Agent skill

Iron Proxy Gateway Rules

by nanocoai in nanocoai/nanoclaw

Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works.

MITAuto-check passedAgent Workflows

Install Iron Proxy Gateway Rules

skills CLI
$ npx skills add nanocoai/nanoclaw --skill iron-proxy-gateway -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nanocoai/nanoclaw iron-proxy-gateway --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/add-iron-proxy/payload/container/skills/iron-proxy-gateway .claude/skills/iron-proxy-gateway && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iron-proxy-gateway
GitHub stars
31k
Token cost
~598 tokens
SKILL.md length
300 words
Files
2
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works.

  • Connecting GitHub through gh in a NanoClaw agent session
  • SKILL.md covers Policy failures, Connect an account and Rules
  • Needs GH_TOKEN
  • Diagnosing a 403 or 401 on an external API call behind the proxy

What it does

In a session that uses Iron Proxy, all outbound HTTP and HTTPS traffic passes through the proxy. A request that needs a credential waits for human approval before the proxy inserts the real secret, and the agent only ever sees a placeholder. To connect an account, the agent runs the shared `ncl groups connect` command for the API hostname you named, returns the exact `connect_url` and describes its action.

An `operator_console` result means the operator must set up the credential, grant and destination in the gateway, and it is not an OAuth link; an `unsupported` result means no flow should be invented. A bare 403 does not show which layer refused, so the agent reports the hostname and error and asks for a host-side check, and a 401 may simply mean the stored token is invalid. Clients such as `gh` may use the non-secret `gateway-managed` placeholder, real tokens are never typed, and no MCP server is added just to connect an account.

When your agent uses it

  • Connecting GitHub through gh in a NanoClaw agent session
  • Diagnosing a 403 or 401 on an external API call behind the proxy
  • Requesting access to a new external API without exposing a token

Example prompts

  • “Connect GitHub for this session so gh can open a pull request.”
  • “The Linear API call returns 403. Work out which layer blocked it without guessing about credentials.”
  • “I need access to a new REST API from the agent. Start the account connection.”

Requirements

  • HTTP_PROXY, HTTPS_PROXY and the Iron Proxy CA injected by NanoClaw
  • Compatibility (from SKILL.md): Requires HTTP_PROXY, HTTPS_PROXY, and the Iron Proxy CA injected by NanoClaw.

What it can do on your machine

Read from SKILL.md and the folder at commit 66f0823. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires HTTP_PROXY, HTTPS_PROXY, and the Iron Proxy CA injected by NanoClaw.

    From compatibility in the SKILL.md frontmatter.

Context cost

Iron Proxy Gateway Rules loads about 598 tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 300 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~598

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nanocoai/nanoclaw at commit 66f0823, republished under its MIT licence (© nanocoai). 300 words, ~598 tokens.

Download SKILL.mdSave it as .claude/skills/iron-proxy-gateway/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
iron-proxy-gateway
description
Use Iron Proxy for external accounts and APIs, including GitHub through gh. Connect credentials through the operator console and diagnose blocked requests without exposing tokens or adding unnecessary MCP servers.
compatibility
Requires HTTP_PROXY, HTTPS_PROXY, and the Iron Proxy CA injected by NanoClaw.
metadata.author
nanoclaw
metadata.version
1.0.0

Iron Proxy gateway

Your outbound HTTP and HTTPS requests pass through your session's Iron Proxy. A policy-selected credential request waits for human approval before the proxy inserts a credential. You receive only a useless placeholder.

Policy failures

A bare 403 does not prove which layer rejected the request. It may be the destination rule, credential grant, human approval, or upstream API. Respect the block, report the hostname and observed error, and request a host-side check instead of guessing that credentials were never injected.

Connect an account

Run the shared command for the API hostname requested by the user:

bash
ncl groups connect --host <API hostname>

Return the exact connect_url and describe its action. An operator_console handoff requires the operator to configure the credential, grant, and destination in the gateway; it is not an OAuth link. Do not invent a connection flow when the result is unsupported. The command does not grant access or change policy.

Use the user's requested CLI or a direct HTTP client. Do not add an MCP server merely to connect an account. Clients requiring local authentication may use gateway-managed as a non-secret placeholder (for example GH_TOKEN for gh). Never use a real token in the client. Never run a local login to store credentials.

Request approval and account connection are separate. A 401 is not proof that injection did not happen: the stored token may itself be invalid. Report the observed result, follow the shared handoff, and verify with a credentialed request after the operator completes configuration. Never claim connected before success.

Rules

  • Never ask for, print, or store a raw API key or OAuth token.
  • Never bypass the configured proxy or its CA validation.
  • Never treat a pending approval as granted.
  • Never claim a blocked destination is connected.
  • Treat proxy errors as policy or operator-configuration errors, not as permission to weaken TLS.

© nanocoai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/add-iron-proxy/payload/container/skills/iron-proxy-gateway of nanocoai/nanoclaw.

  • SKILL.md
  • instructions.md

Open the folder on GitHubat commit 66f0823

Compare with similar skills

Iron Proxy Gateway Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iron Proxy Gateway Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iron Proxy Gateway Rules this skillnanocoai/nanoclaw31k—~598Automated safety check: PassMIT
Open Source Maintainernumman-ali/n-skills1.1k—~1.8kAutomated safety check: PassApache-2.0
Highlight Imagesrweekly/rweekly.org826—~1.9kAutomated safety check: NotesNone
GitHub Copilot CLI DelegationCherryHQ/cherry-studio52k—~365Automated safety check: PassAGPL-3.0
Do Issueathola/claude-night-market341—~1.5kAutomated safety check: PassMIT
Secure GitHub Actionsvechain/x-app-template450—~1.2kAutomated safety check: PassMIT

Similar skills

  • Open Source Maintainer

    numman-ali/n-skills

    End-to-end GitHub repository maintenance for open-source projects.

