Agent skill

Run Claude Gateway Ref

by pleaseai in pleaseai/shunt

Launch and drive a local reference Claude apps gateway (claude gateway + Dex + Postgres) to probe, capture, or re-verify the login / managed-settings / OTLP-telemetry wire protocol that shunt's…

Apache-2.0Auto-check passedDevOps & Cloud

Install Run Claude Gateway Ref

skills CLI
$ npx skills add pleaseai/shunt --skill run-claude-gateway-ref -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pleaseai/shunt run-claude-gateway-ref --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pleaseai/shunt.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/run-claude-gateway-ref .claude/skills/run-claude-gateway-ref && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
run-claude-gateway-ref
GitHub stars
281
Token cost
~1.4k tokens
SKILL.md length
517 words
Files
4
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Launch and drive a local reference Claude apps gateway (claude gateway + Dex + Postgres) to probe, capture, or re-verify the login / managed-settings / OTLP-telemetry wire protocol that shunt's…

  • DevOps & Cloud work in your project
  • SKILL.md covers Prerequisites, Run (agent path), Verified wire facts… and Gotchas, plus 1 more section
  • Runs Shell scripts from its folder; calls claude, curl and python3

What it does

Run Claude Gateway Ref is an agent skill from pleaseai/shunt. Launch and drive a local reference Claude apps gateway (claude gateway + Dex + Postgres) to probe, capture, or re-verify the login / managed-settings / OTLP-telemetry wire protocol that shunt's gateway superset (login → managed/settings → telemetry, epic

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `dex.yaml`, `driver.sh` and `gateway.yaml`).

It sits in DevOps & Cloud. It works with OpenTelemetry, PostgreSQL, Google Gemini and Kimi. The repository describes itself as: Shunt Claude Code agents to any model — selective, per-agent inference-layer routing proxy. The licence is Apache-2.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/run-claude-gateway-ref”

Requirements

  • Python 3
  • A Bash shell
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit e147f9b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • claude
    • curl
    • python3
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Run Claude Gateway Ref loads about 1.4k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 517 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pleaseai/shunt at commit e147f9b, republished under its Apache-2.0 licence (© pleaseai). 517 words, ~1,391 tokens.

Download SKILL.mdSave it as .claude/skills/run-claude-gateway-ref/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
run-claude-gateway-ref
description
Launch and drive a local reference Claude apps gateway (claude gateway + Dex + Postgres) to probe, capture, or re-verify the login / managed-settings / OTLP-telemetry wire protocol that shunt's gateway superset (login → managed/settings → telemetry, epic

Run the reference Claude apps gateway (protocol probe)

Spins up the real claude gateway (built into the claude binary) with a local Dex IdP and throwaway Postgres, then drives the full device-flow login non-interactively with curl — no browser needed. Use it to (re)capture the wire contract shunt mirrors: exact token JSON, /managed/settings body, env push, OTLP relay behavior.

Everything is driven by .claude/skills/run-claude-gateway-ref/driver.sh (paths relative to repo root). Backend note: curl is sufficient — the /device browser page is scriptable once you send same-origin CSRF headers.

Prerequisites

  • Docker running (pulls postgres:16-alpine, ghcr.io/dexidp/dex:v2.44.0)
  • claude binary ≥ 2.1.207 (verified with 2.1.211), python3, curl
  • Ports free: 8790 (gateway), 5556 (dex), 55432 (pg), 44318 (sink)

Run (agent path)

bash
S=.claude/skills/run-claude-gateway-ref/driver.sh
$S up          # pg + dex containers, gateway on :8790, waits healthy
$S sink-start  # optional: local OTLP sink so the telemetry relay is observable
$S login       # full RFC 8628 device flow via curl → capture/token.json
$S probe       # captures protocol.md, managed_settings.json (+304), models.json,
               # refresh grant, POST /v1/metrics relay, /user/bootstrap
$S status      # health of all three processes
$S down        # kill gateway + sink, remove containers

Artifacts land in /tmp/shunt-gw-probe/capture/ (override root with GWREF_WORK). Gateway log: /tmp/shunt-gw-probe/gateway.log (audit events are JSON lines — evt: device.authorize, device.verify, session.mint, session.refresh, managed.serve, auth.denied). Sink log: /tmp/shunt-gw-probe/sink.log.

