Monstermq Broker Config
vogler75/monster-mq
Guide for configuring, deploying, and operating the MonsterMQ broker.
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
$ npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nanocoai/nanoclaw add-iron-proxy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/add-iron-proxy .claude/skills/add-iron-proxy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "add-iron-proxy" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-iron-proxy into .claude/skills/add-iron-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-iron-proxy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-iron-proxyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nanocoai/nanoclaw add-iron-proxy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/add-iron-proxy .agents/skills/add-iron-proxy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "add-iron-proxy" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-iron-proxy into .agents/skills/add-iron-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-iron-proxy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nanocoai/nanoclaw add-iron-proxy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/add-iron-proxy .cursor/skills/add-iron-proxy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "add-iron-proxy" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-iron-proxy into .cursor/skills/add-iron-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-iron-proxy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nanocoai/nanoclaw.git --path .claude/skills/add-iron-proxy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nanocoai/nanoclaw add-iron-proxy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/add-iron-proxy .gemini/skills/add-iron-proxy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "add-iron-proxy" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-iron-proxy into .gemini/skills/add-iron-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-iron-proxy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nanocoai/nanoclaw add-iron-proxyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/add-iron-proxy .github/skills/add-iron-proxy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "add-iron-proxy" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-iron-proxy into .github/skills/add-iron-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-iron-proxy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nanocoai/nanoclaw add-iron-proxy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/add-iron-proxy .opencode/skills/add-iron-proxy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "add-iron-proxy" agent skill from https://github.com/nanocoai/nanoclaw/tree/main/.claude/skills/add-iron-proxy into .opencode/skills/add-iron-proxy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "add-iron-proxy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
add-iron-proxyInstalls or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.
NanoClaw gets an Iron Proxy gateway from this install routine. It copies a provider payload, including the proxy provider, its approval middleware, tests and agent guidance, into the normal NanoClaw source paths, registers the provider with a single import and installs the gRPC bridge dependencies with pnpm. NanoClaw core keeps ownership of approval storage, cards, clicks, authorization and timeouts.
Setup then pulls pinned images of the upstream Iron Control Rails console and its PostgreSQL database, runs them on a dedicated Docker network, creates a local operator account and registers this copy's proxy and principal through Iron's API. Credentials and encryption keys go to owner-only files under data/session-materials/iron-control, the database has its own persistent volume and no published port, and agents never get the console credentials or the database.
The folder is large, with a long file list that includes setup assets, a Go front proxy with security tests, credential-scope conformance cases, evals and a REMOVE.md file. It is a local installation only, and a refresh reuses the services and keys already recorded for that copy.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 66f0823. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Go and Shell, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
pnpmdockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm and docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Iron Proxy Gateway for NanoClaw loads about 4.6k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 2,256 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
W_GATEWAY_UNCREDENTIALED_READS=true` in `.env`, a GET or HEAD that sends no body or upgrade skips the card when no Iron`NANOCLAW_IRON_PROXY_PORT` in `.env` sets the internal proxy port (default `8080`). Setup uses the same value for the frAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from nanocoai/nanoclaw at commit 66f0823, republished under its MIT licence (© nanocoai). 2,256 words, ~4,576 tokens.
.claude/skills/add-iron-proxy/SKILL.md (or your agent's skills folder). This skill also uses 50 other files; get the full folder from GitHub.Install the official iron-control console and PostgreSQL alongside one central Iron Proxy. NanoClaw core supplies the generic gateway seam and human approval flow. Read docs/gateway-seam.md before changing the integration.
Use the bundled setup scripts and the source revisions in versions.json. The console is the upstream Rails application; its UI is not generated or copied into NanoClaw. This is a local Docker installation. Reuse this copy's recorded services and keys when refreshing it.
