Agent skill

OneCLI Gateway

by nanocoai in nanocoai/nanoclaw

Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

MITAuto-check passedBackend & APIs

Install OneCLI Gateway

skills CLI
$ npx skills add nanocoai/nanoclaw --skill onecli-gateway -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nanocoai/nanoclaw onecli-gateway --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/add-onecli/payload/container/skills/onecli-gateway .claude/skills/onecli-gateway && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
onecli-gateway
GitHub stars
31k
Token cost
~856 tokens
SKILL.md length
402 words
Files
2
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

  • Reading email or checking a calendar through an already connected account
  • SKILL.md covers How to Access External Services, Making Requests, Credential Stubs for MCP Servers and When a Request Fails, plus 1 more section
  • Calls curl; reaches gmail.googleapis.com and api.github.com
  • Calling the GitHub or Stripe API without handling tokens

What it does

Outbound HTTPS traffic from the agent passes through the OneCLI gateway, so the agent calls the real API address with curl, fetch, requests, axios or git and sends no auth headers. Gmail, GitHub, Google Calendar, Google Drive and key-based services such as Stripe work this way once the app is connected, and standard clients pick up the HTTPS_PROXY environment variable automatically.

When a call returns 401, 403 or an app_not_connected error, the agent shows you the connect link from the response, or points you to the OneCLI dashboard, and retries after you confirm. For MCP servers that need local credential files, it writes stub files filled with the onecli-managed placeholder and 0600 permissions, and leaves existing managed files alone. The rules rule out browser extensions, manual auth flows and asking you for keys.

When your agent uses it

  • Reading email or checking a calendar through an already connected account
  • Calling the GitHub or Stripe API without handling tokens
  • An API request fails with a 401 or app_not_connected error
  • Starting an MCP server that needs local credential files

Example prompts

  • “List the five most recent messages in my Gmail inbox.”
  • “Show my ten latest GitHub repositories and open issues on the newest one.”
  • “Check the last few Stripe charges and tell me if any failed.”

Requirements

  • HTTPS_PROXY set in the environment, automatic when launched with onecli run
  • The target app connected in the OneCLI dashboard
  • Compatibility (from SKILL.md): Requires HTTPS_PROXY set in environment (automatic when launched via `onecli run`)

What it can do on your machine

Read from SKILL.md and the folder at commit 66f0823. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • gmail.googleapis.com
    • api.github.com
    • api.stripe.com

    Also links to:

    • onecli.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires HTTPS_PROXY set in environment (automatic when launched via `onecli run`)

    From compatibility in the SKILL.md frontmatter.

Context cost

OneCLI Gateway loads about 856 tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 402 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~856

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nanocoai/nanoclaw at commit 66f0823, republished under its MIT licence (© nanocoai). 402 words, ~856 tokens.

Download SKILL.mdSave it as .claude/skills/onecli-gateway/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
onecli-gateway
description
OneCLI Gateway: transparent HTTPS proxy that injects stored credentials into outbound calls. You MUST use this skill when the user asks you to read emails, check calendar, access GitHub repos, create issues, check Stripe payments, or interact with ANY external service or API. Do NOT use browser extensions or OAuth CLI tools. Make HTTP requests directly; the gateway injects credentials automatically.
compatibility
Requires HTTPS_PROXY set in environment (automatic when launched via `onecli run`)
metadata.author
onecli
metadata.version
0.5.0

OneCLI Gateway

Your outbound HTTPS traffic is transparently proxied through the OneCLI gateway, which injects stored credentials at the proxy boundary. You never see or handle credential values directly.

How to Access External Services

You have direct HTTP access to external APIs. OAuth apps (Gmail, GitHub, Google Calendar, Google Drive, etc.) and API key services are all available through the gateway. Just make the request directly; the gateway injects credentials if the app is connected. If not, it returns an error with a connect URL you can present to the user.

Making Requests

Call the real API URL. The gateway intercepts the request and injects credentials automatically.

bash
curl -s "https://gmail.googleapis.com/gmail/v1/users/me/messages?maxResults=5"
curl -s "https://api.github.com/user/repos?per_page=10"
curl -s "https://api.stripe.com/v1/charges?limit=5"

Standard HTTP clients (curl, fetch, requests, axios, Go net/http, git) all honor the HTTPS_PROXY environment variable automatically. You do not need to set any auth headers.

Credential Stubs for MCP Servers

Some MCP servers need local credential files to start. Stubs for connected apps are pre-written automatically. Files containing "onecli-managed" values are managed by OneCLI — do NOT modify or delete them.

If an MCP server won't start due to missing credentials, create stubs before starting it. Use "onecli-managed" as the placeholder for all secret values, with file permissions 0600. See the guide at: https://www.onecli.sh/docs/guides/credential-stubs/general-app

Show full SKILL.md (201 more words)Show less

When a Request Fails

If you get a 401, 403, or a gateway error (e.g., app_not_connected):

Step 1 — Show the user a connect link. Use the connect_url from the error response:

To connect [service], open this link: [connect_url from the error response]

If there is no connect_url in the error, tell the user to open the OneCLI dashboard and connect the service there.

Step 2 — Retry after the user connects. Let the user know you will retry once they have connected. When they confirm, retry the original request. If the retry still fails, ask if they need help with the setup.

Rules

  • Never say "I don't have access to X" without first making the HTTP request through the proxy.
  • Never use browser extensions, gcloud, or manual auth flows. The gateway handles credentials for you.
  • Never ask the user for API keys or tokens directly. Direct them to connect the service in the OneCLI dashboard.
  • Never suggest the user open Gmail/Calendar/GitHub in their browser when they ask you to read or interact with those services. You have API access. Use it.
  • If the gateway returns a policy error (403 with a JSON body), respect the block. Do not retry or circumvent it.

