Agent skill

Wildcard Proxy

by koolamusic in koolamusic/claudefiles

Set up Caddy on a server so any local port is reachable at https://<port.<domain/, and two-letter or named labels like https://ui.<domain/ map to ports too, with certificates issued on demand and…

MITAuto-check: notes

Install Wildcard Proxy

skills CLI
$ npx skills add koolamusic/claudefiles --skill wildcard-proxy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install koolamusic/claudefiles wildcard-proxy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/koolamusic/claudefiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wildcard-proxy .claude/skills/wildcard-proxy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wildcard-proxy
GitHub stars
130
Token cost
~2k tokens
SKILL.md length
884 words
Files
3 (incl. references)
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Set up Caddy on a server so any local port is reachable at https://<port.<domain/, and two-letter or named labels like https://ui.<domain/ map to ports too, with certificates issued on demand and…

  • Works in 6 steps: Caddy v2 installed and running as a… → Wildcard DNS: *.{{DOMAIN}} resolves to… → Ports 80 and 443 reachable from the… → …
  • The user says set up the wildcard proxy
  • SKILL.md covers How a label becomes a port, Inputs, Prerequisites — check before… and Install, plus 4 more sections
  • Calls curl and python3

What it does

Wildcard Proxy is an agent skill from koolamusic/claudefiles. Set up Caddy on a server so any local port is reachable at https://<port.<domain/, and two-letter or named labels like https://ui.<domain/ map to ports too, with certificates issued on demand and gated so only routed hostnames get one. Use when the user says 'set up the wildcard proxy', 'port routing on this server', 'configure caddy so ports get subdomains', 'add a short name for port N', 'what port is ab', or is preparing a new server to expose local services by port.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files.

The repository describes itself as: A minimal catalog of my favourite skills for working with claude. The licence is MIT.

When your agent uses it

  • The user says set up the wildcard proxy
  • Port routing on this server
  • Configure caddy so ports get subdomains
  • Add a short name for port N

Example prompts

  • “set up the wildcard proxy”
  • “port routing on this server”
  • “configure caddy so ports get subdomains”
  • “/wildcard-proxy”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Caddy v2 installed and running as a systemd service: caddy version, systemctl is-active caddy.
  2. Wildcard DNS: *.{{DOMAIN}} resolves to this server. Check with a label nobody has used: dig +short zq.{{DOMAIN}} should print the server's…
  3. Ports 80 and 443 reachable from the internet and not held by another server: sudo ss -tlnp '( sport = :80 or sport = :443 )'.
  4. No other on_demand_tls block in /etc/caddy/Caddyfile. Caddy allows one ask endpoint. If one exists, stop and ask the user. Merging two…
  5. ASK_PORT free: ss -tln | grep ':{{ASK_PORT}} ' prints nothing, or only Caddy itself when migrating an older version of this config.
  6. Nothing private already listening on a routable port. After install, anything bound to loopback on a routed port is public. Before…

What it can do on your machine

Read from SKILL.md and the folder at commit 8a20283. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wildcard Proxy loads about 2k tokens when it runs, and up to ~2.5k if it reads all its reference files. Until then it costs about 123 tokens; SKILL.md has 884 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:39
    nternet and not held by another server: `sudo ss -tlnp '( sport = :80 or sport = :443 )'`.
  • NoteRuns commands with sudoSKILL.md:57
    sudo cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak-$(date +%F)
  • NoteRuns commands with sudoSKILL.md:75
    sudo install -m 644 /tmp/wildcard-proxy.caddy /etc/caddy/wildcard-proxy.caddy
  • NoteRuns commands with sudoSKILL.md:76
    sudo cp -n wildcard-proxy.names /etc/caddy/wildcard-proxy.names
  • NoteRuns commands with sudoSKILL.md:96
    sudo caddy validate --config /etc/caddy/Caddyfile --adapter caddyfile
  • NoteRuns commands with sudoSKILL.md:100
    sudo systemctl reload caddy

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from koolamusic/claudefiles at commit 8a20283, republished under its MIT licence (© koolamusic). 884 words, ~1,956 tokens.

Download SKILL.mdSave it as .claude/skills/wildcard-proxy/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
wildcard-proxy
description
Set up Caddy on a server so any local port is reachable at https://<port>.<domain>/, and two-letter or named labels like https://ui.<domain>/ map to ports too, with certificates issued on demand and gated so only routed hostnames get one. Use when the user says 'set up the wildcard proxy', 'port routing on this server', 'configure caddy so ports get subdomains', 'add a short name for port N', 'what port is ab', or is preparing a new server to expose local services by port.

