portal-expose

Tinjau · 67
Diindeks di Registry

Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint and report its lifecycle. Use when the user asks to deploy, publish, share, tunnel,

Verified installs0
Star263
Versi1.0.0
Kualitas71/100 · Kuat
Kepercayaan67/100 · Hanya sandbox
Audit80/100 · Berisiko

Profil aset

Agent pemrograman dan pengembangan

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Lihat kategori

Skenario

Agent pemrograman

I need a coding agent that can understand a repository, edit code, and review pull requests.

Kecocokan Agent

Claude Code + Browser agents + CLI

Cocok untuk Codex, Claude Code, Cursor, CLI, atau Agent khusus.

Pasang

Siap

npx skills add gosuda/portal-tunnel --skill portal-expose

Pemeliharaan

Terkini

1 hari sejak push

Risiko

Berisiko

Dependency or permission surface needs review

Kualitas GitHub

263

71/100 Kualitas · 75/100 Kepercayaan

Tag cakupan

CodingAgent pemrogramanautomationagent-skill

Catatan ulasan

Dependency or permission surface needs review · Permission surface may require sandboxing

Kartu adopsi Agent

Kepercayaan, audit, dan kesiapan pemasangan dalam sekali lihat

Skor ini menggabungkan metadata repositori publik, sinyal ulasan OpenAgentSkill, kebaruan pemeliharaan, dan kesiapan pemasangan. Ini adalah sinyal shortlist, bukan pengganti peninjauan manusia.

Kualitas

Kuat
71

Solid option that is likely worth shortlisting for production workflows.

Kepercayaan

Hanya sandbox
67

Kandidat berguna dengan sinyal kepercayaan yang kurang atau bercampur. Gunakan di ruang kerja terisolasi hingga loop hasil membuktikan kecocokan tugas.

Audit

Berisiko
80

Tinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.

Trust Score OpenAgentSkill v5

Hanya sandbox

Jalankan hanya dalam sandbox dan bandingkan alternatif terdekat sebelum digunakan untuk kerja nyata.

CodexClaude CodeCursorOpenAgentSkill CLI

Star

263 star GitHub

Aktivitas repositori

263 star dan 29 fork

Pemeliharaan

1 hari sejak push

Lisensi

MIT

Pasang

npx skills add gosuda/portal-tunnel --skill portal-expose

Keamanan pemasangan

Jalur pemasangan paket atau runtime standar

Cakupan izin

shell or command execution, filesystem or document access

Hasil Agent

Belum ada data hasil Agent

Dokumentasi

Konteks README/SKILL.md kuat

Ringkasan risiko

Tinjau sebelum produksi

  • Financial research output is not financial advice; require human review before any live investment decision.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access

Kesiapan pemasangan

Jalur pemasangan tersedia

  • Jalur pemasangan tersedia
  • Bukti repositori tersedia
  • Lisensi dinyatakan
  • Belum ada bukti hasil Agent-Proven

Metadata yang dapat dibaca Agent

Data keputusan yang dapat dibaca mesin untuk skill ini.

Gunakan blok ini atau JSON tersemat untuk memutuskan apakah Agent perlu memasang skill ini, memilih alternatif, atau meminta tinjauan manusia terlebih dahulu.

Buka JSON

Tugas yang sesuai

  • alur kerja Local desktop
  • Tim Claude Code
  • builders willing to evaluate younger projects
  • Navigate local resources

Agent yang sesuai

CodexClaude CodeCursorOpenAgentSkill CLIBrowser agentsCLI

Keputusan pemasangan

Perintah
npx skills add gosuda/portal-tunnel --skill portal-expose
Kebijakan
Blokir
Tinjauan manusia
Ya

Kepercayaan dan risiko

Kepercayaan
67/100
Audit
80/100
Tingkat risiko
Berisiko

Lingkar hasil

Endpoint
/api/agent/outcome
ID event
resolve
Hasil
5

Perintah pemasangan

npx skills add gosuda/portal-tunnel --skill portal-expose

Jangan gunakan ketika

  • Tim yang membutuhkan SLA dengan dukungan vendor
  • Lingkungan berkompliansi tinggi tanpa tinjauan keamanan internal
  • No major risk signals from current metadata
  • Audit risk risky exceeds max_risk=medium
  • Petunjuk izin berisiko tinggi: eksekusi shell atau perintah

Keamanan Agent v2

48/100 · Hindari pemasangan otomatis

Blocked for auto-installBlokir

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

Selesaikan via API

Tinggi

Eksekusi shell atau perintah

Metadata skill merujuk terminal, CLI, shell, subprocess, atau alur kerja eksekusi perintah.

