Reverse Proxy
sickn33/agentic-awesome-skills
Configure nginx and Traefik as reverse proxies. An agent skill from sickn33/agentic-awesome-skills.
Set up Caddy on a server so any local port is reachable at https://<port.<domain/, and two-letter or named labels like https://ui.<domain/ map to ports too, with certificates issued on demand and…
$ npx skills add koolamusic/claudefiles --skill wildcard-proxy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install koolamusic/claudefiles wildcard-proxy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/koolamusic/claudefiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wildcard-proxy .claude/skills/wildcard-proxy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wildcard-proxy" agent skill from https://github.com/koolamusic/claudefiles/tree/main/skills/wildcard-proxy into .claude/skills/wildcard-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wildcard-proxy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/koolamusic/claudefiles/tree/main/skills/wildcard-proxyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add koolamusic/claudefiles --skill wildcard-proxy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install koolamusic/claudefiles wildcard-proxy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/koolamusic/claudefiles.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/wildcard-proxy .agents/skills/wildcard-proxy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wildcard-proxy" agent skill from https://github.com/koolamusic/claudefiles/tree/main/skills/wildcard-proxy into .agents/skills/wildcard-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wildcard-proxy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add koolamusic/claudefiles --skill wildcard-proxy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install koolamusic/claudefiles wildcard-proxy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/koolamusic/claudefiles.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/wildcard-proxy .cursor/skills/wildcard-proxy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wildcard-proxy" agent skill from https://github.com/koolamusic/claudefiles/tree/main/skills/wildcard-proxy into .cursor/skills/wildcard-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wildcard-proxy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/koolamusic/claudefiles.git --path skills/wildcard-proxy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add koolamusic/claudefiles --skill wildcard-proxy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install koolamusic/claudefiles wildcard-proxy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/koolamusic/claudefiles.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/wildcard-proxy .gemini/skills/wildcard-proxy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wildcard-proxy" agent skill from https://github.com/koolamusic/claudefiles/tree/main/skills/wildcard-proxy into .gemini/skills/wildcard-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wildcard-proxy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install koolamusic/claudefiles wildcard-proxyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add koolamusic/claudefiles --skill wildcard-proxy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/koolamusic/claudefiles.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/wildcard-proxy .github/skills/wildcard-proxy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wildcard-proxy" agent skill from https://github.com/koolamusic/claudefiles/tree/main/skills/wildcard-proxy into .github/skills/wildcard-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wildcard-proxy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add koolamusic/claudefiles --skill wildcard-proxy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install koolamusic/claudefiles wildcard-proxy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/koolamusic/claudefiles.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/wildcard-proxy .opencode/skills/wildcard-proxy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wildcard-proxy" agent skill from https://github.com/koolamusic/claudefiles/tree/main/skills/wildcard-proxy into .opencode/skills/wildcard-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wildcard-proxy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wildcard-proxySet up Caddy on a server so any local port is reachable at https://<port.<domain/, and two-letter or named labels like https://ui.<domain/ map to ports too, with certificates issued on demand and…
Wildcard Proxy is an agent skill from koolamusic/claudefiles. Set up Caddy on a server so any local port is reachable at https://<port.<domain/, and two-letter or named labels like https://ui.<domain/ map to ports too, with certificates issued on demand and gated so only routed hostnames get one. Use when the user says 'set up the wildcard proxy', 'port routing on this server', 'configure caddy so ports get subdomains', 'add a short name for port N', 'what port is ab', or is preparing a new server to expose local services by port.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files.
The repository describes itself as: A minimal catalog of my favourite skills for working with claude. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8a20283. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Wildcard Proxy loads about 2k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 123 tokens; SKILL.md has 884 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
nternet and not held by another server: `sudo ss -tlnp '( sport = :80 or sport = :443 )'`.sudo cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak-$(date +%F)sudo install -m 644 /tmp/wildcard-proxy.caddy /etc/caddy/wildcard-proxy.caddysudo cp -n wildcard-proxy.names /etc/caddy/wildcard-proxy.namessudo caddy validate --config /etc/caddy/Caddyfile --adapter caddyfilesudo systemctl reload caddyAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from koolamusic/claudefiles at commit 8a20283, republished under its MIT licence (© koolamusic). 884 words, ~1,956 tokens.
.claude/skills/wildcard-proxy/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.One Caddy config, installed once per server, that routes https://<label>.<domain>/ to 127.0.0.1:<port>. After install, exposing a service is just binding it to a loopback port. A short name is one line in a names file.
Checked in this order; first match wins.
| Label | Rule | Example |
|---|---|---|
| short name | listed in wildcard-proxy.names | ui → 4001 |
| port number | matches the allowed port regex | 4012 → 4012 |
| any two letters | 1 + two-digit alphabet position of each letter (a=00 … z=25) | ab → 10001, hz → 10725, zz → 12525 |
The computed range is 10000–12525. Port for letters xy = 10000 + 100·pos(x) + pos(y). A short name overrides that name's computed port: ui would otherwise be 12008.