Copy the package's provider, approval middleware, tests, and agent guidance into their normal NanoClaw paths.
payload/src/gateway-providers/iron-proxy.ts -> src/gateway-providers/iron-proxy.ts
payload/src/gateway-providers/iron-proxy.test.ts -> src/gateway-providers/iron-proxy.test.ts
payload/src/gateway-providers/iron-proxy-allowlist.ts -> src/gateway-providers/iron-proxy-allowlist.ts
payload/src/gateway-providers/iron-proxy-local-model.ts -> src/gateway-providers/iron-proxy-local-model.ts
payload/src/gateway-providers/iron-proxy-local-model.test.ts -> src/gateway-providers/iron-proxy-local-model.test.ts
payload/src/gateway-providers/iron-proxy-approval.ts -> src/gateway-providers/iron-proxy-approval.ts
payload/src/gateway-providers/iron-proxy-approval.test.ts -> src/gateway-providers/iron-proxy-approval.test.ts
payload/src/gateway-providers/iron-proxy-credential-scope.ts -> src/gateway-providers/iron-proxy-credential-scope.ts
payload/src/gateway-providers/iron-proxy-credential-scope.test.ts -> src/gateway-providers/iron-proxy-credential-scope.test.ts
payload/src/gateway-providers/iron-proxy-transform.proto -> src/gateway-providers/iron-proxy-transform.proto
payload/container/skills/iron-proxy-gateway/SKILL.md -> container/skills/iron-proxy-gateway/SKILL.md
payload/container/skills/iron-proxy-gateway/instructions.md -> container/skills/iron-proxy-gateway/instructions.mdThe provider file makes the only product registration call. It declares idempotent sessions, typed runtime contributions, owned-resource cleanup, normalized approvals, network access, and agent guidance. NanoClaw core owns approval persistence, cards, clicks, authorization, and timeouts.
import './iron-proxy.js';@grpc/grpc-js@1.14.5
@grpc/proto-loader@0.8.1Setup pulls the pinned official Iron Control image and database image, starts them on a dedicated Docker network, creates a local operator account, and registers this copy's proxy and principal through Iron's API. It stores credentials and encryption keys in owner-only files under data/session-materials/iron-control/. The database has its own persistent volume and no published port. Neither the console credentials nor its database are mounted into agents.
The installer streams stage names and elapsed-time updates. Source downloads stop after two minutes, the image build after twenty minutes, and console startup after six minutes. It never opens a Git credential prompt. The proxy is built locally from the pinned public upstream source, so installation does not require a GitHub account or access to a private proxy image. The console and build dependencies use their pinned public images. On failure, fix the reported access or service issue and rerun setup; keep existing database volumes and encryption keys together. Raw subprocess output is not streamed because it can contain credentials.
Setup builds unmodified upstream Iron Proxy and a separate NanoClaw approval front in the same image. No Iron fork or source patch is used. The front is the only network-facing listener. It authenticates session identities, inspects each HTTP request inside HTTPS tunnels, checks the allowlist, and waits for an explicit approval before forwarding to Iron on 127.0.0.1:18080. Empty, malformed, rejected or timed-out decisions fail closed. Iron's own dial-time loopback and link-local deny rules prevent DNS aliases from reaching the internal backend. Managed control-plane updates only change Iron's credential transforms; they cannot remove the front's checks.
The front builds and runs the pinned OneCLI helper in gateway-compat/onecli-summary; do not add app-specific rules. Only method, host, path, response status, the resulting OneCLI summary and whether the request sends a body or upgrade reach the approval bridge. Raw bodies, authorization headers, query strings and Iron transform traces do not. The helper sees a bounded pre-injection body prefix; the full original stream is preserved. Read the approval-presentation contract in docs/gateway-seam.md. The build tests stock Iron, the front, and the summary helper, then records an immutable image ID and source hash.
NanoClaw's approval service uses a private Unix socket on Linux. On macOS it uses loopback with mutual TLS and a proxy-only client certificate. Credentials pass directly from Iron Control to Iron Proxy.
With NANOCLAW_GATEWAY_UNCREDENTIALED_READS=true in .env, a GET or HEAD that sends no body or upgrade skips the card when no Iron credential rule could apply to its host and method. The bridge reads the rules from the proxy's config.yaml and, when managed, from Iron Control's effective config for the principal the proxy is assigned now. It reads them fresh for each such request and keeps every card for 30 seconds after its first read, because Iron applies grant changes on its own 10-second sync. Every rule it has seen stays in scope, recorded in seen-credential-rules.json beside config.yaml, because Iron can keep applying a grant that Iron Control has dropped. Delete that file and restart the host to forget revoked grants. The card also stays when Iron Control cannot be read, when the assignment changes mid-read, when a rule has an unknown shape, when config.yaml or proxy.env is newer than the running proxy (restart it), or when proxy.env sets a custom sync interval. Two gaps remain. A grant created in the moment between that read and the forward can be used without a card. So can a grant created and revoked between two reads, if Iron synced it in between, until Iron drops it. A front built before this change never attests a payload-free request, so re-run setup to rebuild it. See docs/gateway-seam.md for the data-leak trade-off.
