Agent skill

Portless

by yonatangross in yonatangross/orchestkit

Named HTTPS .localhost URLs with portless (v0.15.x). An agent skill from yonatangross/orchestkit.

MITAuto-check passedDevOps & Cloud

Install Portless

skills CLI
$ npx skills add yonatangross/orchestkit --skill portless -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yonatangross/orchestkit portless --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skills/portless .claude/skills/portless && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
portless
GitHub stars
292
Token cost
~2.4k tokens
SKILL.md length
882 words
Files
5 (incl. references)
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Named HTTPS .localhost URLs with portless (v0.15.x). An agent skill from yonatangross/orchestkit.

  • Works in 4 steps: Agent-Accessible Dev Server → Emulate + Portless (Named API Mocks) → Git Worktree Dev → …
  • Setting up a local dev environment
  • SKILL.md covers New in 2026-04 → 2026-07…, When to Use, Quick Start and Framework-Specific Setup, plus 5 more sections
  • Calls npm

What it does

Portless is an agent skill from yonatangross/orchestkit. Named HTTPS .localhost URLs with portless (v0.15.x). Eliminates port collisions, gives agents stable URLs, adds branch-named subdomains for git worktrees, LAN mode (--lan), and Tailscale sharing. Use when setting up a local dev environment or testing from phones and tablets on the same wifi. Do NOT use for production deployments, CI environments (set PORTLESS=0), or DNS/hosting configuration.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `checklists/new-project-setup.md`, `references/framework-integration.md` and `references/upstream-oauth.md`). Compatibility notes: Claude Code 2.1.277+

It sits in DevOps & Cloud, covering Git worktrees and Deployment. It works with Node.js. The repository describes itself as: The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install ork for stable (v9.x), or ork-alpha for the v10 line, which ships daily. The licence is MIT.

When your agent uses it

  • Setting up a local dev environment
  • Testing from phones and tablets on the same wifi
  • Production deployments
  • CI environments (set PORTLESS=0)

Example prompts

  • “/portless”

Requirements

  • Node.js
  • Docker
  • Compatibility (from SKILL.md): Claude Code 2.1.277+

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Agent-Accessible Dev Server
  2. Emulate + Portless (Named API Mocks)
  3. Git Worktree Dev
  4. Bypass in CI

What it can do on your machine

Read from SKILL.md and the folder at commit e4ff8d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Claude Code 2.1.277+

    From compatibility in the SKILL.md frontmatter.

Context cost

Portless loads about 2.4k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 882 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yonatangross/orchestkit at commit e4ff8d9, republished under its MIT licence (© yonatangross). 882 words, ~2,405 tokens.

Download SKILL.mdSave it as .claude/skills/portless/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
portless
description
Named HTTPS .localhost URLs with portless (v0.15.x). Eliminates port collisions, gives agents stable URLs, adds branch-named subdomains for git worktrees, LAN mode (--lan), and Tailscale sharing. Use when setting up a local dev environment or testing from phones and tablets on the same wifi. Do NOT use for production deployments, CI environments (set PORTLESS=0), or DNS/hosting configuration.
compatibility
Claude Code 2.1.277+
user-invocable
false
context
inherit
metadata.upstream-package
portless
metadata.upstream-version-tested
0.15.6
metadata.version
1.2.0
metadata.author
OrchestKit
metadata.complexity
low
metadata.tags
dev-server, localhost, https, portless, devops, mdns, lan

Portless Integration

Named .localhost URLs for local development. Replaces localhost:3000 with https://myapp.localhost.

Full CLI reference: Load Read("references/upstream.md") for complete command docs.

