OneCLI Gateway
nanocoai/nanoclaw
Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.
Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…
$ npx skills add UsefulSoftwareCo/executor --skill emulate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install UsefulSoftwareCo/executor emulate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/UsefulSoftwareCo/executor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/emulate .claude/skills/emulate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "emulate" agent skill from https://github.com/UsefulSoftwareCo/executor/tree/main/.claude/skills/emulate into .claude/skills/emulate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "emulate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/UsefulSoftwareCo/executor/tree/main/.claude/skills/emulateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add UsefulSoftwareCo/executor --skill emulate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install UsefulSoftwareCo/executor emulate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/UsefulSoftwareCo/executor.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/emulate .agents/skills/emulate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "emulate" agent skill from https://github.com/UsefulSoftwareCo/executor/tree/main/.claude/skills/emulate into .agents/skills/emulate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "emulate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add UsefulSoftwareCo/executor --skill emulate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install UsefulSoftwareCo/executor emulate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/UsefulSoftwareCo/executor.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/emulate .cursor/skills/emulate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "emulate" agent skill from https://github.com/UsefulSoftwareCo/executor/tree/main/.claude/skills/emulate into .cursor/skills/emulate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "emulate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/UsefulSoftwareCo/executor.git --path .claude/skills/emulate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add UsefulSoftwareCo/executor --skill emulate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install UsefulSoftwareCo/executor emulate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/UsefulSoftwareCo/executor.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/emulate .gemini/skills/emulate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "emulate" agent skill from https://github.com/UsefulSoftwareCo/executor/tree/main/.claude/skills/emulate into .gemini/skills/emulate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "emulate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install UsefulSoftwareCo/executor emulateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add UsefulSoftwareCo/executor --skill emulate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/UsefulSoftwareCo/executor.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/emulate .github/skills/emulate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "emulate" agent skill from https://github.com/UsefulSoftwareCo/executor/tree/main/.claude/skills/emulate into .github/skills/emulate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "emulate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add UsefulSoftwareCo/executor --skill emulate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install UsefulSoftwareCo/executor emulate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/UsefulSoftwareCo/executor.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/emulate .opencode/skills/emulate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "emulate" agent skill from https://github.com/UsefulSoftwareCo/executor/tree/main/.claude/skills/emulate into .opencode/skills/emulate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "emulate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
emulateUse the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…
Emulate is an agent skill from UsefulSoftwareCo/executor. Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a request ledger for assertions. Use when a test or demo needs a real-shaped upstream API, an OAuth/OIDC provider, a spec to feed addSpec, or proof that a request actually landed.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering OAuth and OpenID Connect and OpenAPI specifications. It works with WorkOS, GitHub and Stripe. The repository describes itself as: The missing integration layer for AI agents. Let them call any OpenAPI / MCP / GraphQL / custom js functions in secure environment. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 27dccb8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
emulators.devresend.emulators.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Emulate loads about 2.2k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 921 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
human-pokeable cloud instance with zero .env**:Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from UsefulSoftwareCo/executor at commit 27dccb8, republished under its MIT licence (© UsefulSoftwareCo). 921 words, ~2,178 tokens.
.claude/skills/emulate/SKILL.md (or your agent's skills folder).@executor-js/emulate (our fork of Vercel Labs' emulate) provides stateful,
wire-level emulators for 16 services: github vercel google okta microsoft spotify slack apple aws resend stripe mongoatlas clerk x workos autumn.
These are not mocks: real SDKs and real product code run against them
unmodified — the cloud e2e target points the actual WorkOS SDK (sealed
sessions, JWKS, hosted AuthKit login) and Autumn billing at emulators and
exercises the product's real auth code.
This repo only consumes the published npm package. There is no
vendor/emulate submodule — everything imports @executor-js/emulate from
npm. The emulator source is its own standalone project; to change or deploy
an emulator, see "Changing or deploying an emulator" at the bottom.
Local, programmatic (what e2e/setup/cloud.boot.ts does):
import { createEmulator } from "@executor-js/emulate";
const github = await createEmulator({ service: "github", port: 4501 });
// github.url, await github.close() — plus the full typed client belowbaseUrl sets the advertised origin (redirects, form actions, spec
servers) when a proxy fronts the emulator — the bind stays on port.
