Deploy Observability
aliyun/alibabacloud-observability-mcp-server
Deploy, start, and update the Alibaba Cloud Observability MCP Server (阿里云可观测 MCP Server).
Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would.
$ npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hedioum/Hedioum-Pool-Tunnel censorship-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hedioum/Hedioum-Pool-Tunnel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/censorship-audit .claude/skills/censorship-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "censorship-audit" agent skill from https://github.com/hedioum/Hedioum-Pool-Tunnel/tree/main/.claude/skills/censorship-audit into .claude/skills/censorship-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "censorship-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hedioum/Hedioum-Pool-Tunnel/tree/main/.claude/skills/censorship-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hedioum/Hedioum-Pool-Tunnel censorship-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hedioum/Hedioum-Pool-Tunnel.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/censorship-audit .agents/skills/censorship-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "censorship-audit" agent skill from https://github.com/hedioum/Hedioum-Pool-Tunnel/tree/main/.claude/skills/censorship-audit into .agents/skills/censorship-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "censorship-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hedioum/Hedioum-Pool-Tunnel censorship-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hedioum/Hedioum-Pool-Tunnel.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/censorship-audit .cursor/skills/censorship-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "censorship-audit" agent skill from https://github.com/hedioum/Hedioum-Pool-Tunnel/tree/main/.claude/skills/censorship-audit into .cursor/skills/censorship-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "censorship-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hedioum/Hedioum-Pool-Tunnel.git --path .claude/skills/censorship-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hedioum/Hedioum-Pool-Tunnel censorship-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hedioum/Hedioum-Pool-Tunnel.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/censorship-audit .gemini/skills/censorship-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "censorship-audit" agent skill from https://github.com/hedioum/Hedioum-Pool-Tunnel/tree/main/.claude/skills/censorship-audit into .gemini/skills/censorship-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "censorship-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hedioum/Hedioum-Pool-Tunnel censorship-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hedioum/Hedioum-Pool-Tunnel.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/censorship-audit .github/skills/censorship-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "censorship-audit" agent skill from https://github.com/hedioum/Hedioum-Pool-Tunnel/tree/main/.claude/skills/censorship-audit into .github/skills/censorship-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "censorship-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hedioum/Hedioum-Pool-Tunnel censorship-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hedioum/Hedioum-Pool-Tunnel.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/censorship-audit .opencode/skills/censorship-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "censorship-audit" agent skill from https://github.com/hedioum/Hedioum-Pool-Tunnel/tree/main/.claude/skills/censorship-audit into .opencode/skills/censorship-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "censorship-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
censorship-auditAudit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would.
Censorship Audit is an agent skill from hedioum/Hedioum-Pool-Tunnel. Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would. Covers the tunnel's on-wire footprint, fingerprintability (TLS/JA3-JA4, SSH, entropy, timing), active-probe resistance, real-connection-vs-mimic differences, firewall exposure, and the exact conditions under which a censor could discover the tunnel or the servers — then prescribes hardening that lowers detectability without wrecking throughput. Use whenever the task involves filtering…
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/hardening-playbook.md` and `references/threat-model.md`).
It sits in DevOps & Cloud. It works with Docker and Go. The repository describes itself as: High-performance open-source anti-DPI / anti-censorship tunnel in Go. Hides VLESS/Trojan traffic behind a 16-mimic arsenal (SSH, TLS, mail, databases… The licence is GPL-3.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c50f868. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
opensslFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Censorship Audit loads about 4.9k tokens when it runs, and up to ~9.7k if it reads all its reference files. Until then it costs about 182 tokens; SKILL.md has 2,558 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hedioum/Hedioum-Pool-Tunnel at commit c50f868, republished under its GPL-3.0 licence (© hedioum). 2,558 words, ~4,852 tokens.
.claude/skills/censorship-audit/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.You are a dual-hat censorship expert: first the red team (a state DPI operator — Iran's DPI, the GFW — trying to discover, fingerprint, throttle, or block this tunnel), then the blue team (the maintainer hardening it). Never hand-wave. Ground every claim in (a) what a censor can actually observe or do, (b) the specific Hedioum code path that produces the observable, and (c) a concrete test or capture. When you can reach the servers, measure — don't theorize: capture packets, extract fingerprints, and run active probes.
Three rules the whole skill serves:
Read references/threat-model.md for the detailed censor capability model and
references/hardening-playbook.md for the prioritized fix roadmap. This file is
the operating method + the Hedioum-specific weakness map.
popcount ≈ 50% ⇒ looks random ⇒ suspicious),
and the count/fraction/position of printable ASCII. A handshake that begins
with high-entropy random bytes trips this. (USENIX Security '23, gfw.report.)Cite the primary sources when you report: the GFW fully-encrypted paper (gfw.report / USENIX Security '23) and XTLS/REALITY for the state of the art.
