Agent skill

Cloudflare Tunnel

by xiaoyuboi in xiaoyuboi/cloudflare-tunnel-skill

A skill your agent uses when a user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel.

MITAuto-check passed

Install Cloudflare Tunnel

skills CLI
$ npx skills add xiaoyuboi/cloudflare-tunnel-skill --skill cloudflare-tunnel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xiaoyuboi/cloudflare-tunnel-skill cloudflare-tunnel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare-tunnel
GitHub stars
259
Token cost
~1.4k tokens
SKILL.md length
547 words
Files
12 (incl. scripts, references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel.

  • Works in 3 steps: Local service URL, usually… → Exposure mode: quick or named. → Whether the service contains admin…
  • A user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel
  • SKILL.md covers Paths and State, Mode Selection, Required Checks and Quick Mode, plus 3 more sections
  • Runs Python scripts from its folder; calls cloudflared, python3 and curl; reaches xxxx.trycloudflare.com

What it does

Cloudflare Tunnel is an agent skill from xiaoyuboi/cloudflare-tunnel-skill. Use when a user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel. Supports temporary Quick Tunnel URLs for previews and named tunnels with fixed custom domains for stable public mapping.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts and reference files (for example `README.md`, `README_EN.md` and `agents/openai.yaml`).

It works with Cloudflare. The repository describes itself as: 一个 Cloudflare Tunnel Agent 工作流 skill,支持将本地服务临时发布到公网,或通过固定域名进行公网映射。 | An agent workflow skill that exposes local services to the public internet via Cloudflare Tunnel, with… The licence is MIT.

When your agent uses it

  • A user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel

Example prompts

  • “/cloudflare-tunnel”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Local service URL, usually http://localhost: or https://localhost:.
  2. Exposure mode: quick or named.
  3. Whether the service contains admin panels, tokens, private data, internal systems, or unauthenticated write APIs.

What it can do on your machine

Read from SKILL.md and the folder at commit 1f4eeba. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • cloudflared
    • python3
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • xxxx.trycloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudflare Tunnel loads about 1.4k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 547 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from xiaoyuboi/cloudflare-tunnel-skill at commit 1f4eeba, republished under its MIT licence (© xiaoyuboi). 547 words, ~1,374 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare-tunnel/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
cloudflare-tunnel
description
Use when a user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel. Supports temporary Quick Tunnel URLs for previews and named tunnels with fixed custom domains for stable public mapping.
license
MIT
metadata.tags
cloudflare, tunnel, cloudflared, localhost, public-url, preview, custom-domain

Cloudflare Tunnel Agent Workflow

Help the user expose a local service through Cloudflare Tunnel. Choose the safest working mode:

  • Quick mode: temporary https://*.trycloudflare.com URL. Use for demos, previews, classroom sharing, and short-lived testing.
  • Named mode: fixed hostname such as app.example.com. Use when the user owns a Cloudflare-managed domain and needs a stable public URL.

Before running commands, identify:

  1. Local service URL, usually http://localhost:<port> or https://localhost:<port>.
  2. Exposure mode: quick or named.
  3. Whether the service contains admin panels, tokens, private data, internal systems, or unauthenticated write APIs.

If the service is sensitive, pause and warn the user before exposing it. See references/security.md.

Paths and State

All scripts/... and references/... paths in this document are relative to this skill's install directory, not the user's project. When the working directory is the user's project, call the helper with its full installed path, for example:

bash
python3 ~/.claude/skills/cloudflare-tunnel/scripts/tunnel_helper.py quick --url http://localhost:3000

The helper writes runtime state to .cloudflare-tunnel/ inside the current working directory, so run status and stop from the same directory where quick was started. If that directory is a git repository, make sure .cloudflare-tunnel/ is in its .gitignore before committing.

Mode Selection

Use quick mode when:

  • The user says temporary, demo, preview, share localhost, quick public link, or no domain.
  • The URL may change after restart.
  • The user does not need Cloudflare login.