    1.1k GitHub stars~1.8k tokensUpdated 28 days ago
    Agent WorkflowsAuto-check passed
  • Highlight Images

    rweekly/rweekly.org

    Find, download, resize, and embed images for the three Highlight links in draft.md.

    826 GitHub stars~1.9k tokensUpdated 4 days ago
    Agent WorkflowsAuto-check: notes
  • GitHub Copilot CLI Delegation

    CherryHQ/cherry-studio

    Runs GitHub Copilot CLI non-interactively on a repository task and reads its JSONL output, denying tools by default so nothing changes unless you ask.

    52k GitHub stars~365 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Do Issue

    athola/claude-night-market

    Implements GitHub or GitLab issues via parallel subagents with review gates between task batches.

    341 GitHub stars~1.5k tokensUpdated 3 days ago
    Agent WorkflowsAuto-check passed
  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Review This Branch

    no-human-ai/no_human

    Run the nohuman review gate (fresh-session adversarial reviewer + tamper guard) over the current branch or a GitHub pull request, with no server, no database, and no onboarding, and relay the…

    332 GitHub stars~1.4k tokensUpdated 4 days ago
    DevelopmentAuto-check passed

More from nanocoai/nanoclaw

All 59 skills in this repo
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 3 days ago
    Auto-check: notes
  • Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

    31k GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check: notes
  • Agent Browser

    nanocoai/nanoclaw

    Drives a web browser from the shell with the agent-browser CLI: open pages, read an element snapshot, click and fill by reference, grab text and screenshots.

    31k GitHub starsUsed in 2 repos~1.6k tokens
    Auto-check passed
  • Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.

    31k GitHub stars~6k tokensUpdated 3 days ago
    Auto-check: notes
  • Wires up an additional phone number onto an already-installed Dial channel, so one NanoClaw install answers SMS and AI voice calls on more than one line.

    31k GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed
  • Add Dial Tool

    nanocoai/nanoclaw

    Installs the `dial` CLI and a credential in NanoClaw agent containers so chosen agents can send SMS, place AI voice calls and receive verification codes.

    31k GitHub stars~4.4k tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about Iron Proxy Gateway Rules

What does Iron Proxy Gateway Rules do?

Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works. In a session that uses Iron Proxy, all outbound HTTP and HTTPS traffic passes through the proxy. A request that needs a credential waits for human approval before the proxy inserts the real secret, and the agent only ever sees a placeholder.

When should I use Iron Proxy Gateway Rules?

Iron Proxy Gateway Rules fits situations like: connecting GitHub through gh in a NanoClaw agent session; diagnosing a 403 or 401 on an external API call behind the proxy; requesting access to a new external API without exposing a token.

How do I install Iron Proxy Gateway Rules in Claude Code?

Run `npx skills add nanocoai/nanoclaw --skill iron-proxy-gateway -a claude-code`. Or copy the skill folder (.claude/skills/add-iron-proxy/payload/container/skills/iron-proxy-gateway in nanocoai/nanoclaw) into .claude/skills/iron-proxy-gateway in your project. Claude Code loads it when a task matches its description.

How do I install Iron Proxy Gateway Rules in Codex?

Run `npx skills add nanocoai/nanoclaw --skill iron-proxy-gateway -a codex`. Or copy the skill folder (.claude/skills/add-iron-proxy/payload/container/skills/iron-proxy-gateway in nanocoai/nanoclaw) into .agents/skills/iron-proxy-gateway in your project. Codex loads it when a task matches its description.

Can I use Iron Proxy Gateway Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nanocoai/nanoclaw --skill iron-proxy-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iron-proxy-gateway, .gemini/skills/iron-proxy-gateway, .github/skills/iron-proxy-gateway and .opencode/skills/iron-proxy-gateway in your project.

What does Iron Proxy Gateway Rules need to run?

Going by SKILL.md and its folder, Iron Proxy Gateway Rules needs credentials named GH_TOKEN. Our summary lists: HTTP_PROXY, HTTPS_PROXY and the Iron Proxy CA injected by NanoClaw. Compatibility (from SKILL.md): Requires HTTP_PROXY, HTTPS_PROXY, and the Iron Proxy CA injected by NanoClaw..

Does Iron Proxy Gateway Rules access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Iron Proxy Gateway Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iron Proxy Gateway Rules use?

Iron Proxy Gateway Rules is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iron Proxy Gateway Rules use?

About 598 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iron Proxy Gateway Rules?

Skills that share tags, products or a category with Iron Proxy Gateway Rules: Open Source Maintainer (numman-ali/n-skills, 1.1k stars), Highlight Images (rweekly/rweekly.org, 826 stars), GitHub Copilot CLI Delegation (CherryHQ/cherry-studio, 52k stars) and Do Issue (athola/claude-night-market, 341 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iron Proxy Gateway Rules?

nanocoai (a GitHub organization) maintains it in nanocoai/nanoclaw, which has 30,902 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 6, 2026.

Source: nanocoai/nanoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.