portal-expose
Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint and report its lifecycle. Use when the user asks to deploy, publish, share, tunnel,
供给资产档案
编程与开发 Agent
代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。
场景
编程 Agent
我需要一个能理解仓库、修改代码并审查 Pull Request 的编程 Agent。
适配 Agent
Claude Code + Browser agents + CLI
适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。
安装
就绪
npx skills add gosuda/portal-tunnel --skill portal-expose
维护状态
新鲜
今天有推送
风险
高风险
Dependency or permission surface needs review
GitHub 质量
263
71/100 质量 · 75/100 信任
覆盖标签
审查说明
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent 采用评分卡
一眼查看信任、审计与安装准备度
这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。
质量
强可靠的选择,值得加入生产工作流候选列表。
信任
仅限沙盒有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。
审计
高风险对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。
OpenAgentSkill 信任评分 v5
仅限沙盒
仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。
Stars
263 个 GitHub Stars
仓库活跃度
263 个 Star,29 个 Fork
维护状态
今天有推送
许可证
MIT
安装
npx skills add gosuda/portal-tunnel --skill portal-expose
安装安全性
标准软件包或运行时安装路径
权限范围
shell or command execution, filesystem or document access
Agent 结果
暂未有 Agent 结果数据
文档
README/SKILL.md 上下文充分
风险摘要
生产前审查
- Financial research output is not financial advice; require human review before any live investment decision.
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
安装准备度
安装路径可用
- 安装路径可用
- 仓库证据可用
- 已声明许可证
- 暂无 Agent 验证结果证据
Agent 可读元数据
这个 Skill 的机器可读决策数据。
使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。
适用任务
- Local desktop 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
- Navigate local resources
适用 Agent
安装决策
- 命令
- npx skills add gosuda/portal-tunnel --skill portal-expose
- 策略
- 阻止
- 人工审查
- 是
信任与风险
- 信任
- 67/100
- 审计
- 80/100
- 风险级别
- 高风险
结果闭环
- 端点
- /api/agent/outcome
- 事件 ID
- resolve
- 结果
- 5
不适用场景
- 需要厂商支持 SLA 的团队
- 没有内部安全审查的高合规环境
- 暂未有 OpenAgentSkill 使用反馈数据
- Audit risk risky exceeds max_risk=medium
- 高风险权限提示:Shell 或命令执行
Agent 安全 v2
48/100 · 避免自动安装
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
高
Shell 或命令执行
Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。
中
Browser automation
Skill may drive a browser or interact with web pages.
中
网络访问
Skill 可能访问远程页面、API、仓库或外部服务。
中
文件系统访问
Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。
- Audit risk risky exceeds max_risk=medium
- 高风险权限提示:Shell 或命令执行
- Dependency or permission surface needs review
安装目标
在你的 Agent 工作流中安装此 Skill
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install gosuda-portal-exposeAgent 解析计划
让 Agent 在安装前验证匹配度。
Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。
打开 JSON
/api/agent/resolve?task=Use%20portal-expose%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve 文本
/api/agent/resolve?task=Use%20portal-expose%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
安装交接
/api/skills/gosuda-portal-expose/install
Agent 应检查
- 从 Resolve API 检查任务匹配与替代方案。
- 检查审计评分、信任评分和安全策略警告。
- 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。
复制提示词
Task: Use portal-expose in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20portal-expose%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/gosuda-portal-expose/install
Install command: npx skills add gosuda/portal-tunnel --skill portal-expose
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent 交接
把安装路径交给 Agent,而不是再给一个目录页。
通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。
安装交接
/api/skills/gosuda-portal-expose/install
LLM 文本格式
/api/skills/gosuda-portal-expose/install?format=text
寻找替代方案
/api/skills/search?q=portal-expose&limit=3
Agent 提示词
Use portal-expose for this task. Review https://www.openagentskill.com/api/skills/gosuda-portal-expose/install, then install with: npx skills add gosuda/portal-tunnel --skill portal-exposeRegistry 元数据
用于自动选择 Skill 的 Agent 可读档案。
本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。
Manifest
/api/registry/manifest/gosuda-portal-expose
LLM 文本
/api/registry/manifest/gosuda-portal-expose?format=text
安装别名
/api/registry/install/gosuda-portal-expose
推荐
/api/registry/recommend?task=Use%20portal-expose%20in%20an%20agent%20workflow&limit=3
适配 Agent
Local desktop
平台
Claude Code, Browser agents
Agent 决策面板
Fallback candidate for Local desktop
先用此 Skill 做原型验证,并保留备选方案。
栈中角色
备选候选
主要匹配
Local desktop
信任标签
先做原型验证
安装路径
命令已就绪
适用场景
- Local desktop 工作流
- Claude Code 团队
- builders willing to evaluate younger projects
证据
- 仓库近期活跃
- 已提供安装命令或 GitHub 仓库
- 71/100 质量档案
先审查
- 暂未有 OpenAgentSkill 使用反馈数据
实施路径
- 1在沙盒 Agent 中安装它,并端到端完成一次Local desktop任务。
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
信任档案
仅限沙盒
有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。
GitHub 采用度
信息263 个 GitHub Stars
Star/Fork 活跃度
检查263 个 Star,29 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过今天有推送
许可证清晰度
通过MIT
积极信号
- AI 审查已通过
- 安装路径可用
- 仓库证据可用
- 近期维护的仓库
- 安装命令未发现明显高风险模式
- 结果闭环已就绪,但需要首次真实 Agent 运行
安装前审查
- Financial research output is not financial advice; require human review before any live investment decision.