Use named mode when:

  • The user asks for a fixed domain, stable public URL, webhook endpoint, or long-lived mapping.
  • The user has a Cloudflare account and a domain whose DNS is managed by Cloudflare.
  • The hostname should survive process restarts.

If unclear, default to quick mode for non-sensitive demos and ask only when exposing a sensitive service or creating a fixed hostname.

Required Checks

Check cloudflared:

bash
cloudflared --version

Verify the local service before creating a tunnel:

bash
curl -I http://localhost:<PORT>

Treat 200, 301, 302, 304, 401, and 403 as evidence that the service is reachable. Investigate connection failures before starting a tunnel.

Show full SKILL.md (234 more words)Show less

Quick Mode

Read references/quick-tunnel.md when the user wants a temporary public URL.

Preferred helper:

bash
python3 scripts/tunnel_helper.py quick --url http://localhost:<PORT>

The helper starts cloudflared in the background, waits for a trycloudflare.com URL, writes state under .cloudflare-tunnel/, and prints JSON with the public URL.

Helper behavior worth knowing:

  • If a quick tunnel for the same local URL is already running, it is reused ("reused": true). A running tunnel for a different local URL is stopped and replaced.
  • Transient api.trycloudflare.com failures are retried up to 3 times automatically.
  • verify falls back to DNS-over-HTTPS when the system resolver cannot resolve a fresh trycloudflare.com hostname (common behind fake-IP proxy DNS). DNS propagation can take one or two minutes; retry verify before treating the tunnel as broken.

Manual fallback:

bash
printf '' > /tmp/cloudflared-empty.yml
cloudflared --config /tmp/cloudflared-empty.yml tunnel --no-autoupdate --protocol http2 --url http://localhost:<PORT>

Wait for both:

  • https://*.trycloudflare.com in the output
  • at least one Registered tunnel connection log line

Then verify:

bash
python3 scripts/tunnel_helper.py verify --url https://xxxx.trycloudflare.com

Stop a helper-started tunnel:

bash
python3 scripts/tunnel_helper.py stop

Named Mode

Read references/named-tunnel.md when the user wants a fixed domain.

Typical locally-managed CLI flow:

bash
cloudflared tunnel login
cloudflared tunnel create <TUNNEL_NAME>
cloudflared tunnel route dns <TUNNEL_NAME> <HOSTNAME>

Create a config:

bash
python3 scripts/tunnel_helper.py named-config \
  --name <TUNNEL_NAME> \
  --hostname <HOSTNAME> \
  --url http://localhost:<PORT>

Run:

bash
cloudflared tunnel --config .cloudflare-tunnel/<TUNNEL_NAME>.yml run <TUNNEL_NAME>

Named mode may require an interactive browser login. Do not paste, print, commit, or store Cloudflare tokens outside the user's local Cloudflare config.

Output

After success, return:

  • Public URL
  • Local URL
  • Mode used
  • How to stop the tunnel
  • A short temporary/stability warning for quick mode

Example:

text
Public URL: https://xxxx.trycloudflare.com
Local URL: http://localhost:3000
Mode: quick
Stop: python3 scripts/tunnel_helper.py stop

This is a temporary Quick Tunnel URL. It stops working if cloudflared exits, the computer sleeps, or the network disconnects.

Troubleshooting

Use references/troubleshooting.md for:

  • no public URL in logs
  • 404 from the tunnel
  • 502 / Bad Gateway
  • self-signed local HTTPS
  • phone cannot open the link
  • named tunnel DNS or login failures

© xiaoyuboi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (scripts, references) in the repository root of xiaoyuboi/cloudflare-tunnel-skill.