Attach to a running one (another process, or hosted on Cloudflare with
Durable Object state at https://<service>.<instance>.emulators.dev —
catalog at GET https://emulators.dev/_emulate/services). Service hosts
(https://<service>.emulators.dev) are control plane only, with no shared
default instance behind them: create a private instance first and connect to
the returned providerBaseUrl.
import { connectEmulator } from "@executor-js/emulate";
const created = await fetch("https://resend.emulators.dev/_emulate/instances", { method: "POST" });
const { providerBaseUrl } = await created.json();
const resend = await connectEmulator({ baseUrl: providerBaseUrl });
// optional: { service: "resend" } verifies the manifest on connectIn e2e scenarios use createEmulatorInstance from
e2e/src/emulator-instance.ts, which wraps this.
Both createEmulator and connectEmulator return the same EmulatorClient
surface (since 0.7.0) — use it instead of hand-rolling /_emulate fetches:
| Call | Use |
|---|---|
client.openapiUrl | The spec URL — feed it straight to Executor's addSpec to register the emulator as an integration |
client.credentials.mint({type:"api-key"}) | IssuedCredential in the service's real shape: API keys, bearer tokens, OAuth/OIDC clients, client-credentials apps |
client.ledger.list() / .clear() | LedgerEntry[]: matched operationId, sanitized headers/body, auth identity, response status, webhook deliveries |
client.seed({...}) | Add state via the service's seed schema (e.g. WorkOS {oauth:{default_access_token_ttl_seconds:60}} to compress token expiry) |
client.reset() | Reset state + logs, replay seed — works remotely, unlike the old local-only reset |
client.manifest() / .quickstart() / .specs() / .coverage() | What the service is, which operations are real vs partial |
client.state() / .logs() / .connections() | Store snapshot, webhook deliveries, copyable SDK/env/curl snippets |
The same routes exist as raw HTTP under /_emulate/* (start at
GET /_emulate/quickstart, written for agents) for curl/browser use — but in
TypeScript, reach for the client; the types are the point.
Test an integration end-to-end for real (the connect-handoff pattern):
client.credentials.mint(...) → register client.openapiUrl with the
product → invoke a tool through the product → find the call in
client.ledger.list() (match on entry.request.body / operationId). The
ledger is the proof — "the product made this exact upstream call with this
auth" — which beats asserting on the product's own response.
Real OAuth/OIDC flows: google/okta/microsoft/apple/clerk/workos mint
OAuth clients and run real authorize/token endpoints. The WorkOS emulator
additionally serves hosted AuthKit login pages (any email signs in — users
are minted on the fly, no password), an OAuth authorization server for MCP
clients, and Vault KV. Real SDK + WORKOS_API_URL override = the product's
untouched auth code against it. Set EMULATE_WORKOS_AUDIENCE=<client_id>
before createEmulator so minted MCP access tokens carry the right audience.
A live, human-pokeable cloud instance with zero .env:
cd e2e && bun run cli up cloud --share — WorkOS + Autumn emulators + the
app's real dev stack (recipe in e2e/setup/cloud.boot.ts), fronted with
tailscale HTTPS.
The emulators live in their own repo — not in executor and not a
submodule: github.com/UsefulSoftwareCo/emulate (clone it as a sibling of
executor). It's a pnpm + turbo monorepo on node ≥ 24 — a different toolchain
from executor's bun, which is exactly why it's standalone rather than
vendored here.
You have full autonomy over it: work directly on main, and commit, push,
publish, and deploy without asking. The loop:
dist, so a source-only edit does nothing until you
build it — this is the single most common mistake. @emulators/* packages
are a workspace:* graph, so adding or renaming one needs an install +
rebuild too.@executor-js/emulate to npm.emulate-hosts worker behind
*.emulators.dev) when behavior the hosted instances serve has changed.@executor-js/emulate dependency to the version
you just published. Never point a consumer at a local checkout to ship —
publish, then bump.The emulate repo's own AGENTS.md / README.md carry the current build,
publish, and deploy commands (npm + Cloudflare creds are in 1Password). Read
them there rather than memorizing flags here — they move.