New in 2026-04 → 2026-07 (portless 0.10.x → 0.15.0)

  • portless doctor (0.15.0) — read-only diagnostics that check Node.js, the state directory, proxy liveness, route entries, hostname resolution, HTTPS CA trust, and LAN prerequisites, then print suggested fixes. Run it before filing an issue or when a .localhost URL won't resolve.
  • HTTP/2 Host forwarding fix (0.15.0) — the proxy now forwards the HTTP/2 :authority as Host to HTTP/1.1 backends, fixing apps that read Host and previously saw 127.0.0.1 for browser traffic. --force takeover cleanup now removes only routes still owned by the exiting process, so a forced takeover no longer deregisters the new owner's route.
  • --ngrok flag (0.14.0) — share an app publicly via ngrok while local access keeps its .localhost URL. Pair with the existing Tailscale/Funnel options when you need a public URL without giving up the named-subdomain dev experience.
  • Node.js 24+ required (0.13.1, BREAKING) — the proxy and CLI now require Node.js 24 or newer; older runtimes are unsupported. This release also hardens startup-service persistence so .localhost URLs survive reboot reliably.
  • State directory moved to ~/.portless (0.11, BREAKING) — state relocated from scattered/temp locations to ~/.portless; override with PORTLESS_STATE_DIR. Old state from pre-0.11 installs is not migrated automatically.
  • OS startup service (0.13.0) — portless service install / service status / service uninstall register a native startup service for the HTTPS proxy across macOS launchd, Linux systemd, and Windows Task Scheduler. .localhost URLs survive reboot without a manual portless proxy start. portless clean removes the service alongside CA + hosts cleanup.
  • Tailscale readiness preflight (0.13.0) — --tailscale and --funnel now validate Tailscale HTTPS + Funnel prerequisites before starting the child process, surfacing actionable errors instead of hanging during registration.
  • Tailscale integration (0.12.0) — --tailscale shares your app over your tailnet with automatic HTTPS on port 443; --funnel exposes it publicly via Tailscale Funnel. Apps receive PORTLESS_TAILSCALE_URL so they can reference their own public address. portless list now shows tailnet URLs.
  • Zero-config mode (0.11.0) — bare portless auto-discovers dev scripts from package.json. Multi-app monorepos get automatic subdomain assignment; Turborepo task-graph integration is wired in. portless.json config file supported. --script overrides the default "dev" script.
  • portless prune — removes orphaned dev servers and stale Tailscale registrations.
  • portless clean (extended) — now also tears down Tailscale registrations alongside CA + hosts cleanup.
  • Rsbuild + VitePlus auto-port injection — same auto-wiring as Vite/Next.
  • State directory moved to ~/.portless (was scattered).
  • HTTPS on 443 by default (breaking from 0.9.x http:1355). Valid cert, no setup. --no-tls reverts.
  • NODE_EXTRA_CA_CERTS auto-injected (0.10.2) into child processes — node HTTPS calls trust portless CA with zero setup.
  • --wildcard subdomains — https://*.myapp.localhost for multi-tenant / preview routing.
  • portless alias <name> <port> — map a docker-compose / emulate port to a named URL without a long-running run process.
  • portless clean — full teardown: stops proxy, removes CA, wipes state, cleans /etc/hosts.
  • --lan mode — mDNS .local hostnames reachable across wifi (phone, tablet, other machines) without router config.
  • Fixed app ports — --app-port 3000 / PORTLESS_APP_PORT for tools that need a known port (debuggers, docker).
  • hosts-sync on by default for Safari compat (disable with PORTLESS_SYNC_HOSTS=0).
  • HTTP/2 HMR fixes for Vite/VitePlus/Next.js dev — websocket upgrades no longer break under h2.
  • Expo / React Native support — portless run expo start gives Metro a stable URL for device QR codes.
Show full SKILL.md (348 more words)Show less

When to Use

  • Starting a dev server that agents or browser tests will target
  • Running multiple services locally (API + frontend + docs)
  • Working in git worktrees (branch-named subdomains)
  • Local OAuth flows (stable callback URLs)
  • Connecting emulate API mocks to named URLs

Quick Start

bash
# Instead of: npm run dev (random port)
portless run npm run dev
# → https://myapp.localhost (stable, named, HTTPS on 443 — default in 0.10+)

# Multi-service
portless run --name api npm run dev:api
portless run --name web npm run dev:web
# → https://api.localhost, https://web.localhost

# LAN mode (0.10.0) — reachable from phone/tablet via mDNS
portless proxy start --lan
portless run npm run dev
# → https://myapp.local (resolves across the local network, no router config)

# Full teardown (0.10.1) — stops proxy, removes CA, wipes state, cleans /etc/hosts
portless clean

# Boot persistence (0.13.0) — install native startup service (launchd / systemd / Task Scheduler)
portless service install
portless service status
# Removed automatically by `portless clean`, or explicitly:
portless service uninstall

0.10.x breaking change: default switched from https://app.localhost to https://app.localhost on port 443. Use --no-tls to revert. NODE_EXTRA_CA_CERTS is injected into child processes automatically (0.10.2) — no manual cert setup. /etc/hosts is synced automatically for Safari; disable with PORTLESS_SYNC_HOSTS=0.