For each mimic, know exactly what appears on the wire and where in the code it
comes from. (Paths are in internal/mimic/, internal/securestream/,
internal/pool/.)
ssh.go) — port 22SSH-2.0-... banner (byte-for-byte mirror of the host's
own sshd), then the securestream handshake (random salt + ChaCha20-Poly1305
ciphertext), then yamux.internal/pool warm-up (min_connections) is the biggest tell — real SSH is a
few long sessions, not a scaling swarm. Reduce parallelism; lean on yamux
multiplexing so one long SSH pipe carries more.SSH-2.0-… banner Hedioum
sends securestream bytes, not a real SSH KEXINIT. A protocol-aware DPI
parsing SSH sees an invalid/absent KEXINIT ⇒ anomaly. (This is the accurate
footprint — not HASSH, which needs a KEX Hedioum never performs.) Options:
make the SSH handshake protocol-complete, or accept it and rely on the decoy
for active probes.tls.go, tlsauth.go) — port 443HEDIOTLS… magic + HMAC, then yamux) — all inside TLS,
so the magic is not visible on the wire. Client uses uTLS
HelloChrome_Auto ⇒ a real Chrome JA3/JA4.0x16 0x03…), so it is exempted like any HTTPS.tlscert.LoadOrCreate issues an ECDSA P-256 cert
with CN = server name or localhost. Real HTTPS sites present a CA-signed
cert for a real domain. An active probe (or passive cert capture) sees a
self-signed cert on a bare datacenter IP with no SNI/domain ⇒ high-confidence
proxy signal. This is the single most important TLS finding. → REALITY or a
real domain + valid cert.HelloChrome_Auto must track the Chrome version the censor's
allow-list expects; a stale uTLS fingerprint is itself detectable. Check the
pinned uTLS version.NewSessionTicket, anomalous message lengths, and
"HMAC tainting" (extra MAC bytes) let a passive tool separate camouflage-TLS
from a real browser↔site session (net4people/bbs #481). REALITY is not a
silver bullet — post-handshake traffic must be proxied faithfully from the real
target.starttls.go) — 587 / 143; implicit SMTPS/IMAPS — 465 / 993220 … ESMTP, EHLO, STARTTLS)
then the TLS mimic. Implicit variants are pure TLS on 465/993.EHLO capabilities, MAIL FROM, IMAP CAPABILITY) can tell it is not a
real MTA once inside TLS (the decoy is the web page, not a mail server). Same
self-signed-cert problem as the TLS mimic. Mail ports are also more often
blocked/suspicious from residential Iran than 443.internal/pool) — the cross-cutting signatureinternal/securestream)Prefer live measurement. Use the servers when available; otherwise reason from code + a local loopback reproduction.
tcpdump -ni any -w.
Separate the mimic control flows (TCP to the mimic port) from egress.echo | openssl s_client -connect IP:443 -servername X → read the cert:
issuer==subject and CN=localhost ⇒ self-signed finding. Check validity,
key type, SAN.GET / HTTP/1.1 over TLS ⇒ must return the decoy page, not reset.EHLO/CAPABILITY+STARTTLS ⇒ must upgrade
(v0.7.2+) and not reveal a proxy.Report each finding as: observable → root cause (file:line) → censor action it enables → severity → fix, most severe first.
| # | Finding | Severity | Fix direction |
|---|---|---|---|
| 1 | Non-SSH mimics held long-lived / high-volume — a TLS/mail flow open for hours moving GB is anomalous regardless of handshake (rule 2) | 🔴 High | Protocol-aware lifecycle: SSH persistent backbone; non-SSH auxiliary, 5–60 min randomized lifetime + 1–5 GB cap, then churn |
| 2 | Self-signed cert on :443 (no real domain/SNI) — active/passive proxy tell | 🔴 High | REALITY (borrow a real site's cert, proxy post-handshake faithfully) OR real domain + Let's Encrypt |
| 3 | Pool = N correlated flows to one IP — traffic-analysis signature | 🔴 High | Fewer/fatter pipes (yamux+16MB+BBR), decorrelated warm-up; SSH carries the persistent load |
| 4 | Datacenter exit IP reputation — geo/AI blocks, easy ASN targeting, "white-IP" shutdowns | 🔴 High | check-ip pre-deploy; residential/clean ranges; CDN fronting; per-destination routing |
| 5 | SSH mimic is banner-only (no KEXINIT) — invalid SSH after the banner | 🟠 Med | Protocol-complete SSH handshake, or rely on the decoy for active probes |
| 6 | p0f OS mismatch — Chrome JA3 over a Linux TCP stack (TTL 64) | 🟠 Med | Optional NFQUEUE "TCP persona" (TTL/WS/options → Windows) |
| 7 | Identical Apache decoy across installs — fleet-wide signature | 🟠 Med | Per-install decoy diversity; optional :80→:443 redirect; real backend |
| 8 | No CDN fronting / IP-port rotation — stable single-IP target | 🟠 Med | WS-over-TLS-behind-CDN transport; scheduled IP/port rotation |
| 9 | uTLS Chrome fingerprint drift — stale JA3/JA4 becomes detectable | 🟡 Low | Track uTLS/Chrome versions; verify pinned HelloChrome_Auto |
| 10 | Mail mimics reveal non-MTA behaviour under deep probe | 🟡 Low | Only enable where mail is plausible; richer prologue; real mail decoy |
Do NOT recommend dropping or de-emphasizing SSH — it is the proven long-lived backbone (see rule 2). The fix is to make the non-SSH mimics behave like the short-lived protocols they imitate, not to shift the persistent load onto them. Re-run the audit and update this table; do not treat it as static.