Login identity: dev@example.com / password (Dex static user, no groups).

Verified wire facts (2026-07-16, gateway 2.1.211)

Captured live; these fill the gaps docs/gateway-protocol.md marks unspecified:

  • Token response (device grant AND refresh grant, same shape): {"access_token":"<HS256 JWT>","refresh_token":"<opaque>","token_type":"Bearer","expires_in":3600}. JWT claims: sub (IdP subject), email, name, aud=oidc client_id, iss=public_url. Refresh rotates the refresh token. Gateway refresh = refresh against the IdP (3500ms budget) + re-mint; IdP failure → 401 {"error":"invalid_grant"}.
  • /managed/settings body: {"uuid":"sha256:…","checksum":"sha256:…","settings":{<managed-settings.json>}}, ETag = checksum, If-None-Match → 304. With telemetry.forward_to set it pushes six env vars (docs say five): CLAUDE_CODE_ENABLE_TELEMETRY=1, OTEL_{METRICS,LOGS,TRACES}_EXPORTER=otlp, OTEL_EXPORTER_OTLP_ENDPOINT=<public_url>, OTEL_EXPORTER_OTLP_PROTOCOL=http/protobuf, merged with policy env.
  • Discovery includes undocumented gateway_protocol_version: 1, token_endpoint_auth_methods_supported: ["none"], scopes_supported.
  • IdP callback is {public_url}/oauth/callback (register in the IdP client).
  • Telemetry relay is verbatim — body forwarded byte-identical, no identity attributes stamped by the gateway; POST /v1/{metrics,logs,traces} returns 200 even when the destination is down. Boot log says signals enabled: metrics for a bare forward_to entry.
  • /v1/models is filtered by the caller's policy availableModels; full Anthropic shape (type, has_more, first_id, last_id).
  • Error envelope adds top-level request_id alongside {"type":"error","error":{…}}.
  • GET /user/bootstrap (new, Claude Desktop): 404 not_found_error unless a policy carries a desktop: block.
Show full SKILL.md (202 more words)Show less

Gotchas

  • POST /device is CSRF-guarded: without Origin + Referer + Sec-Fetch-Site: same-origin it returns 200 with "request came from another site and was blocked" instead of the 302 to the IdP. The audit log shows device.verify result=csrf_rejected.
  • The gw_dev cookie from the /device POST must be replayed on /oauth/callback or the device grant is never approved.
  • Dex latest (master) hangs forever on refresh (memory AND sqlite3 storage) → gateway session.refresh fails with "timed out after 3500ms" and the client gets invalid_grant. Pin v2.44.0.
  • Loopback OIDC issuer is rejected by the SSRF guard unless CLAUDE_GATEWAY_ALLOW_LOOPBACK=1 (driver sets it). http:// public_url is accepted on loopback.
  • Don't let curl -w write into a JSON capture file — it corrupts the JSON and the next python3 json.load fails with "Extra data".
  • The dummy upstreams API key boots fine; only /v1/messages inference would fail. Postgres is required at boot (gateway runs 6 migrations).

Troubleshooting

  • refresh grant: 401 + gateway log "timed out after 3500ms" → your Dex image is unpinned/master; docker rm -f shunt-gw-dex and rerun up (pulls v2.44.0).
  • device POST did not redirect from the driver → CSRF headers missing (driver sends them; check you didn't proxy/strip them).
  • Boot fails on config: unknown keys fail fast with a field-level error; check /tmp/shunt-gw-probe/gateway.log first.

© pleaseai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in .claude/skills/run-claude-gateway-ref of pleaseai/shunt.

  • SKILL.md
  • dex.yaml
  • driver.sh
  • gateway.yaml

Open the folder on GitHubat commit e147f9b

Compare with similar skills

Run Claude Gateway Ref next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Run Claude Gateway Ref compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Run Claude Gateway Ref this skillpleaseai/shunt281—~1.4kAutomated safety check: PassApache-2.0
Phoenix LLM ObservabilityOrchestra-Research/AI-Research-SKILLs13k2 repos~2.9kAutomated safety check: PassMIT
Youtubeeat-pray-ai/yutu699—~1.1kAutomated safety check: PassMIT
Pulse Releasequnqin24/Pulse517—~1.3kAutomated safety check: PassApache-2.0
Bridgic LLMsbitsky-tech/bridgic155—~839Automated safety check: NotesMIT
Paper ReviewRapidAI/MaClaw147—~1kAutomated safety check: PassMIT

Similar skills

  • Phoenix LLM Observability

    Orchestra-Research/AI-Research-SKILLs

    Sets up Arize Phoenix to trace, evaluate and monitor LLM applications, with instrumentation for OpenAI, LangChain and LlamaIndex and a self-hosted server.

