Kubeshark KFL2 Filter Reference
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
Systematic approach to diagnosing and resolving SSL/proxy connectivity issues with restricted websites
$ npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install HKUDS/OpenSpace ssl-proxy-troubleshoot-fb786c --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c .claude/skills/ssl-proxy-troubleshoot-fb786c && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ssl-proxy-troubleshoot-fb786c" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c into .claude/skills/ssl-proxy-troubleshoot-fb786c/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssl-proxy-troubleshoot-fb786c", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786cType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install HKUDS/OpenSpace ssl-proxy-troubleshoot-fb786c --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c .agents/skills/ssl-proxy-troubleshoot-fb786c && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ssl-proxy-troubleshoot-fb786c" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c into .agents/skills/ssl-proxy-troubleshoot-fb786c/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssl-proxy-troubleshoot-fb786c", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install HKUDS/OpenSpace ssl-proxy-troubleshoot-fb786c --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c .cursor/skills/ssl-proxy-troubleshoot-fb786c && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ssl-proxy-troubleshoot-fb786c" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c into .cursor/skills/ssl-proxy-troubleshoot-fb786c/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssl-proxy-troubleshoot-fb786c", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/HKUDS/OpenSpace.git --path benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install HKUDS/OpenSpace ssl-proxy-troubleshoot-fb786c --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c .gemini/skills/ssl-proxy-troubleshoot-fb786c && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ssl-proxy-troubleshoot-fb786c" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c into .gemini/skills/ssl-proxy-troubleshoot-fb786c/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssl-proxy-troubleshoot-fb786c", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install HKUDS/OpenSpace ssl-proxy-troubleshoot-fb786cInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .github/skills && cp -r skills-src/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c .github/skills/ssl-proxy-troubleshoot-fb786c && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ssl-proxy-troubleshoot-fb786c" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c into .github/skills/ssl-proxy-troubleshoot-fb786c/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssl-proxy-troubleshoot-fb786c", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install HKUDS/OpenSpace ssl-proxy-troubleshoot-fb786c --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HKUDS/OpenSpace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c .opencode/skills/ssl-proxy-troubleshoot-fb786c && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ssl-proxy-troubleshoot-fb786c" agent skill from https://github.com/HKUDS/OpenSpace/tree/main/benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c into .opencode/skills/ssl-proxy-troubleshoot-fb786c/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ssl-proxy-troubleshoot-fb786c", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ssl-proxy-troubleshoot-fb786cSystematic approach to diagnosing and resolving SSL/proxy connectivity issues with restricted websites
Ssl Proxy Troubleshoot Fb786c is an agent skill from HKUDS/OpenSpace. Systematic approach to diagnosing and resolving SSL/proxy connectivity issues with restricted websites
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in DevOps & Cloud, covering Cloud networking. The repository describes itself as: "OpenSpace: The Skill Management Layer for AI Agents" -- https://open-space.cloud/. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3827781. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlopensslFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
target-domain.govtarget-domain.state.il.usgoogle.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ssl Proxy Troubleshoot Fb786c loads about 1.6k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 381 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from HKUDS/OpenSpace at commit 3827781, republished under its MIT licence (© HKUDS). 381 words, ~1,571 tokens.
.claude/skills/ssl-proxy-troubleshoot-fb786c/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.This skill provides a structured workflow for diagnosing and resolving network connectivity issues when accessing government websites, corporate portals, or other restricted domains that commonly exhibit SSL certificate problems, proxy requirements, or access restrictions.
Apply this skill when:
Test basic connectivity before attempting complex solutions:
# Test DNS resolution
nslookup target-domain.gov
dig target-domain.gov
# Test basic TCP connectivity
timeout 5 bash -c 'cat < /dev/null > /dev/tcp/target-domain.gov/443' && echo "Port 443 open" || echo "Port 443 closed"
# Test with curl (verbose)
curl -v https://target-domain.gov 2>&1 | head -50If SSL errors occur, diagnose the certificate issue:
# Check certificate details
openssl s_client -connect target-domain.gov:443 -servername target-domain.gov 2>/dev/null | openssl x509 -noout -dates -subject -issuer
# Test with different SSL versions
curl --tlsv1.2 -v https://target-domain.gov
curl --tlsv1.3 -v https://target-domain.gov
# Try disabling verification (testing only)
curl -k https://target-domain.govTest various proxy configurations:
# Try without proxy
curl --noproxy "*" https://target-domain.gov
# Try with system proxy
curl -x http://proxy.example.com:8080 https://target-domain.gov
# Try explicit no-proxy for .gov domains
export no_proxy=".gov,.mil,.edu"
curl https://target-domain.gov
# Test with different proxy protocols
curl -x http://proxy:8080 https://target-domain.gov
curl -x https://proxy:8080 https://target-domain.gov
curl -x socks5://proxy:1080 https://target-domain.govTest alternative access methods:
# Try HTTP instead of HTTPS
curl http://target-domain.gov
# Try alternative ports
curl https://target-domain.gov:8443
curl https://target-domain.gov:4443
# Try www subdomain variation
curl https://www.target-domain.gov
# Try alternative domain extensions
curl https://target-domain.state.il.usSome sites block automated access:
# Use browser user-agent
curl -A "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" https://target-domain.gov
# Add common headers
curl -H "Accept: text/html" -H "Accept-Language: en-US" https://target-domain.gov
# Include referer header
curl -e "https://www.google.com/" https://target-domain.govIf curl fails, try Python with different configurations:
import requests
from requests.adapters import HTTPAdapter
# Disable SSL verification (testing only)
session = requests.Session()
session.verify = False
session.mount('https://', HTTPAdapter())
try:
response = session.get('https://target-domain.gov', timeout=30)
print(f"Status: {response.status_code}")
except Exception as e:
print(f"Error: {e}")
# Try with custom SSL context
import ssl
context = ssl.create_default_context()
context.check_hostname = False
context.verify_mode = ssl.CERT_NONEWhen primary data sources remain inaccessible after exhausting troubleshooting:
When access fails after systematic troubleshooting:
## Access Attempt Summary
- **Target**: [domain]
- **Methods Tried**: [list all approaches]
- **Errors Encountered**: [specific error messages]
- **Time Spent**: [duration]
- **Recommendation**: [alternative sources or next steps]SSL Error?