references/hardening-playbook.md)In rough order of impact-per-effort for THIS project:
internal/pool (per-mimic lifetime
& byte budget), internal/ingress/dial.go (churn/replacement).check-ip (Gemini/OpenAI/ASN) before deploy;
clean/residential ranges; domain/GeoIP split-routing for sensitive services.Extreme-adversary note (full shutdown): during Iran's total "international internet" shutdowns only white-listed IPs stay reachable. Plan for it: a domestic-CDN-fronted path, or a foreign IP/port pairing that lands on an allow-listed edge, is the only thing that survives — no amount of DPI evasion helps when the pipe itself is cut.
The user's goal is no speed/quality loss AND no blocking. For every recommendation, quantify the cost:
Never recommend a stealth change without naming what it costs and how to verify it was worth it (before/after capture + a real speedtest through the tunnel).
© hedioum, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .claude/skills/censorship-audit of hedioum/Hedioum-Pool-Tunnel.
Open the folder on GitHubat commit c50f868
Censorship Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Censorship Audit this skillhedioum/Hedioum-Pool-Tunnel | 139 | — | ~4.9k | Automated safety check: Pass | GPL-3.0 | |
| Deploy Observabilityaliyun/alibabacloud-observability-mcp-server | 166 | — | ~2.6k | Automated safety check: Notes | None | |
| Devinggo Generatorhuagelong/devinggo | 122 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Shopware CLI Dockershopware/shopware-cli | 124 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Deployment and CI/CD Patternsaffaan-m/ECC | 277k | 6 repos | ~2.8k | Automated safety check: Pass | MIT | |
| Educates Upgrade Goeducates/educates-training-platform | 161 | — | ~1.4k | Automated safety check: Notes | Apache-2.0 |
aliyun/alibabacloud-observability-mcp-server
Deploy, start, and update the Alibaba Cloud Observability MCP Server (阿里云可观测 MCP Server).
huagelong/devinggo
DevingGo 代码生成器 CLI 工具集。当用户需要生成 CRUD 代码、创建模块、管理 Worker 任务、 导入导出模块、或需要快速搭建后端/前端代码时使用。适用于任何涉及代码生成、模块管理、 数据库表对应的前后端代码生成的场景。
shopware/shopware-cli
A skill your agent uses when working on Docker-backed Shopware projects and needing to run Shopware or Symfony CLI commands, interact with project services or databases, start or stop the…
affaan-m/ECC
Covers rolling, blue-green and canary deployments, multi-stage Dockerfiles, a GitHub Actions pipeline, health checks and production readiness for web apps.
educates/educates-training-platform
Upgrade the Go version across the entire educates-training-platform project.
Cod-e-Codes/marchat
Prepares marchat releases: version bumps, CHANGELOG, packaging checksums, GitHub Actions release workflow, and Docker tags.
Categories
Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would. Censorship Audit is an agent skill from hedioum/Hedioum-Pool-Tunnel. Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would.
Censorship Audit fits situations like: the task involves filtering resistance; DPI/SNI/JA3 evasion; tunnel footprint/traces; why did this server get blocked.
Run `npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a claude-code`. Or copy the skill folder (.claude/skills/censorship-audit in hedioum/Hedioum-Pool-Tunnel) into .claude/skills/censorship-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a codex`. Or copy the skill folder (.claude/skills/censorship-audit in hedioum/Hedioum-Pool-Tunnel) into .agents/skills/censorship-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hedioum/Hedioum-Pool-Tunnel --skill censorship-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/censorship-audit, .gemini/skills/censorship-audit, .github/skills/censorship-audit and .opencode/skills/censorship-audit in your project.
Going by SKILL.md and its folder, Censorship Audit needs the command-line tools its instructions call (openssl).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Censorship Audit is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Censorship Audit: Deploy Observability (aliyun/alibabacloud-observability-mcp-server, 166 stars), Devinggo Generator (huagelong/devinggo, 122 stars), Shopware CLI Docker (shopware/shopware-cli, 124 stars) and Deployment and CI/CD Patterns (affaan-m/ECC, 277k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hedioum (a GitHub organization) maintains it in hedioum/Hedioum-Pool-Tunnel, which has 139 GitHub stars. The repository was last updated on August 19, 2026.
Source: hedioum/Hedioum-Pool-Tunnel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.