    13k GitHub starsUsed in 2 repos~2.9k tokens
    AI & LLM EngineeringAuto-check passed
  • Youtube

    eat-pray-ai/yutu

    A skill your agent uses whenever the user mentions YouTube, video uploads, channel management, playlists, video SEO, or any YouTube Data API operation.

    699 GitHub stars~1.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Pulse Release

    qunqin24/Pulse

    Release a new Pulse version end to end — checks, bilingual CHANGELOG entry, VERSION, tag, the release workflow, syncing main, and the issue replies that go with it.

    517 GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Bridgic LLMs

    bitsky-tech/bridgic

    LLM provider initialization for bridgic projects. An agent skill from bitsky-tech/bridgic.

    155 GitHub stars~839 tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Paper Review

    RapidAI/MaClaw

    论文深度解读 Skill — 下载论文PDF → LLM深度解读(问题/创新点/方法原理/实验分析)→ PDF图片提取 → 生成组会PPT → 生成解读音频MP3。端到端学术论文解读工具。

    147 GitHub stars~1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Add Model Price

    litefuse/litefuse

    Add new LLM model pricing entries to Litefuse's default-model-prices.json.

    100 GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed

More from pleaseai/shunt

  • Run Shunt

    pleaseai/shunt

    Build, launch, and drive shunt — the Claude Code LLM gateway (a Rust/axum Anthropic-Messages proxy).

    281 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Run Claude Gateway Ref

What does Run Claude Gateway Ref do?

Launch and drive a local reference Claude apps gateway (claude gateway + Dex + Postgres) to probe, capture, or re-verify the login / managed-settings / OTLP-telemetry wire protocol that shunt's…. Run Claude Gateway Ref is an agent skill from pleaseai/shunt.

When should I use Run Claude Gateway Ref?

Run Claude Gateway Ref fits situations like: devOps & Cloud work in your project.

How do I install Run Claude Gateway Ref in Claude Code?

Run `npx skills add pleaseai/shunt --skill run-claude-gateway-ref -a claude-code`. Or copy the skill folder (.claude/skills/run-claude-gateway-ref in pleaseai/shunt) into .claude/skills/run-claude-gateway-ref in your project. Claude Code loads it when a task matches its description.

How do I install Run Claude Gateway Ref in Codex?

Run `npx skills add pleaseai/shunt --skill run-claude-gateway-ref -a codex`. Or copy the skill folder (.claude/skills/run-claude-gateway-ref in pleaseai/shunt) into .agents/skills/run-claude-gateway-ref in your project. Codex loads it when a task matches its description.

Can I use Run Claude Gateway Ref in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pleaseai/shunt --skill run-claude-gateway-ref -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/run-claude-gateway-ref, .gemini/skills/run-claude-gateway-ref, .github/skills/run-claude-gateway-ref and .opencode/skills/run-claude-gateway-ref in your project.

What does Run Claude Gateway Ref need to run?

Going by SKILL.md and its folder, Run Claude Gateway Ref needs a shell for the scripts in its folder and the command-line tools its instructions call (claude, curl, python3 and docker). Our summary lists: Python 3; A Bash shell; Docker.

Does Run Claude Gateway Ref access the network?

SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Run Claude Gateway Ref safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Run Claude Gateway Ref use?

Run Claude Gateway Ref is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Run Claude Gateway Ref use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Run Claude Gateway Ref?

Skills that share tags, products or a category with Run Claude Gateway Ref: Phoenix LLM Observability (Orchestra-Research/AI-Research-SKILLs, 13k stars), Youtube (eat-pray-ai/yutu, 699 stars), Pulse Release (qunqin24/Pulse, 517 stars) and Bridgic LLMs (bitsky-tech/bridgic, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Run Claude Gateway Ref?

pleaseai (a GitHub organization) maintains it in pleaseai/shunt, which has 281 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 8, 2026.

Source: pleaseai/shunt on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.