Wildcard Proxy

One Caddy config, installed once per server, that routes https://<label>.<domain>/ to 127.0.0.1:<port>. After install, exposing a service is just binding it to a loopback port. A short name is one line in a names file.

How a label becomes a port

Checked in this order; first match wins.

LabelRuleExample
short namelisted in wildcard-proxy.namesui → 4001
port numbermatches the allowed port regex4012 → 4012
any two letters1 + two-digit alphabet position of each letter (a=00 … z=25)ab → 10001, hz → 10725, zz → 12525

The computed range is 10000–12525. Port for letters xy = 10000 + 100·pos(x) + pos(y). A short name overrides that name's computed port: ui would otherwise be 12008.

Anything else (abc, a1, 3000 outside the ranges, deeper subdomains) gets no certificate and no route.

Inputs

PlaceholderMeaningDefault
{{DOMAIN}}the wildcard parent, e.g. host.example.netask the user
{{DOMAIN_RE}}same, dots escapedderived
{{PORT_RE}}allowed numeric labels, as regex alternatives40[0-9][0-9]|80[0-9][0-9] (4000–4099, 8000–8099)
{{ASK_PORT}}loopback port for the certificate gate5555

Use [0-9][0-9], not [0-9]{2}, in PORT_RE. Caddyfile braces look like placeholders.

Prerequisites — check before installing

  1. Caddy v2 installed and running as a systemd service: caddy version, systemctl is-active caddy.

  2. Wildcard DNS: *.{{DOMAIN}} resolves to this server. Check with a label nobody has used: dig +short zq.{{DOMAIN}} should print the server's public IP (curl -4 -s ifconfig.me; also check dig +short AAAA if the server has IPv6).

  3. Ports 80 and 443 reachable from the internet and not held by another server: sudo ss -tlnp '( sport = :80 or sport = :443 )'.

  4. No other on_demand_tls block in /etc/caddy/Caddyfile. Caddy allows one ask endpoint. If one exists, stop and ask the user. Merging two gates is a design decision. The exception is an older inline version of this same config: replace it with the import, and keep the static sites.

  5. ASK_PORT free: ss -tln | grep ':{{ASK_PORT}} ' prints nothing, or only Caddy itself when migrating an older version of this config.

  6. Nothing private already listening on a routable port. After install, anything bound to loopback on a routed port is public. Before install, list what is already there:

    bash
    ss -tlnp | awk 'NR>1{n=split($4,a,":"); p=a[n]; if ((p>=4000&&p<=4099)||(p>=8000&&p<=8099)||(p>=10000&&p<=12525&&p%100<=25&&int(p/100)%100<=25)) print $4, $6}'

    Show the user every hit and confirm each one is meant to be public. Default ports in the computed range include memcached's 11211 (ml) and Webmin's 10000 (aa).

Install

Templates are in references/ beside this file.

1. Back up the live config.

bash
sudo cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak-$(date +%F)

2. Render the site file. From this skill's references/ directory:

bash
DOMAIN=host.example.net
DOMAIN_RE=$(printf '%s' "$DOMAIN" | sed 's/\./\\\\./g')
sed -e "s/{{DOMAIN}}/$DOMAIN/g" -e "s/{{DOMAIN_RE}}/$DOMAIN_RE/g" \
    -e 's/{{PORT_RE}}/40[0-9][0-9]|80[0-9][0-9]/g' -e 's/{{ASK_PORT}}/5555/g' \
    wildcard-proxy.caddy > /tmp/wildcard-proxy.caddy

Confirm no placeholder survived: grep -c '{{' /tmp/wildcard-proxy.caddy prints 0. Confirm the regex line reads host\.example\.net, with single backslashes.

3. Place both files. Don't overwrite an existing names file. It holds the user's names.

bash
sudo install -m 644 /tmp/wildcard-proxy.caddy /etc/caddy/wildcard-proxy.caddy
sudo cp -n wildcard-proxy.names /etc/caddy/wildcard-proxy.names

4. Wire it into the main Caddyfile. The global options block must be the first thing in the file. Add the on_demand_tls lines to it, creating the block if absent, and put the import anywhere after:

{
	on_demand_tls {
		ask http://127.0.0.1:5555/ask
	}
}

import wildcard-proxy.caddy

On a fresh install, remove the packaged welcome-page :80 { … } block. It catches every plain-HTTP request.