NANOCLAW_IRON_PROXY_PORT in .env sets the internal proxy port (default 8080). Setup uses the same value for the front listener and the agent proxy URL. This does not publish a host port. Re-run setup and restart this NanoClaw copy after changing it.
NANOCLAW_IRON_CONTROL_PORT sets the console port (default 10257). Only 127.0.0.1 is published. Set it before setup if another install uses that port; use the URL printed by setup. The official image currently targets linux/amd64; Docker on Apple Silicon runs it with emulation. On another architecture, setup checks the engine before it pulls anything and stops, printing the command that enables amd64 emulation, when the engine cannot run that image.
pnpm exec tsx .claude/skills/add-iron-proxy/scripts/setup.ts --with-controlversions.json and disables interactive
Git prompts. Check connectivity and the pinned revision, then retry.exec format error
at the Iron Control step: the pinned console image is amd64 only. Run the printed
tonistiigi/binfmt command against the Docker engine, or choose the OneCLI gateway;
then re-run setup. The registration lives in the kernel and is gone after a reboot:
re-run the command, or register it at boot (a systemd unit or your Docker host's
boot script), or Iron Control restart-loops with exec format error. Setup only checks an engine running on this machine's own kernel;
a VM or remote engine (Docker Desktop, Colima, a DOCKER_HOST elsewhere) is not
inspected and needs emulation enabled inside the engine.control.env.
Keep the database volume and encryption keys together; do not generate replacement
keys for an existing database. nanoclaw uninstall removes both together: the
containers carry this copy's nanoclaw-install and nanoclaw-role=gateway labels
(gateway-owned: the gateway role and no session, so the update drain and residue
reaping keep them), and the uninstaller removes their Compose project's volume and
network with data/.
If the folder was deleted by hand, the error prints the docker rm -f and
docker volume rm commands that delete the old database; run them only if its
credentials can go.pnpm run buildpnpm exec vitest run src/gateway-providers/iron-proxy.test.ts src/gateway-providers/iron-proxy-approval.test.ts src/gateway-providers/iron-proxy-credential-scope.test.ts src/gateway-providers/gateway-provider-registry.test.ts src/gateway-approval-coordinator.test.ts .claude/skills/add-iron-proxy/scripts/control.test.ts .claude/skills/add-iron-proxy/scripts/setup.test.ts .claude/skills/add-iron-proxy/scripts/provider-credentials.test.ts .claude/skills/add-iron-proxy/scripts/credential-isolation.test.ts .claude/skills/add-iron-proxy/scripts/install-command.test.ts src/gateway-providers/iron-proxy-local-model.test.ts .claude/skills/add-iron-proxy/scripts/local-model.test.tsThe setup consumer writes NANOCLAW_GATEWAY_PROVIDER=iron-proxy only after every directive succeeds. Restart only this copy's NanoClaw service after an upgrade so its session contribution and approval bridge match the new installation. Check the proxy has synced its assigned principal before reporting the gateway ready.
The request order is front identity and allowlist → human approval → stock Iron credentials → upstream. The front also requires an explicit response decision before returning upstream data. HTTPS tunnels pin the target authority; each inner HTTP request is checked again. Streaming responses and WebSocket upgrades use this same request/response gate. Credentialed application requests use HTTPS; the approval bridge rejects plaintext HTTP destinations, except one keyless model on this machine pinned by host and port (see Serve a local model). Do not rewrite an HTTP request’s approval metadata as HTTPS to bypass that restriction. The bridge forwards every allowed HTTP request to core as a default approval request. Core uses the active agent provider’s model-domain declaration to permit model traffic without a card; other destinations retain human approval. CONNECT verifies identity; the inner HTTP request is the approval point. Existing standalone model credentials are moved into Iron Control during setup and removed from the old secret file after successful storage and grant.
Open the URL printed by setup. Give the operator the path to login.txt in the same private directory; keep passwords and API tokens out of chat and command logs. control.ts status prints only the URL and login-file location.
The pinned console provides Secrets, Credentials, OAuth Apps, and Principals. Use Secrets to create a credential, choose its source, and set its host, method, and path rules. The current console shows principals and grants but creates grants through its API. Apply a secret to this NanoClaw copy with the bundled helper:
pnpm exec tsx .claude/skills/add-iron-proxy/scripts/control.ts grant static <secret-id>Other supported kinds are gcp, aws, oauth, postgres, and hmac. The command only grants an existing credential to this install's recorded principal. Read references/control-plane.md for the exact supported UI, source links, policy example, and verification steps.
