills2.2k—~4.8kAutomated safety check: PassMIT
Tabler Astro Dev Servertabler/tabler42k—~1.2kAutomated safety check: PassMIT
Create Docsvictorgarciaesgi/nuxt-typed-router4132 repos~2.8kAutomated safety check: PassMIT
Tabler Astro Component Scriptstabler/tabler42k—~2.1kAutomated safety check: PassMIT
Paperclip Pagepaperclipai/paperclip99k—~1kAutomated safety check: PassMIT

Similar skills

  • Run402

    LeoYeAI/openclaw-master-skills

    Provision Postgres databases, deploy static sites, generate images, and build full-stack webapps on Run402 using x402 micropayments.

    2.2k GitHub stars~4.8k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Starts the right Tabler dev server, keeps it from clashing with builds and verifies changes in the browser before a page or component is handed back.

    42k GitHub stars~1.2k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Create Docs

    victorgarciaesgi/nuxt-typed-router

    Create complete documentation sites for projects. An agent skill from victorgarciaesgi/nuxt-typed-router.

    413 GitHub starsUsed in 2 repos~2.8k tokens
    Frontend & DesignAuto-check passed
  • Rules for adding or fixing client-side scripts in Tabler's Astro components so the copied preview HTML stays readable, self-contained and runs in the right order.

    42k GitHub stars~2.1k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Paperclip Page

    paperclipai/paperclip

    Publish static HTML pages and asset folders to the Paperclip S3/CloudFront page host.

    99k GitHub stars~1k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Kill AI Slop

    yetone/kill-ai-slop

    Find and remove AI slop — the generic, machine-default visual and copy tics of vibe-coded products — from a web project.

    1.3k GitHub stars~1.4k tokensUpdated 25 days ago
    Frontend & DesignAuto-check passed

More from gosuda/portal-tunnel

  • Portal Connect

    gosuda/portal-tunnel

    Reach, inspect, or consume a service that someone published through a Portal relay.

    304 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Portal Relay

    gosuda/portal-tunnel

    Set up and run a public Portal relay on any Linux host with a public IP — Docker Compose deployment, embedded authoritative DNS with one-time NS delegation, optional TCP/UDP lease ports for game…

    304 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check: notes
  • How to drive the portal-tunnel agent dashboard bubbletea TUI end-to-end without a live agent or relay, using a stub control server plus a fabricated agent-endpoint.json.

    304 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Portal Expose

What does Portal Expose do?

Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint…. Portal Expose is an agent skill from gosuda/portal-tunnel. Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint and report its lifecycle.

When should I use Portal Expose?

Portal Expose fits situations like: the user asks to deploy; connect a local app to Portal; A specific relay; create a public preview.

How do I install Portal Expose in Claude Code?

Run `npx skills add gosuda/portal-tunnel --skill portal-expose -a claude-code`. Or copy the skill folder (plugins/portal-deploy/skills/portal-expose in gosuda/portal-tunnel) into .claude/skills/portal-expose in your project. Claude Code loads it when a task matches its description.

How do I install Portal Expose in Codex?

Run `npx skills add gosuda/portal-tunnel --skill portal-expose -a codex`. Or copy the skill folder (plugins/portal-deploy/skills/portal-expose in gosuda/portal-tunnel) into .agents/skills/portal-expose in your project. Codex loads it when a task matches its description.

Can I use Portal Expose in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gosuda/portal-tunnel --skill portal-expose -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/portal-expose, .gemini/skills/portal-expose, .github/skills/portal-expose and .opencode/skills/portal-expose in your project.

What does Portal Expose need to run?

Going by SKILL.md and its folder, Portal Expose needs the command-line tools its instructions call (curl).

Does Portal Expose access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Portal Expose safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Portal Expose use?

Portal Expose is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Portal Expose use?

About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.4k tokens, read only when the agent opens those files.

What are the alternatives to Portal Expose?

Skills that share tags, products or a category with Portal Expose: Run402 (LeoYeAI/openclaw-master-skills, 2.2k stars), Tabler Astro Dev Server (tabler/tabler, 42k stars), Create Docs (victorgarciaesgi/nuxt-typed-router, 413 stars) and Tabler Astro Component Scripts (tabler/tabler, 42k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Portal Expose?

gosuda (a GitHub organization) maintains it in gosuda/portal-tunnel, which has 304 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: gosuda/portal-tunnel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.