├── Yes → Try curl -k (test only)
│ ├── Works → Document SSL issue, proceed with verification disabled
│ └── Fails → Continue diagnostics
│
Proxy Issue?
├── Suspected → Try --noproxy "*"
│ ├── Works → Configure no_proxy for target domain
│ └── Fails → Try explicit proxy settings
│
Timeout/Refused?
├── Yes → Try HTTP instead of HTTPS
│ Try alternative ports
│ Try www subdomain
│ └── All fail → Implement fallback strategies
│
All Methods Fail?
└── Implement fallback strategies and document attemptsSecurity Considerations: Disabling SSL verification should only be used for diagnosis in trusted environments. Never use in production without understanding the risks.
Rate Limiting: Add delays between requests to avoid triggering rate limits or IP blocks.
Documentation: Always document which methods were tried and their results for future reference.
Iteration Limit: If 5+ distinct approaches fail, pivot to fallback strategies rather than continuing to iterate on the same blocked endpoint.
Legal Compliance: Ensure all access attempts comply with terms of service and applicable laws.
This troubleshooting workflow is complete when:
© HKUDS, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c of HKUDS/OpenSpace.
Open the folder on GitHubat commit 3827781
Ssl Proxy Troubleshoot Fb786c next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ssl Proxy Troubleshoot Fb786c this skillHKUDS/OpenSpace | 7.8k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Kubeshark KFL2 Filter Referencekubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Nginx To Higress Migrationhigress-group/higress | 9.5k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Bfe Rd Workflowbfenetworks/bfe | 6.3k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress | 5.1k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| NGINX Ingress Policy CRD Guidenginx/kubernetes-ingress | 5.1k | — | ~2k | Automated safety check: Pass | Apache-2.0 |
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
higress-group/higress
Migrate from ingress-nginx to Higress in Kubernetes environments.
bfenetworks/bfe
引导用户在 bfe 代码库中完成一次完整的功能研发流程,包括需求对齐、文档修改、代码实现、集成测试与回归验证. An agent skill from bfenetworks/bfe.
nginx/kubernetes-ingress
Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.
nginx/kubernetes-ingress
Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.
erfnzdeh/arvancloud-agent-skill
Drives ArvanCloud's REST APIs for CDN, DNS, cloud servers, object storage and more, with helper scripts for calls, account inventory and certificates.
HKUDS/OpenSpace
Walks through producing a master audio track plus stems in Python, from checking a reference file and timing sections by BPM to effects, a zip archive and final verification.
HKUDS/OpenSpace
Handle cascading data retrieval tool failures by falling back to embedded knowledge generation
HKUDS/OpenSpace
Gives an agent a workaround when its code-execution sandbox keeps failing: save the Python script to a file and run it through the shell instead.
HKUDS/OpenSpace
A recovery routine for agents whose sandboxed code runner keeps failing: save the Python script to disk, then run it through the shell and read the output.
HKUDS/OpenSpace
Fallback ladder for failed sandboxed code runs, plus the habit of fixing the working directory first so generated files land in the right place.
HKUDS/OpenSpace
Fallback workflow for executing Python code when executecodesandbox fails repeatedly
Categories
Systematic approach to diagnosing and resolving SSL/proxy connectivity issues with restricted websites. Ssl Proxy Troubleshoot Fb786c is an agent skill from HKUDS/OpenSpace.
Ssl Proxy Troubleshoot Fb786c fits situations like: tasks that involve Cloud networking.
Run `npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a claude-code`. Or copy the skill folder (benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c in HKUDS/OpenSpace) into .claude/skills/ssl-proxy-troubleshoot-fb786c in your project. Claude Code loads it when a task matches its description.
Run `npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a codex`. Or copy the skill folder (benchmarks/gdpval/skills/ssl-proxy-troubleshoot-fb786c in HKUDS/OpenSpace) into .agents/skills/ssl-proxy-troubleshoot-fb786c in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HKUDS/OpenSpace --skill ssl-proxy-troubleshoot-fb786c -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ssl-proxy-troubleshoot-fb786c, .gemini/skills/ssl-proxy-troubleshoot-fb786c, .github/skills/ssl-proxy-troubleshoot-fb786c and .opencode/skills/ssl-proxy-troubleshoot-fb786c in your project.
Going by SKILL.md and its folder, Ssl Proxy Troubleshoot Fb786c needs the command-line tools its instructions call (curl and openssl). Our summary lists: Python 3.
SKILL.md names 3 domains. In commands or code: target-domain.gov, target-domain.state.il.us and google.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ssl Proxy Troubleshoot Fb786c is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ssl Proxy Troubleshoot Fb786c: Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), Bfe Rd Workflow (bfenetworks/bfe, 6.3k stars) and NGINX Ingress Controller Feature Checklists (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
HKUDS (a GitHub organization) maintains it in HKUDS/OpenSpace, which has 7,754 GitHub stars. The repository holds 199 skills in this directory. The repository was last updated on August 12, 2026.
Source: HKUDS/OpenSpace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.