The pinned source has no general egress Policies screen or audit search. Do not promise the screens shown in newer or hosted documentation. A grant's request rules govern credential use; the local egress allowlist remains separate.
To allow another destination explicitly, the operator runs:
pnpm exec tsx .claude/skills/add-iron-proxy/scripts/setup.ts --allow-host <hostname-or-*.domain>For a standalone proxy without the console, omit --with-control on a fresh install. A recorded console is preserved on refresh. Both modes build the pinned public source. To reuse an independently built image, build the exact commit from versions.json
and label the image org.opencontainers.image.revision with that commit. Then run
pnpm exec tsx .claude/skills/add-iron-proxy/scripts/setup.ts --local-image <image>.
Setup checks the revision and records the immutable local image ID. All installs require the exact bundled approval-front label; a stock Iron image alone is not the full NanoClaw integration.
Use the existing provider-auth entry point after /add-codex installs the
provider. Browser sign-in, device pairing, and API-key entry are the same for
all gateways; scripts/credential-store.ts supplies Iron's custody adapter.
Iron Control stores API keys and manages subscription refresh-token rotation
through its native broker. Agents receive only a synthetic auth.json file.
A subscription login uses a new, dedicated Codex session; never copy personal
Codex credentials. The setup flow and provider picker stay unchanged.
pnpm exec tsx setup/index.ts --step provider-auth codexAfter installing /add-opencode, use the same provider-auth entry point:
pnpm exec tsx setup/index.ts --step provider-auth opencodeThe OpenCode setup flow supports ChatGPT sign-in and API keys through Iron
Control. It installs no OneCLI service and needs no OneCLI management settings.
ChatGPT arrives as the seam's chatgpt OAuth profile: Iron creates three
records, a native broker from OpenCode's public OAuth client and refresh token,
a broker-backed bearer secret, and a separate granted secret that carries the
ChatGPT-Account-Id header; any other OAuth profile is rejected. The agent sees only placeholders. Initial sign-in and reauthentication wait for the
native broker to refresh successfully (up to two minutes) before setup continues. API keys use each backend's declared header
scheme. Setup grants the secrets to this install's principal and permits the
model hostname. Rotation and reauthentication keep IDs and grants; reauthentication
also resets a dead broker with the new refresh token. Moving a key to another
host requires confirmation and re-entering its value: Iron's update API replaces
a secret's source whenever its rules change, so a blank answer keeps a key only
on its existing host. Records use install-scoped foreign IDs, so an interrupted
save is retried on the same IDs, and missing grants are reconciled without
reading values. Before keeping or overwriting a record, setup rechecks its
ownership and rules and stops if they no longer match. Broker refresh may continue during login; a change to the broker's
client binding or the secrets' rules stops setup.
Native backends and keyless or custom HTTPS endpoints on port 443 are supported.
Setup refuses plain HTTP (except a local model, below), other ports, IP addresses
and private names such as *.home.arpa, because Iron trusts only public
certificates. Setup adds the model host to Iron's allowlist.
Follow your provider's skill to restart the host and test a real reply.
A keyless model on this machine can use http://host.docker.internal:<port>/v1. Traffic still goes through Iron.
127.0.0.1 (Docker Desktop) or the Docker bridge address, often 172.17.0.1 (Linux). Not 0.0.0.0: that exposes it to your network.Only that port and the OpenAI inference routes are reachable. Don't grant an Iron credential for host.docker.internal: Iron would send it over plain HTTP. A model that needs a key, or runs on another machine, needs https on a public DNS name.
Follow REMOVE.md. Stop only this copy's proxy and console services. Keep the database volume and encryption keys together when preserving data.
OpenCode and Codex use distinct non-secret markers. Iron replaces only the matching
header marker, so each runtime retains its own account on a shared HTTPS host.
Claude's managed model marker remains distinct. These replacements use
require: false: a request from another provider must pass without substitution.
The upstream API still rejects an unavailable or unmatched placeholder.