Framework-Specific Setup

Load Read("references/framework-integration.md") for full framework recipes.

Most frameworks (Next.js, Vite, Express) work with portless run <cmd>. Some need explicit flags:

FrameworkAuto-detected?Extra flags needed
Next.jsYesNone
Vite / AstroYesNone
Express / Fastify / HonoYesNone (reads PORT env var)
Ruby on RailsYesNone
FastAPI / uvicornNo--port $PORT --host $HOST
DjangoNo$HOST:$PORT positional arg

Why .localhost?

Feature.localhost (RFC 6761)127.0.0.1:PORT/etc/hosts hack
No /etc/hosts editingYesYesNo
HTTPS with valid certYesNoManual
Wildcard subdomainsYesNoNo
Works in all browsersYesYesVaries
Cookie isolation per serviceYesNoYes
No port conflictsYesNoYes

Key Environment Variables

When portless runs your command, it injects:

VariableValueUse in agents
PORTAssigned ephemeral port (4000-4999)Internal only
HOST127.0.0.1Internal only
PORTLESS_URLhttps://myapp.localhostUse this in agent prompts
NODE_EXTRA_CA_CERTSPath to portless CA (auto-injected 0.10.2)Child node processes trust portless certs without setup
Toggle env vars
VariableEffect
PORTLESS=0Bypass portless entirely (CI)
PORTLESS_SYNC_HOSTS=0Disable auto /etc/hosts sync (default: on in 0.10.1+)
PORTLESS_STATE_DIROverride state dir (default: ~/.portless or /tmp/portless for privileged ports)

OrchestKit Integration Patterns

1. Agent-Accessible Dev Server
bash
# Start with portless, then agents can target PORTLESS_URL
portless run npm run dev

# In ork:expect or agent-browser:
agent-browser open $PORTLESS_URL
2. Emulate + Portless (Named API Mocks)
bash
# Register emulate ports as named aliases
portless alias github-api 4001
portless alias vercel-api 4000
portless alias google-api 4002

# Now agents can target:
#   https://github-api.localhost — GitHub emulator
#   https://vercel-api.localhost — Vercel emulator
3. Git Worktree Dev
bash
# In worktree for feature/auth-flow:
portless run npm run dev
# → https://auth-flow.myapp.localhost (auto branch prefix)
4. Bypass in CI
bash
# Disable portless in CI — direct port access
PORTLESS=0 npm run dev

Anti-Patterns

Don'tDo Instead
Hardcode localhost:3000 in testsUse PORTLESS_URL or process.env.PORTLESS_URL
Run portless in CISet PORTLESS=0 in CI environments
Use numeric ports in AGENTS.mdDocument the portless URL

References

FileContent
references/upstream.mdFull portless CLI reference (synced from Vercel)
references/upstream-oauth.mdOAuth callback patterns with stable URLs
references/framework-integration.mdFramework recipes (FastAPI, Django, Docker, gotchas)
checklists/new-project-setup.mdStep-by-step: add portless to a new project

© yonatangross, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in src/skills/portless of yonatangross/orchestkit.

  • SKILL.md
  • checklists/new-project-setup.md
  • references/framework-integration.md
  • references/upstream-oauth.md
  • references/upstream.md

Open the folder on GitHubat commit e4ff8d9

Compare with similar skills

Portless next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Portless compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Portless this skillyonatangross/orchestkit292—~2.4kAutomated safety check: PassMIT
Releasear-io/ar-io-node127—~4.2kAutomated safety check: NotesAGPL-3.0
Update NanoClaw Safelynanocoai/nanoclaw31k—~2.9kAutomated safety check: NotesMIT
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0
Deployment and CI/CD Patternsaffaan-m/ECC276k6 repos~2.8kAutomated safety check: PassMIT
Rasengan Deploymentrasengan-dev/rasenganjs124—~624Automated safety check: PassMIT

Similar skills

  • Release

    ar-io/ar-io-node

    Drive the AR.IO Node release process end-to-end — preflight checks, prepare commit, finalize with image SHAs, test docker compose profiles, tag & publish, and post-release cleanup.