Sedang

Browser automation

Skill may drive a browser or interact with web pages.

Sedang

Akses jaringan

Skill kemungkinan mengambil halaman jarak jauh, API, repositori, atau layanan eksternal.

Sedang

Akses sistem file

Skill dapat membaca atau menulis file proyek, dokumen, artefak yang dihasilkan, atau status workspace lokal.

  • Audit risk risky exceeds max_risk=medium
  • Petunjuk izin berisiko tinggi: eksekusi shell atau perintah
  • Dependency or permission surface needs review

Target pemasangan

Pasang skill ini di alur Agent Anda

Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install gosuda-portal-expose

Rencana resolusi Agent

Biarkan Agent memverifikasi kecocokan sebelum memasang.

API Resolve mengembalikan skill utama, alternatif, kebijakan keamanan, catatan audit, target pemasangan, dan prompt siap pakai.

Buka rencana teks

Agent harus memeriksa

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Salin prompt

Task: Use portal-expose in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20portal-expose%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/gosuda-portal-expose/install
Install command: npx skills add gosuda/portal-tunnel --skill portal-expose
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Serah-terima Agent

Berikan jalur pemasangan kepada Agent, bukan direktori lain.

Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.

Buka API pemasangan

Prompt Agent

Use portal-expose for this task. Review https://www.openagentskill.com/api/skills/gosuda-portal-expose/install, then install with: npx skills add gosuda/portal-tunnel --skill portal-expose

Metadata Registry

Profil yang dapat dibaca Agent untuk pemilihan skill otomatis.

API Registry menyediakan sinyal keputusan, kepercayaan, audit, use case, dan pemasangan tanpa mengikis UI.

Buka Manifest

Kecocokan Agent

72/100

Local desktop

Platform

Claude Code, Browser agents

Laporan audit

Berisiko · 80/100

Tinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.

Lihat laporan auditLihat laporan evaluasi

Panel keputusan Agent

Companion skill for Local desktop

Shortlist this skill and compare it with close alternatives before production adoption.

72
Kesiapan
Shortlist
Tahap

Peran di stack

Skill pendamping

Kecocokan utama

Local desktop

Label kepercayaan

Shortlist kuat

Jalur pemasangan

Perintah siap

Gunakan saat

  • alur kerja Local desktop
  • Tim Claude Code
  • builders willing to evaluate younger projects

Bukti

  • recent repository activity
  • install command or GitHub repo available
  • profil kualitas 71/100
  • 5 event interaksi OpenAgentSkill

tinjau dulu

  • No major risk signals from current metadata

Jalur implementasi

  1. 1Pasang di Agent sandbox dan jalankan satu tugas Local desktop dari awal hingga akhir.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Profil kepercayaan

Hanya sandbox

Kandidat berguna dengan sinyal kepercayaan yang kurang atau bercampur. Gunakan di ruang kerja terisolasi hingga loop hasil membuktikan kecocokan tugas.

67
Trust Score OpenAgentSkill

Adopsi GitHub

Info

263 star GitHub

Aktivitas star/fork

Periksa

263 star dan 29 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

1 hari sejak push

Kejelasan lisensi

Lulus

MIT

Sinyal positif

  • Tinjauan AI disetujui
  • Jalur pemasangan tersedia
  • Bukti repositori tersedia
  • Repositori yang baru dipelihara
  • Perintah pemasangan tidak memiliki pola berisiko tinggi yang jelas
  • Loop hasil siap tetapi membutuhkan eksekusi Agent nyata pertama

Tinjau sebelum memasang

  • Financial research output is not financial advice; require human review before any live investment decision.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • Quality score needs review
  • Permission surface needs review: shell or command execution, filesystem or document access
  • Stars/forks activity: 263 stars, 29 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, external package install surface
  • Permission surface: shell or command execution, filesystem or document access
  • Belum ada laporan hasil Agent nyata
  • Tinjauan manusia diperlukan sebelum pemasangan tanpa pengawasan

Tindakan yang disarankan

Jalankan hanya dalam sandbox dan bandingkan alternatif terdekat sebelum digunakan untuk kerja nyata.

Profil kualitas

Kuat kandidat untuk alur kerja Agent

Solid option that is likely worth shortlisting for production workflows.

71
Star GitHub
263
Keterkinian
1 hari lalu
Siap dipasang
Ya
Lisensi
MIT

Kecocokan alur kerja

Gunakan skill ini pada skenario berikut

Kecocokan alur kerja

Tambahkan ke alur kerja lengkap

Daftar alternatif

Bandingkan sebelum memasang

Similar skills that may fit this task.