Refresh the installed provider payloads and rebuild the agent image before using this version. Reconnect older Codex credentials to replace their host-wide injection rules. If setup identifies a conflicting legacy or manual grant, reconnect that provider with this version (including Claude's model credential), or remove the conflicting grant in Iron Control. Stored secrets are write-only and are not silently rewritten. Setup checks direct and role grants, including inactive OAuth brokers. The installation's Iron principal remains the authorization boundary; these markers select credentials, not permissions for separate untrusted tenants.
© nanocoai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 50 other files (scripts, references, assets) in .claude/skills/add-iron-proxy of nanocoai/nanoclaw.
Open the folder on GitHubat commit 66f0823
Iron Proxy Gateway for NanoClaw next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Iron Proxy Gateway for NanoClaw this skillnanocoai/nanoclaw | 31k | — | ~4.6k | Automated safety check: Notes | MIT | |
| Monstermq Broker Configvogler75/monster-mq | 143 | — | ~2.2k | Automated safety check: Pass | GPL-3.0 | |
| Self-Hosted n8n Deploymentczlonkowski/n8n-skills | 6.4k | — | ~3.5k | Automated safety check: Notes | MIT | |
| Weft FrontendWeaveMindAI/weft | 2k | — | ~8k | Automated safety check: Notes | Custom licence | |
| Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 |
vogler75/monster-mq
Guide for configuring, deploying, and operating the MonsterMQ broker.
czlonkowski/n8n-skills
Deploys a production n8n instance to a fresh Linux server over SSH with Docker Compose and Caddy HTTPS, in single or queue mode, and covers updates, backups and hardening.
WeaveMindAI/weft
Read when the user wants a page, app or site for the program, and before dispatching the frontend-builder: the verified scaffold commands, the default stack (pnpm, SvelteKit, PostgreSQL, BetterAuth…
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
omnigent-ai/omnigent
Brings up the Omnigent server and Postgres as a Docker compose stack on any Docker host, and covers the Dockerfile's runtime and host build targets for extending it to a new platform.
nanocoai/nanoclaw
Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.
nanocoai/nanoclaw
Drives a web browser from the shell with the agent-browser CLI: open pages, read an element snapshot, click and fill by reference, grab text and screenshots.
nanocoai/nanoclaw
Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.
nanocoai/nanoclaw
Wires up an additional phone number onto an already-installed Dial channel, so one NanoClaw install answers SMS and AI voice calls on more than one line.
nanocoai/nanoclaw
Installs the `dial` CLI and a credential in NanoClaw agent containers so chosen agents can send SMS, place AI voice calls and receive verification codes.
nanocoai/nanoclaw
Connects NanoClaw to iMessage through one channel with either a local Mac backend or a hosted backend via photon.codes, copying in the adapter and installing its package.
Works with
Categories
Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge. NanoClaw gets an Iron Proxy gateway from this install routine. It copies a provider payload, including the proxy provider, its approval middleware, tests and agent guidance, into the normal NanoClaw source paths, registers the provider with a single import and installs the gRPC bridge dependencies with pnpm.
Iron Proxy Gateway for NanoClaw fits situations like: choosing Iron as the gateway for a NanoClaw install; adding the Iron Control management UI to an existing NanoClaw setup; refreshing the proxy and console after upstream changes; restoring the proxy, approval bridge and agent guidance after they were removed.
Run `npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a claude-code`. Or copy the skill folder (.claude/skills/add-iron-proxy in nanocoai/nanoclaw) into .claude/skills/add-iron-proxy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a codex`. Or copy the skill folder (.claude/skills/add-iron-proxy in nanocoai/nanoclaw) into .agents/skills/add-iron-proxy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nanocoai/nanoclaw --skill add-iron-proxy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-iron-proxy, .gemini/skills/add-iron-proxy, .github/skills/add-iron-proxy and .opencode/skills/add-iron-proxy in your project.
Going by SKILL.md and its folder, Iron Proxy Gateway for NanoClaw needs Go and a shell for the scripts in its folder and the command-line tools its instructions call (pnpm and docker). Our summary lists: A NanoClaw installation; Docker; pnpm.
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Iron Proxy Gateway for NanoClaw is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Iron Proxy Gateway for NanoClaw: Monstermq Broker Config (vogler75/monster-mq, 143 stars), Self-Hosted n8n Deployment (czlonkowski/n8n-skills, 6.4k stars), Weft Frontend (WeaveMindAI/weft, 2k stars) and Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nanocoai (a GitHub organization) maintains it in nanocoai/nanoclaw, which has 30,902 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 6, 2026.
Source: nanocoai/nanoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.