  • SKILL.md
  • .gitignore
  • LICENSE
  • README.md
  • README_EN.md
  • agents/openai.yaml
  • references/named-tunnel.md
  • references/quick-tunnel.md
  • references/security.md
  • references/troubleshooting.md
  • scripts/test_quick_tunnel.py
  • scripts/tunnel_helper.py

Open the folder on GitHubat commit 1f4eeba

Compare with similar skills

Cloudflare Tunnel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare Tunnel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare Tunnel this skillxiaoyuboi/cloudflare-tunnel-skill259—~1.4kAutomated safety check: PassMIT
Cloudflare Browser Renderingcloudflare/moltworker10k—~742Automated safety check: PassApache-2.0
Turnstile Spincloudflare/skills3k4 repos~7.2kAutomated safety check: NotesApache-2.0
Star Office UI Setupringhyacinth/Star-Office-UI7.5k—~1.3kAutomated safety check: PassMIT
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0

Similar skills

  • Cloudflare Browser Rendering

    cloudflare/moltworker

    Official

    Drives headless Chrome through Cloudflare Browser Rendering over a CDP WebSocket to take screenshots, navigate and scrape pages, and record multi-page videos.

    10k GitHub stars~742 tokensUpdated 5 mo ago
    Productivity & AutomationAuto-check passed
  • Turnstile Spin

    cloudflare/skills

    Official

    Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.

    3k GitHub starsUsed in 4 repos~7.2k tokens
    Frontend & DesignAuto-check: notes
  • Star Office UI Setup

    ringhyacinth/Star-Office-UI

    Sets up Star Office UI, a pixel-art office dashboard that shows AI agent states, lets other agents join and can be opened from a phone or a public link.

    7.5k GitHub stars~1.3k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Nextjs On Cloudflare

    cloudflare/skills

    Official

    Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.

    3k GitHub starsUsed in 2 repos~678 tokens
    DevOps & CloudAuto-check passed

Works with

Questions about Cloudflare Tunnel

What does Cloudflare Tunnel do?

A skill your agent uses when a user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel. Cloudflare Tunnel is an agent skill from xiaoyuboi/cloudflare-tunnel-skill. Use when a user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel.

When should I use Cloudflare Tunnel?

Cloudflare Tunnel fits situations like: A user wants to expose a local HTTP/HTTPS service to the public internet with Cloudflare Tunnel.

How do I install Cloudflare Tunnel in Claude Code?

Run `npx skills add xiaoyuboi/cloudflare-tunnel-skill --skill cloudflare-tunnel -a claude-code`. Or copy the skill folder (the xiaoyuboi/cloudflare-tunnel-skill repository) into .claude/skills/cloudflare-tunnel in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare Tunnel in Codex?

Run `npx skills add xiaoyuboi/cloudflare-tunnel-skill --skill cloudflare-tunnel -a codex`. Or copy the skill folder (the xiaoyuboi/cloudflare-tunnel-skill repository) into .agents/skills/cloudflare-tunnel in your project. Codex loads it when a task matches its description.

Can I use Cloudflare Tunnel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xiaoyuboi/cloudflare-tunnel-skill --skill cloudflare-tunnel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-tunnel, .gemini/skills/cloudflare-tunnel, .github/skills/cloudflare-tunnel and .opencode/skills/cloudflare-tunnel in your project.

What does Cloudflare Tunnel need to run?

Going by SKILL.md and its folder, Cloudflare Tunnel needs Python for the scripts in its folder and the command-line tools its instructions call (cloudflared, python3 and curl). Our summary lists: Python 3.

Does Cloudflare Tunnel access the network?

SKILL.md names 1 domain. In commands or code: xxxx.trycloudflare.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cloudflare Tunnel safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cloudflare Tunnel use?

Cloudflare Tunnel is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare Tunnel use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Cloudflare Tunnel?

Skills that share tags, products or a category with Cloudflare Tunnel: Cloudflare Browser Rendering (cloudflare/moltworker, 10k stars), Turnstile Spin (cloudflare/skills, 3k stars), Star Office UI Setup (ringhyacinth/Star-Office-UI, 7.5k stars) and Cloudflare (hodgef/apiker, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare Tunnel?

xiaoyuboi (a GitHub user) maintains it in xiaoyuboi/cloudflare-tunnel-skill, which has 259 GitHub stars. The repository was last updated on June 11, 2026.

Source: xiaoyuboi/cloudflare-tunnel-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.