5. Validate, then reload. Never reload an unvalidated config.

bash
sudo caddy validate --config /etc/caddy/Caddyfile --adapter caddyfile
bash
sudo systemctl reload caddy
Show full SKILL.md (387 more words)Show less

Verify

Gate — every routed label returns 200, everything else 403:

bash
for l in 4012 ab zz 3000 abc; do printf '%s %s\n' $l "$(curl -s -o /dev/null -w '%{http_code}' "http://127.0.0.1:5555/ask?domain=$l.$DOMAIN")"; done

Expected: 4012 200, ab 200, zz 200, 3000 403, abc 403.

Gate is loopback-only — ss -tln | grep ':5555 ' shows 127.0.0.1:5555, not *:5555.

End to end — serve something on a loopback port and fetch it publicly:

bash
python3 -m http.server 4012 --bind 127.0.0.1
bash
curl -s -o /dev/null -w '%{http_code}\n' https://4012.$DOMAIN/

200 means it works. The first request to a new hostname triggers certificate issuance and can fail once with 000. Wait a few seconds and retry once before diagnosing.

Add a short name

Append <label> <port> to /etc/caddy/wildcard-proxy.names. Labels use lowercase letters, digits, and hyphens. Then validate and reload as in install step 5. Check that the label returns 200 from the gate.

To answer "what port is xy": check the names file first, then compute 10000 + 100·pos(x) + pos(y).

Rules for services behind it

  • Bind to 127.0.0.1, never 0.0.0.0. Caddy must be the only way in. A 0.0.0.0 bind exposes the service on the raw IP without TLS.
  • Scan before picking a port: ss -tln. Don't trust a remembered list.
  • Watch for static sites that share a port. A Caddyfile entry like cloud.example.net { reverse_proxy 127.0.0.1:4040 } means 4040 is taken even though it matches the range. Grep the Caddyfile for reverse_proxy 127.0.0.1: before choosing.
  • A static site block for x.{{DOMAIN}} wins over the wildcard. That's intended, but it means the names file doesn't control that label.
  • Everything is public and unauthenticated. The hostnames are guessable. Say so once before exposing anything sensitive.

Known limits

  • Certificate rate limits. About 900 hostnames can request a certificate: 200 numeric, 676 two-letter, plus names. Anyone who knows the scheme can trigger issuance for all of them and exhaust the CA's per-domain weekly limit, which blocks new certificates until it resets. Hostnames that already have certificates keep working. The full fix is a single wildcard certificate via the DNS challenge, which needs a Caddy build with the DNS provider's module. Offer it, don't do it unasked.
  • Caddy map quirks the template works around. Do not "simplify" these away:
    • Map outputs don't expand placeholders. 1{wp_da}{wp_db} as a map output stays literal, so the computed port is built inside reverse_proxy.
    • Map converts bare numeric outputs to integers. Unquoted 01 becomes 1, so ab dials port 101. The alphabet digits stay quoted.
    • The label is extracted by a regex on the full host, not {labels.N}. Label indices shift with domain depth.

© koolamusic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/wildcard-proxy of koolamusic/claudefiles.

  • SKILL.md
  • references/wildcard-proxy.caddy
  • references/wildcard-proxy.names

Open the folder on GitHubat commit 8a20283

Compare with similar skills

Wildcard Proxy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wildcard Proxy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wildcard Proxy this skillkoolamusic/claudefiles130—~2kAutomated safety check: NotesMIT
Reverse Proxysickn33/agentic-awesome-skills47k2 repos~2.8kAutomated safety check: NotesMIT
Proxiesoxylabs/agent-skills875—~1.7kAutomated safety check: PassMIT
Saleor Port Changessaleor/saleor23k—~969Automated safety check: PassBSD-3-Clause
OmniRoute Proxy Settingsdiegosouzapw/OmniRoute75k—~207Automated safety check: PassMIT
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT

Similar skills

  • Reverse Proxy

    sickn33/agentic-awesome-skills

    Configure nginx and Traefik as reverse proxies. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.8k tokens
    DevOps & CloudAuto-check: notes
  • Proxies

    oxylabs/agent-skills

    Oxylabs proxy networks: Residential, Mobile, shared Datacenter/ISP, and Dedicated Datacenter/ISP proxies with geo-targeting, IP rotation, session persistence, and port-based sticky IPs.