Bandingkan semua

Ringkasan

--- name: portal-expose description: Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint and report its lifecycle. Use when the user asks to deploy, publish, share, tunnel, expose, create a public preview, add a paid route, or configure x402 for a local app with Portal. Do not use for deploying a Portal relay, generic cloud hosting, or publishing this plugin. license: MIT ---

# Expose an App with Portal

Portal publishes a service that is already running on the user's machine. It does not build the app or move it to a cloud host. Treat a successful tunnel as dependent on both the local app and the Portal process or agent remaining available.

Read `references/portal-cli.md` when choosing commands or persistent-agent configuration. Read `references/x402.md` whenever the user requests x402 or a paid route. Read `references/safety-and-verification.md` before exposing a nontrivial project, a service with authentication, or any non-HTTP port. Read `references/game-hosting.md` whenever the user asks to host, publish, or share a game server — it covers game-specific ports, protocol identification, relay raw-transport prerequisites, and raw-endpoint verification.

## Choose the Mode

Use the smallest mode that satisfies the request:

- Temporary web preview: `portal expose <target>`. - Trusted static directory or HTML entry: `portal expose --serve <path>`. - Multiple local HTTP services under one URL: repeat `--http-route`. - Paid HTTP path: routed HTTP with an explicit x402 payment contract; never enable payment implicitly. - Durable tunnel that should survive terminal or login restarts: an explicit `portal agent` config and managed service. - Session-owned durable tunnel without an OS service: `portal agent run --foreground`. - Game server (Minecraft, Terraria, Palworld, or any dedicated game server): always start from `references/game-hosting.md` — raw TCP/UDP transport has different prerequisites and verification than HTTP.

Default to a temporary preview when the user says only "share", "preview", or "deploy locally". Do not install an OS service unless the user asks for a persistent, managed, or restart-surviving tunnel and accepts that `portal agent run` without `--foreground` installs a per-user launchd or systemd unit.

## Workflow

### 1. Inspect the Project

- Read the applicable repository instructions before running or changing anything. - Determine the app directory, start command, expected protocol, loopback target, and a meaningful health path. - Prefer declared scripts and documented ports over guessing from process lists. - Do not expose a port merely because it is listening. Tie it to the requested app. - If the project is already running, preserve its process. If it is not running and deployment was requested, start it with the project's normal command and retain the terminal/session handle.

Ask one concise question only when the target, desired lifetime, or transport cannot be discovered safely. An explicit request to deploy, publish, expose, tunnel, or share authorizes creating the public tunnel for the named app; it does not authorize exposing adjacent services.

For x402, do not guess the protected path, payment methods, amount, network, recipient, or network-specific asset. Collect any missing consequential value before building the command or config. Treat an omitted method list as charging every method on the route and confirm that scope when it was not explicit.

### 2. Verify the Local Service

- Wait for the app's real readiness signal, not only for the process to exist. - Make a bounded local request to the selected target. For HTTP, record the URL and status. For TCP/UDP, use a protocol-appropriate check that does not mutate application data. - Stop before opening a tunnel if the local health check fails. - Warn and require explicit direction before exposing databases, container daemons, debug consoles, unauthenticated admin panels, or services containing sensitive data. - Before opening the tunnel, say that the public hostname is listed on participating relays and visible via `portal list` unless the user asked for `--hide`.

### 3. Check Portal

- Run `portal version` when `portal` is available. - If Portal is missing, present the official install method and request approval before running it because installation writes outside the project. Never execute an installer from an unknown relay or third-party URL. - Do not assume a hard-coded latest release or stale flags. Use the installed version and the checked-in Portal reference as the compatibility baseline.

### 4. Build the Command or Agent Config

- Use loopback targets such as `127.0.0.1:<port>` unless the project explicitly needs another address. - Use the user's requested name. Otherwise omit `--name` for a temporary preview or derive a stable DNS-label-safe name for a persistent tunnel. - For `portal expose`, always pass an absolute `--identity-path` outside the repository. The CLI default is `identity.json` in the process working directory and that file contains private key material. For `portal agent`, omit `identity_path` so the agent stores identity under its state directory; if you set the field, use an absolute path outside the repository. - Never print or commit identity JSON, control tokens, facilitator tokens, or wallet secrets. - With a user-selected relay on `portal expose`, pass `--relays <https-url> --discovery=false`. In persistent mode those flags are not accepted on `portal agent run`; put `relays = ["https://..."]` and `discovery = false` on the `[[tunnels]]` entry instead. - The MITM self-probe always runs. Without `--ban-mitm` / `ban_mitm = true`, a suspected TLS termination is only logged and the tunnel keeps serving. Do not claim the default path blocks a relay. Add `--ban-mitm` only when the user wants fail-closed handling. There is no flag that disables the probe. - Never add TCP, UDP, multi-hop, payment, or public metadata flags that the user did not request. `--hide` is the exception for listing: mention the default public listing, then add `--hide` or `hide = true` only when the user wants the tunnel unlisted. - For a paid route, follow `references/x402.md`. Keep payment policy on the smallest requested path, use an explicit network, and never place wallet or facilitator secrets in a command, log, committed file, or final response.