    127 GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Update NanoClaw Safely

    nanocoai/nanoclaw

    Updates a customized NanoClaw install from the official upstream in a staged worktree, with state snapshots, migration gates, health checks and automatic rollback.

    31k GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Covers rolling, blue-green and canary deployments, multi-stage Dockerfiles, a GitHub Actions pipeline, health checks and production readiness for web apps.

    276k GitHub starsUsed in 6 repos~2.8k tokens
    DevOps & CloudAuto-check passed
  • Rasengan Deployment

    rasengan-dev/rasenganjs

    Deployment patterns for Rasengan.js. An agent skill from rasengan-dev/rasenganjs.

    124 GitHub stars~624 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Add Node SDK

    gotempsh/temps

    Integrate the Temps Node.js SDKs for server-side platform access, KV storage, and Blob storage.

    831 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from yonatangross/orchestkit

All 108 skills in this repo
  • API Design

    yonatangross/orchestkit

    API contract design for REST and GraphQL, covering resource shape, URL and header versioning with deprecation windows, RFC 9457 Problem Details error handling, and OpenAPI specs.

    292 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Architecture Decision Record

    yonatangross/orchestkit

    ADR templates in the Nygard format with context, decision, consequences, and alternatives.

    292 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Audit Full

    yonatangross/orchestkit

    Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing.

    292 GitHub stars~3.5k tokensUpdated today
    Auto-check: notes
  • Code Review Playbook

    yonatangross/orchestkit

    Structured review processes, conventional comments, language-specific checklists, and feedback templates.

    292 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Create PR

    yonatangross/orchestkit

    Creates GitHub pull requests with pre-flight validation, conventional title formatting, and structured summary generation.

    292 GitHub stars~4.5k tokensUpdated today
    Auto-check: notes
  • Explore

    yonatangross/orchestkit

    Multi-angle codebase exploration spawning 3-5 parallel agents for code structure, data flow, architecture patterns, and health assessment.

    292 GitHub stars~3.9k tokensUpdated today
    Auto-check: notes

Works with

Questions about Portless

What does Portless do?

Named HTTPS .localhost URLs with portless (v0.15.x). An agent skill from yonatangross/orchestkit. Portless is an agent skill from yonatangross/orchestkit.x).

When should I use Portless?

Portless fits situations like: setting up a local dev environment; testing from phones and tablets on the same wifi; production deployments; CI environments (set PORTLESS=0).

How do I install Portless in Claude Code?

Run `npx skills add yonatangross/orchestkit --skill portless -a claude-code`. Or copy the skill folder (src/skills/portless in yonatangross/orchestkit) into .claude/skills/portless in your project. Claude Code loads it when a task matches its description.

How do I install Portless in Codex?

Run `npx skills add yonatangross/orchestkit --skill portless -a codex`. Or copy the skill folder (src/skills/portless in yonatangross/orchestkit) into .agents/skills/portless in your project. Codex loads it when a task matches its description.

Can I use Portless in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yonatangross/orchestkit --skill portless -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/portless, .gemini/skills/portless, .github/skills/portless and .opencode/skills/portless in your project.

What does Portless need to run?

Going by SKILL.md and its folder, Portless needs the command-line tools its instructions call (npm). Our summary lists: Node.js; Docker. Compatibility (from SKILL.md): Claude Code 2.1.277+.

Does Portless access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Portless safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Portless use?

Portless is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Portless use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.

What are the alternatives to Portless?

Skills that share tags, products or a category with Portless: Release (ar-io/ar-io-node, 127 stars), Update NanoClaw Safely (nanocoai/nanoclaw, 31k stars), Reflexo Release (Myriad-Dreamin/typst.ts, 1.2k stars) and Deployment and CI/CD Patterns (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Portless?

yonatangross (a GitHub user) maintains it in yonatangross/orchestkit, which has 292 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 10, 2026.

Source: yonatangross/orchestkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.