© nanocoai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/add-onecli/payload/container/skills/onecli-gateway of nanocoai/nanoclaw.

  • SKILL.md
  • instructions.md

Open the folder on GitHubat commit 66f0823

Compare with similar skills

OneCLI Gateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

OneCLI Gateway compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
OneCLI Gateway this skillnanocoai/nanoclaw31k—~856Automated safety check: PassMIT
Connectorsautonomous-ai/Physical-AI-Operating-System381—~11kAutomated safety check: NotesApache-2.0
Firecrawl Build Onboardingfirecrawl/firecrawl189k1 repos~1.4kAutomated safety check: NotesISC
EmulateUsefulSoftwareCo/executor4.1k—~2.2kAutomated safety check: NotesMIT
QuickBooks Online Integrationhewi333/Mom-n-Pop-Skills122—~1.9kAutomated safety check: PassMIT
Google Calendarsanjay3290/ai-skills430—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Connectors

    autonomous-ai/Physical-AI-Operating-System

    Discover and use linked third-party services (Gmail, Google Calendar, Google Drive, Notion, Figma, Asana, Linear, GitHub, Ahrefs, Facebook Fan Page and others).

    381 GitHub stars~11k tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    189k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Emulate

    UsefulSoftwareCo/executor

    Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…

    4.1k GitHub stars~2.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • QuickBooks Online Integration

    hewi333/Mom-n-Pop-Skills

    Connects a small business to QuickBooks Online for customers, estimates, invoices and payments, using Intuit OAuth 2.0 with token refresh and sandbox or production setups.

    122 GitHub stars~1.9k tokensUpdated 26 days ago
    Backend & APIsAuto-check passed
  • Google Calendar

    sanjay3290/ai-skills

    Interact with Google Calendar - list calendars, view events, create/update/delete events, and find free time.

    430 GitHub stars~1.2k tokensUpdated 26 days ago
    Backend & APIsAuto-check passed
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes

More from nanocoai/nanoclaw

All 59 skills in this repo
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Agent Browser

    nanocoai/nanoclaw

    Drives a web browser from the shell with the agent-browser CLI: open pages, read an element snapshot, click and fill by reference, grab text and screenshots.

    31k GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check passed
  • Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

    31k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes
  • Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.

    31k GitHub stars~6k tokensUpdated yesterday
    Auto-check: notes
  • Wires up an additional phone number onto an already-installed Dial channel, so one NanoClaw install answers SMS and AI voice calls on more than one line.

    31k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • NanoClaw LLM Wiki Setup

    nanocoai/nanoclaw

    Adds a persistent wiki knowledge base to a NanoClaw group following Karpathy's LLM Wiki pattern, with folders, a tailored container skill and a CLAUDE.md section.

    31k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed

Questions about OneCLI Gateway

What does OneCLI Gateway do?

Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys. Outbound HTTPS traffic from the agent passes through the OneCLI gateway, so the agent calls the real API address with curl, fetch, requests, axios or git and sends no auth headers. Gmail, GitHub, Google Calendar, Google Drive and key-based services such as Stripe work this way once the app is connected, and standard clients pick up the HTTPS_PROXY environment variable automatically.

When should I use OneCLI Gateway?

OneCLI Gateway fits situations like: reading email or checking a calendar through an already connected account; calling the GitHub or Stripe API without handling tokens; an API request fails with a 401 or app_not_connected error; starting an MCP server that needs local credential files.

How do I install OneCLI Gateway in Claude Code?

Run `npx skills add nanocoai/nanoclaw --skill onecli-gateway -a claude-code`. Or copy the skill folder (.claude/skills/add-onecli/payload/container/skills/onecli-gateway in nanocoai/nanoclaw) into .claude/skills/onecli-gateway in your project. Claude Code loads it when a task matches its description.

How do I install OneCLI Gateway in Codex?

Run `npx skills add nanocoai/nanoclaw --skill onecli-gateway -a codex`. Or copy the skill folder (.claude/skills/add-onecli/payload/container/skills/onecli-gateway in nanocoai/nanoclaw) into .agents/skills/onecli-gateway in your project. Codex loads it when a task matches its description.

Can I use OneCLI Gateway in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nanocoai/nanoclaw --skill onecli-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/onecli-gateway, .gemini/skills/onecli-gateway, .github/skills/onecli-gateway and .opencode/skills/onecli-gateway in your project.

What does OneCLI Gateway need to run?

Going by SKILL.md and its folder, OneCLI Gateway needs the command-line tools its instructions call (curl). Our summary lists: HTTPS_PROXY set in the environment, automatic when launched with onecli run; The target app connected in the OneCLI dashboard. Compatibility (from SKILL.md): Requires HTTPS_PROXY set in environment (automatic when launched via `onecli run`).

Does OneCLI Gateway access the network?

SKILL.md names 4 domains. In commands or code: gmail.googleapis.com, api.github.com and api.stripe.com; the agent is likely to contact these when it follows the instructions. As links in the text: onecli.sh. This is read from the text; nothing was executed.

Is OneCLI Gateway safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does OneCLI Gateway use?

OneCLI Gateway is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does OneCLI Gateway use?

About 856 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to OneCLI Gateway?

Skills that share tags, products or a category with OneCLI Gateway: Connectors (autonomous-ai/Physical-AI-Operating-System, 381 stars), Firecrawl Build Onboarding (firecrawl/firecrawl, 189k stars), Emulate (UsefulSoftwareCo/executor, 4.1k stars) and QuickBooks Online Integration (hewi333/Mom-n-Pop-Skills, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains OneCLI Gateway?

nanocoai (a GitHub organization) maintains it in nanocoai/nanoclaw, which has 30,883 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 6, 2026.

Source: nanocoai/nanoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.