Before executing, show the exact public target and any important exposure consequence when it is not already obvious from the user's request.

### 5. Start and Observe the Tunnel

- Run a temporary `portal expose` in a foreground PTY or managed long-running command session. Do not hide it behind an untracked `nohup` process. - For persistent mode, inspect any existing agent config and running service first. `run`, `restart`, and `stop` are service-wide: they affect every `[[tunnels]]` entry that the selected service owns. Reuse and merge the existing config when the same agent should keep other tunnels. An isolated second agent needs its own config, `service_name`, `state_dir`, and loopback `control_addr`. Changing only `service_name` still shares the default state directory and `127.0.0.1:4018`. Do not stop or replace an agent that already owns unrelated tunnels. - Create or update only the selected agent config, then start it with `portal agent run --config <path>` after the user accepts OS-service installation, or `portal agent run --foreground --config <path>` when the current session should own the process. `--foreground` opens the interactive dashboard when stdin and stdout are TTYs. Run that command in a non-TTY managed session so logs stay capturable and the TUI does not start. - Do not run `portal agent dashboard`. It is an interactive TUI. Give the user that command in the handoff. - Capture bounded output. Redact tokens, identity material, signed payloads, and credentials. - HTTP tunnels are ready when a public URL is emitted. Raw TCP/UDP tunnels log `raw transport endpoints allocated` with `tcp_addr` and/or `udp_addr` instead of `service ready at <URL>`. Do not wait for an HTTPS URL on a raw transport.

### 6. Verify the Public Endpoint

- For HTTP, make a bounded HTTPS request to every public URL being handed off. A deliberately authenticated app may return `401` or `403`; explain that as reachable but protected. Treat unexpected `5xx`, TLS errors, or a Portal error page as a failed deployment. - For each paid route, make an unpaid request with a protected method and require `402 Payment Required` plus a payment-requirements header. Compare the returned network, asset, recipient, amount, and resource with the requested policy. Verify the method scope by requesting an intentionally unprotected method when one exists. Never spend funds merely to verify configuration. - For raw TCP or UDP, protocol-probe the allocated `tcp_addr`/`udp_addr` without mutating application data. A successful local port open is not enough. - When a browser-capable tool is available and the app has UI, load the primary page and check for an obvious render or runtime failure. Do not log in or submit data unless the user requested it. - Re-check the local health endpoint if the public request fails so the handoff distinguishes app failure from tunnel or relay failure.

### 7. Hand Off the Result

Report:

- Deployment mode and exact local target. - Public URL or allocated raw endpoint, and the verified status. - Whether the tunnel is listed on public relays or hidden with `--hide`. - Whether MITM handling is detect-only or `--ban-mitm`. - For x402, the protected paths and methods, human amount, network, public recipient, facilitator mode, and whether the unpaid `402` challenge was verified. State explicitly when settlement was not tested. - The identity path and that it must stay out of version control. - The app and Portal process/session or OS-service ownership. - The exact stop or restart command, and whether that command affects other tunnels on the same agent. - Anything that remains temporary, unavailable, or unverified.

Do not call the result permanent when the local machine, app process, or foreground tunnel must remain running.

## Failure Rules

- Local app unhealthy: stop before exposing it and report the failing check. - Portal absent and installation not approved: provide the official command without executing it. - No ready public URL or allocated raw endpoint: keep the bounded diagnostic output and report the relay/tunnel failure. - Paid route returns anything other than the expected `402` challenge: do not describe it as protected or hand it off as ready. Stop only the tunnel created by this workflow, preserve bounded diagnostics, and report the policy mismatch. - MITM self-probe warning without `--ban-mitm`: report the warning and offer `--ban-mitm`; do not claim the relay was blocked. - Requested name unavailable: offer an auto-generated or alternative name; do not silently hijack another identity. - Existing agent owns other tunnels: do not stop or replace it to publish this app. - Cancellation: stop only processes started by this workflow, unless the user explicitly asks to stop an existing app or agent.