Anything else (abc, a1, 3000 outside the ranges, deeper subdomains) gets no certificate and no route.
| Placeholder | Meaning | Default |
|---|---|---|
{{DOMAIN}} | the wildcard parent, e.g. host.example.net | ask the user |
{{DOMAIN_RE}} | same, dots escaped | derived |
{{PORT_RE}} | allowed numeric labels, as regex alternatives | 40[0-9][0-9]|80[0-9][0-9] (4000–4099, 8000–8099) |
{{ASK_PORT}} | loopback port for the certificate gate | 5555 |
Use [0-9][0-9], not [0-9]{2}, in PORT_RE. Caddyfile braces look like placeholders.
Caddy v2 installed and running as a systemd service: caddy version, systemctl is-active caddy.
Wildcard DNS: *.{{DOMAIN}} resolves to this server. Check with a label nobody has used: dig +short zq.{{DOMAIN}} should print the server's public IP (curl -4 -s ifconfig.me; also check dig +short AAAA if the server has IPv6).
Ports 80 and 443 reachable from the internet and not held by another server: sudo ss -tlnp '( sport = :80 or sport = :443 )'.
No other on_demand_tls block in /etc/caddy/Caddyfile. Caddy allows one ask endpoint. If one exists, stop and ask the user. Merging two gates is a design decision. The exception is an older inline version of this same config: replace it with the import, and keep the static sites.
ASK_PORT free: ss -tln | grep ':{{ASK_PORT}} ' prints nothing, or only Caddy itself when migrating an older version of this config.
Nothing private already listening on a routable port. After install, anything bound to loopback on a routed port is public. Before install, list what is already there:
ss -tlnp | awk 'NR>1{n=split($4,a,":"); p=a[n]; if ((p>=4000&&p<=4099)||(p>=8000&&p<=8099)||(p>=10000&&p<=12525&&p%100<=25&&int(p/100)%100<=25)) print $4, $6}'Show the user every hit and confirm each one is meant to be public. Default ports in the computed range include memcached's 11211 (ml) and Webmin's 10000 (aa).
Templates are in references/ beside this file.
1. Back up the live config.
sudo cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak-$(date +%F)2. Render the site file. From this skill's references/ directory:
DOMAIN=host.example.net
DOMAIN_RE=$(printf '%s' "$DOMAIN" | sed 's/\./\\\\./g')
sed -e "s/{{DOMAIN}}/$DOMAIN/g" -e "s/{{DOMAIN_RE}}/$DOMAIN_RE/g" \
-e 's/{{PORT_RE}}/40[0-9][0-9]|80[0-9][0-9]/g' -e 's/{{ASK_PORT}}/5555/g' \
wildcard-proxy.caddy > /tmp/wildcard-proxy.caddyConfirm no placeholder survived: grep -c '{{' /tmp/wildcard-proxy.caddy prints 0. Confirm the regex line reads host\.example\.net, with single backslashes.
3. Place both files. Don't overwrite an existing names file. It holds the user's names.
sudo install -m 644 /tmp/wildcard-proxy.caddy /etc/caddy/wildcard-proxy.caddy
sudo cp -n wildcard-proxy.names /etc/caddy/wildcard-proxy.names4. Wire it into the main Caddyfile. The global options block must be the first thing in the file. Add the on_demand_tls lines to it, creating the block if absent, and put the import anywhere after:
{
on_demand_tls {
ask http://127.0.0.1:5555/ask
}
}
import wildcard-proxy.caddyOn a fresh install, remove the packaged welcome-page :80 { … } block. It catches every plain-HTTP request.
5. Validate, then reload. Never reload an unvalidated config.
sudo caddy validate --config /etc/caddy/Caddyfile --adapter caddyfilesudo systemctl reload caddyGate — every routed label returns 200, everything else 403:
for l in 4012 ab zz 3000 abc; do printf '%s %s\n' $l "$(curl -s -o /dev/null -w '%{http_code}' "http://127.0.0.1:5555/ask?domain=$l.$DOMAIN")"; doneExpected: 4012 200, ab 200, zz 200, 3000 403, abc 403.
Gate is loopback-only — ss -tln | grep ':5555 ' shows 127.0.0.1:5555, not *:5555.
End to end — serve something on a loopback port and fetch it publicly:
python3 -m http.server 4012 --bind 127.0.0.1curl -s -o /dev/null -w '%{http_code}\n' https://4012.$DOMAIN/200 means it works. The first request to a new hostname triggers certificate issuance and can fail once with 000. Wait a few seconds and retry once before diagnosing.
Append <label> <port> to /etc/caddy/wildcard-proxy.names. Labels use lowercase letters, digits, and hyphens. Then validate and reload as in install step 5. Check that the label returns 200 from the gate.
To answer "what port is xy": check the names file first, then compute 10000 + 100·pos(x) + pos(y).