A hot deploy can redden other people's e2e. The emulate-hosts worker
behind *.emulators.dev is shared infrastructure; a control-plane regression
there has failed unrelated PRs' suites before. Scenarios always run on private
per-run instances (POST /_emulate/instances); when a scenario needs behavior
that isn't deployed yet, pin to a published package version.
127.0.0.1, but from another device (tailnet) the app's secure: true
auth cookies are dropped over http → "Invalid login state". Front BOTH the
app and the emulator with HTTPS (tailscale serve), and give the emulator
its public origin via baseUrl AND the app's WORKOS_API_URL — the
authorize URL the browser follows is derived from the latter.© UsefulSoftwareCo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/emulate of UsefulSoftwareCo/executor.
Open the folder on GitHubat commit 27dccb8
Emulate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Emulate this skillUsefulSoftwareCo/executor | 4.1k | — | ~2.2k | Automated safety check: Notes | MIT | |
| OneCLI Gatewaynanocoai/nanoclaw | 31k | — | ~856 | Automated safety check: Pass | MIT | |
| Emulate Seedyonatangross/orchestkit | 288 | — | ~4.5k | Automated safety check: Pass | MIT | |
| Stripe Appsfossasia/eventyay | 1.7k | 1 repos | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Stripe Best Practiceskanchengw/cnllm | 175 | 3 repos | ~925 | Automated safety check: Pass | Apache-2.0 | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence |
nanocoai/nanoclaw
Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.
yonatangross/orchestkit
Generate emulate seed configs for stateful API emulation. An agent skill from yonatangross/orchestkit.
fossasia/eventyay
A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.
kanchengw/cnllm
Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
AgentWorkforce/relay
A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling
UsefulSoftwareCo/executor
Pattern for wrapping third-party SDK clients (Stripe, Resend, AWS, etc.) with Effect.
UsefulSoftwareCo/executor
Runbook for releasing the executor CLI package (stable and beta).
UsefulSoftwareCo/executor
Pattern for implementing optimistic UI updates with effect-atom in this codebase.
UsefulSoftwareCo/executor
Testing Effect HttpApi services end-to-end. An agent skill from UsefulSoftwareCo/executor.
UsefulSoftwareCo/executor
Query Executor's production telemetry — Axiom traces (executor-cloud dataset), prod Postgres via PlanetScale, PostHog product analytics — through the Executor MCP.
UsefulSoftwareCo/executor
Build modals/dialogs self-contained: form and in-flight state lives inside, closing unmounts it.
Categories
Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…. Emulate is an agent skill from UsefulSoftwareCo/executor. Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a request ledger for assertions.
Emulate fits situations like: demo needs a real-shaped upstream API; an OAuth/OIDC provider; A spec to feed addSpec; proof that a request actually landed.
Run `npx skills add UsefulSoftwareCo/executor --skill emulate -a claude-code`. Or copy the skill folder (.claude/skills/emulate in UsefulSoftwareCo/executor) into .claude/skills/emulate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add UsefulSoftwareCo/executor --skill emulate -a codex`. Or copy the skill folder (.claude/skills/emulate in UsefulSoftwareCo/executor) into .agents/skills/emulate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add UsefulSoftwareCo/executor --skill emulate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/emulate, .gemini/skills/emulate, .github/skills/emulate and .opencode/skills/emulate in your project.
Going by SKILL.md and its folder, Emulate needs the command-line tools its instructions call (bun).
SKILL.md names 2 domains. In commands or code: emulators.dev and resend.emulators.dev; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Emulate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Emulate: OneCLI Gateway (nanocoai/nanoclaw, 31k stars), Emulate Seed (yonatangross/orchestkit, 288 stars), Stripe Apps (fossasia/eventyay, 1.7k stars) and Stripe Best Practices (kanchengw/cnllm, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
UsefulSoftwareCo (a GitHub organization) maintains it in UsefulSoftwareCo/executor, which has 4,085 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.
Source: UsefulSoftwareCo/executor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.