Detail teknis

Versi
1.0.0
Lisensi
MIT
Pembaruan terakhir
22 Agu 2026
Diterbitkan
22 Agu 2026

Ringkasan keputusan

Skill pendamping

72
Siap
Shortlist
Tahap

recent repository activity

Audit

Tinjauan pemasangan

Tinjauan pemasangan dan adopsi

80
Berisiko
Keamanan
79/100
Pemeliharaan
100/100
Pasang
92/100
Buka audit lengkapLihat laporan evaluasi

Bukti tervalidasi Agent

Bukti tervalidasi Agent

Laporan hasil setelah resolve, tinjau, pasang, dan satu eksekusi terbatas.

0
Terbukti
Needs first agent runPasang otomatis: tinjau duluTerakhir: Tidak diketahui
Tingkat sukses
Kegagalan terbaru
Hasil
0
Kualitas output
Gagal
0
Tidak relevan
0
Pemasangan
0
Diblokir risiko
0
Perlu penyiapan
0
Produksi
0

Belum ada data hasil Agent. Eksekusi pertama dapat melaporkan keberhasilan, kebutuhan setup, blok risiko, kegagalan, atau tidak relevan melalui /api/agent/outcome.

Pasang

Tambahkan ke alur Agent

Gratis dan sumber terbuka. Tinjau laporan sebelum memasang pada Agent produksi.

Siklus pertumbuhan

Kit berbagi

X

Draf berbasis skenario untuk portal-expose, siap untuk posting manual di X.

Catatan kurator
A practical pick for a web workflow:

portal-expose: Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested...

263 stars

https://www.openagentskill.com/skills/gosuda-portal-expose?ref=x
Buka draf X
Balasan opsional dengan perintah pemasangan
Listing + install path for portal-expose:
https://www.openagentskill.com/skills/gosuda-portal-expose?ref=x

Install: npx skills add gosuda/portal-tunnel --skill portal-expose
Buka draf balasan

Sumber listing

Diindeks Registry

Dapat diklaim

Listing ini diindeks dari sumber publik dan belum ditandai resmi hingga klaim pemelihara disetujui.

Kreator
gosuda
Diindeks oleh
Indeks komunitas OpenAgentSkill

Atribusi menautkan ke repositori publik atau profil kreator. Kreator dapat mengklaim listing untuk memperbarui sinyal kepemilikan.

Klaim skill ini

Klaim pemilik

Klaim listing skill ini

Listing Diindeks Registry ini dikaitkan dengan gosuda, tetapi belum ditandai resmi. Klaim untuk menambahkan sinyal pemilik terverifikasi dan membuat pembaruan peluncuran, pemasangan, serta audit berikutnya lebih tepercaya.

Kit backlink kreator

Tambahkan badge bukti ke README Anda

Tampilkan listing kanonis, sinyal kepercayaan dan audit saat ini, serta bukti Agent-Proven nyata di tempat pengembang mengevaluasi repositori.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/gosuda-portal-expose?metric=listed&label=Listed)](https://www.openagentskill.com/skills/gosuda-portal-expose)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/gosuda-portal-expose?metric=trust&label=Trust)](https://www.openagentskill.com/skills/gosuda-portal-expose)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/gosuda-portal-expose?metric=audit&label=Audit)](https://www.openagentskill.com/skills/gosuda-portal-expose/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/gosuda-portal-expose?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/gosuda-portal-expose)

Penulis

G

gosuda

@gosuda

Kecocokan platform

Sinyal kesehatan

Star GitHub
263
Skor kualitas
40/100
Push GitHub terakhir
22 Agu 2026
Petunjuk framework
Tidak diketahui
Tampilan OpenAgentSkill
5
Salinan pemasangan
0
Klik keluar
0

Sinyal komunitas

Bagikan apakah skill ini bermanfaat untuk alur kerja Agent Anda. Masukan gabungan meningkatkan peringkat dari waktu ke waktu.

Kepercayaan & keamanan

Hanya sandbox

67
  • Adopsi GitHub263 star GitHubInfo
  • Aktivitas star/fork263 star dan 29 fork; aktivitas issue tidak tersedia dalam metadata saat iniPeriksa
  • Pemeliharaan terbaru1 hari sejak pushLulus
  • Kejelasan lisensiMITLulus
  • Kelengkapan README/SKILL.mdMetadata memuat konteks penggunaan dan alur kerja yang cukupLulus
  • Risiko dependensi/runtimecommand execution surface, external package install surfacePeriksa