127.0.0.1, never 0.0.0.0. Caddy must be the only way in. A 0.0.0.0 bind exposes the service on the raw IP without TLS.ss -tln. Don't trust a remembered list.cloud.example.net { reverse_proxy 127.0.0.1:4040 } means 4040 is taken even though it matches the range. Grep the Caddyfile for reverse_proxy 127.0.0.1: before choosing.x.{{DOMAIN}} wins over the wildcard. That's intended, but it means the names file doesn't control that label.map quirks the template works around. Do not "simplify" these away:1{wp_da}{wp_db} as a map output stays literal, so the computed port is built inside reverse_proxy.01 becomes 1, so ab dials port 101. The alphabet digits stay quoted.{labels.N}. Label indices shift with domain depth.© koolamusic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in skills/wildcard-proxy of koolamusic/claudefiles.
Open the folder on GitHubat commit 8a20283
Wildcard Proxy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Wildcard Proxy this skillkoolamusic/claudefiles | 130 | — | ~2k | Automated safety check: Notes | MIT | |
| Reverse Proxysickn33/agentic-awesome-skills | 47k | 2 repos | ~2.8k | Automated safety check: Notes | MIT | |
| Proxiesoxylabs/agent-skills | 875 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Saleor Port Changessaleor/saleor | 23k | — | ~969 | Automated safety check: Pass | BSD-3-Clause | |
| OmniRoute Proxy Settingsdiegosouzapw/OmniRoute | 75k | — | ~207 | Automated safety check: Pass | MIT | |
| Iron Proxy Gateway for NanoClawnanocoai/nanoclaw | 31k | — | ~4.6k | Automated safety check: Notes | MIT |
sickn33/agentic-awesome-skills
Configure nginx and Traefik as reverse proxies. An agent skill from sickn33/agentic-awesome-skills.
oxylabs/agent-skills
Oxylabs proxy networks: Residential, Mobile, shared Datacenter/ISP, and Dedicated Datacenter/ISP proxies with geo-targeting, IP rotation, session persistence, and port-based sticky IPs.
saleor/saleor
Forward-ports or backports a single PR or branch onto the currently checked-out Saleor branch, handling GraphQL version markers and migration numbering along the way.
diegosouzapw/OmniRoute
Configure HTTP/HTTPS/SOCKS proxies for upstream provider requests. Set per-provider or global proxy rules, test connectivity, and manage proxy rotation.
nanocoai/nanoclaw
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
hashgraph-online/awesome-codex-plugins
Make an existing single-player web game multiplayer in a Homie studio.
koolamusic/claudefiles
A skill your agent uses when asked to explain a topic, codebase, process, or document in a specific output format — plain language or Simplified Technical English (STE, in the style of ASD-STE100…
koolamusic/claudefiles
Record silent product demos on this machine: a paced Playwright browser walkthrough of a web app or docs site, or a scripted asciinema terminal session against an API, rendered to mp4 with numbered…
koolamusic/claudefiles
Transform a workflow description into affordance tables showing UI and Code affordances with their wiring.
koolamusic/claudefiles
Turn the current session into a chief-of-staff thread that runs a war room of three role slots — surveyor, executor, auditor — and routes per-branch work to durable, reusable child agents.
koolamusic/claudefiles
A skill your agent uses when a user completes a phase, sprint, milestone, or meaningful unit of work and needs a retrospective.
koolamusic/claudefiles
Guide for creating effective skills. An agent skill from koolamusic/claudefiles.
Set up Caddy on a server so any local port is reachable at https://<port.<domain/, and two-letter or named labels like https://ui.<domain/ map to ports too, with certificates issued on demand and…. Wildcard Proxy is an agent skill from koolamusic/claudefiles.<domain/ map to ports too, with certificates issued on demand and gated so only routed hostnames get one.
Wildcard Proxy fits situations like: the user says set up the wildcard proxy; port routing on this server; configure caddy so ports get subdomains; add a short name for port N.
Run `npx skills add koolamusic/claudefiles --skill wildcard-proxy -a claude-code`. Or copy the skill folder (skills/wildcard-proxy in koolamusic/claudefiles) into .claude/skills/wildcard-proxy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add koolamusic/claudefiles --skill wildcard-proxy -a codex`. Or copy the skill folder (skills/wildcard-proxy in koolamusic/claudefiles) into .agents/skills/wildcard-proxy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add koolamusic/claudefiles --skill wildcard-proxy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wildcard-proxy, .gemini/skills/wildcard-proxy, .github/skills/wildcard-proxy and .opencode/skills/wildcard-proxy in your project.
Going by SKILL.md and its folder, Wildcard Proxy needs the command-line tools its instructions call (curl and python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Wildcard Proxy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 581 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Wildcard Proxy: Reverse Proxy (sickn33/agentic-awesome-skills, 47k stars), Proxies (oxylabs/agent-skills, 875 stars), Saleor Port Changes (saleor/saleor, 23k stars) and OmniRoute Proxy Settings (diegosouzapw/OmniRoute, 75k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
koolamusic (a GitHub user) maintains it in koolamusic/claudefiles, which has 130 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 10, 2026.
Source: koolamusic/claudefiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.