    875 GitHub stars~1.7k tokensUpdated 10 days ago
    Data & AnalyticsAuto-check passed
  • Saleor Port Changes

    saleor/saleor

    Forward-ports or backports a single PR or branch onto the currently checked-out Saleor branch, handling GraphQL version markers and migration numbering along the way.

    23k GitHub stars~969 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • OmniRoute Proxy Settings

    diegosouzapw/OmniRoute

    Configure HTTP/HTTPS/SOCKS proxies for upstream provider requests. Set per-provider or global proxy rules, test connectivity, and manage proxy rotation.

    75k GitHub stars~207 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Port

    hashgraph-online/awesome-codex-plugins

    Make an existing single-player web game multiplayer in a Homie studio.

    1.3k GitHub stars~3.6k tokensUpdated yesterday
    Game DevelopmentAuto-check passed

More from koolamusic/claudefiles

All 15 skills in this repo
  • Explainer Formats

    koolamusic/claudefiles

    A skill your agent uses when asked to explain a topic, codebase, process, or document in a specific output format — plain language or Simplified Technical English (STE, in the style of ASD-STE100…

    130 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Localframe

    koolamusic/claudefiles

    Record silent product demos on this machine: a paced Playwright browser walkthrough of a web app or docs site, or a scripted asciinema terminal session against an API, rendered to mp4 with numbered…

    130 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Breadboarding

    koolamusic/claudefiles

    Transform a workflow description into affordance tables showing UI and Code affordances with their wiring.

    130 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Orchestrator

    koolamusic/claudefiles

    Turn the current session into a chief-of-staff thread that runs a war room of three role slots — surveyor, executor, auditor — and routes per-branch work to durable, reusable child agents.

    130 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Retro

    koolamusic/claudefiles

    A skill your agent uses when a user completes a phase, sprint, milestone, or meaningful unit of work and needs a retrospective.

    130 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Skill Creator

    koolamusic/claudefiles

    Guide for creating effective skills. An agent skill from koolamusic/claudefiles.

    130 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Questions about Wildcard Proxy

What does Wildcard Proxy do?

Set up Caddy on a server so any local port is reachable at https://<port.<domain/, and two-letter or named labels like https://ui.<domain/ map to ports too, with certificates issued on demand and…. Wildcard Proxy is an agent skill from koolamusic/claudefiles.<domain/ map to ports too, with certificates issued on demand and gated so only routed hostnames get one.

When should I use Wildcard Proxy?

Wildcard Proxy fits situations like: the user says set up the wildcard proxy; port routing on this server; configure caddy so ports get subdomains; add a short name for port N.

How do I install Wildcard Proxy in Claude Code?

Run `npx skills add koolamusic/claudefiles --skill wildcard-proxy -a claude-code`. Or copy the skill folder (skills/wildcard-proxy in koolamusic/claudefiles) into .claude/skills/wildcard-proxy in your project. Claude Code loads it when a task matches its description.

How do I install Wildcard Proxy in Codex?

Run `npx skills add koolamusic/claudefiles --skill wildcard-proxy -a codex`. Or copy the skill folder (skills/wildcard-proxy in koolamusic/claudefiles) into .agents/skills/wildcard-proxy in your project. Codex loads it when a task matches its description.

Can I use Wildcard Proxy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add koolamusic/claudefiles --skill wildcard-proxy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wildcard-proxy, .gemini/skills/wildcard-proxy, .github/skills/wildcard-proxy and .opencode/skills/wildcard-proxy in your project.

What does Wildcard Proxy need to run?

Going by SKILL.md and its folder, Wildcard Proxy needs the command-line tools its instructions call (curl and python3). Our summary lists: Python 3.

Does Wildcard Proxy access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Wildcard Proxy safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Wildcard Proxy use?

Wildcard Proxy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wildcard Proxy use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 581 tokens, read only when the agent opens those files.

What are the alternatives to Wildcard Proxy?

Skills that share tags, products or a category with Wildcard Proxy: Reverse Proxy (sickn33/agentic-awesome-skills, 47k stars), Proxies (oxylabs/agent-skills, 875 stars), Saleor Port Changes (saleor/saleor, 23k stars) and OmniRoute Proxy Settings (diegosouzapw/OmniRoute, 75k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wildcard Proxy?

koolamusic (a GitHub user) maintains it in koolamusic/claudefiles, which has 130 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 10, 2026.

Source: koolamusic/claudefiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.