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
- Quality score needs review
- Permission surface needs review: shell or command execution, filesystem or document access
- Stars/forks activity: 263 stars, 29 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, external package install surface
- Permission surface: shell or command execution, filesystem or document access
- 暂未有真实 Agent 结果报告
- 无人值守安装前需要人工审查
建议操作
仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。
质量档案
强 适用于 Agent 工作流的候选
可靠的选择,值得加入生产工作流候选列表。
工作流匹配
在这些场景使用此 Skill
Operate local tools
Local desktop
I need my agent to operate local files and desktop apps in a repeatable workflow.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
工作流匹配
加入完整工作流
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Scrape, clean, and reuse web data
Web data pipeline
A practical workflow for agents that crawl public pages, extract clean content, normalize data, and hand it to downstream research or RAG workflows.
替代方案短名单
安装前对比
可能适合该任务的相近 Skill。
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
MoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
Cua
Open-source infrastructure for Computer-Use Agents. Sandboxes, SDKs, and benchmarks to train and evaluate AI agents that can control full desktops (macOS, Linux, Windows).
概览
--- name: portal-expose description: Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested TCP/UDP service reachable through Portal, then verify the public endpoint and report its lifecycle. Use when the user asks to deploy, publish, share, tunnel, expose, create a public preview, add a paid route, or configure x402 for a local app with Portal. Do not use for deploying a Portal relay, generic cloud hosting, or publishing this plugin. license: MIT ---
# Expose an App with Portal
Portal publishes a service that is already running on the user's machine. It does not build the app or move it to a cloud host. Treat a successful tunnel as dependent on both the local app and the Portal process or agent remaining available.
Read `references/portal-cli.md` when choosing commands or persistent-agent configuration. Read `references/x402.md` whenever the user requests x402 or a paid route. Read `references/safety-and-verification.md` before exposing a nontrivial project, a service with authentication, or any non-HTTP port. Read `references/game-hosting.md` whenever the user asks to host, publish, or share a game server — it covers game-specific ports, protocol identification, relay raw-transport prerequisites, and raw-endpoint verification.
## Choose the Mode
Use the smallest mode that satisfies the request:
- Temporary web preview: `portal expose <target>`. - Trusted static directory or HTML entry: `portal expose --serve <path>`. - Multiple local HTTP services under one URL: repeat `--http-route`. - Paid HTTP path: routed HTTP with an explicit x402 payment contract; never enable payment implicitly. - Durable tunnel that should survive terminal or login restarts: an explicit `portal agent` config and managed service. - Session-owned durable tunnel without an OS service: `portal agent run --foreground`. - Game server (Minecraft, Terraria, Palworld, or any dedicated game server): always start from `references/game-hosting.md` — raw TCP/UDP transport has different prerequisites and verification than HTTP.
Default to a temporary preview when the user says only "share", "preview", or "deploy locally". Do not install an OS service unless the user asks for a persistent, managed, or restart-surviving tunnel and accepts that `portal agent run` without `--foreground` installs a per-user launchd or systemd unit.
## Workflow
### 1. Inspect the Project
- Read the applicable repository instructions before running or changing anything. - Determine the app directory, start command, expected protocol, loopback target, and a meaningful health path. - Prefer declared scripts and documented ports over guessing from process lists. - Do not expose a port merely because it is listening. Tie it to the requested app. - If the project is already running, preserve its process. If it is not running and deployment was requested, start it with the project's normal command and retain the terminal/session handle.
Ask one concise question only when the target, desired lifetime, or transport cannot be discovered safely. An explicit request to deploy, publish, expose, tunnel, or share authorizes creating the public tunnel for the named app; it does not authorize exposing adjacent services.
For x402, do not guess the protected path, payment methods, amount, network, recipient, or network-specific asset. Collect any missing consequential value before building the command or config. Treat an omitted method list as charging every method on the route and confirm that scope when it was not explicit.
### 2. Verify the Local Service
- Wait for the app's real readiness signal, not only for the process to exist. - Make a bounded local request to the selected target. For HTTP, record the URL and status. For TCP/UDP, use a protocol-appropriate check that does not mutate application data. - Stop before opening a tunnel if the local health check fails. - Warn and require explicit direction before exposing databases, container daemons, debug consoles, unauthenticated admin panels, or services containing sensitive data. - Before opening the tunnel, say that the public hostname is listed on participating relays and visible via `portal list` unless the user asked for `--hide`.
### 3. Check Portal
- Run `portal version` when `portal` is available. - If Portal is missing, present the official install method and request approval before running it because installation writes outside the project. Never execute an installer from an unknown relay or third-party URL. - Do not assume a hard-coded latest release or stale flags. Use the installed version and the checked-in Portal reference as the compatibility baseline.
### 4. Build the Command or Agent Config
- Use loopback targets such as `127.0.0.1:<port>` unless the project explicitly needs another address. - Use the user's requested name. Otherwise omit `--name` for a temporary preview or derive a stable DNS-label-safe name for a persistent tunnel. - For `portal expose`, always pass an absolute `--identity-path` outside the repository. The CLI default is `identity.json` in the process working directory and that file contains private key material. For `portal agent`, omit `identity_path` so the agent stores identity under its state directory; if you set the field, use an absolute path outside the repository. - Never print or commit identity JSON, control tokens, facilitator tokens, or wallet secrets. - With a user-selected relay on `portal expose`, pass `--relays <https-url> --discovery=false`. In persistent mode those flags are not accepted on `portal agent run`; put `relays = ["https://..."]` and `discovery = false` on the `[[tunnels]]` entry instead. - The MITM self-probe always runs. Without `--ban-mitm` / `ban_mitm = true`, a suspected TLS termination is only logged and the tunnel keeps serving. Do not claim the default path blocks a relay. Add `--ban-mitm` only when the user wants fail-closed handling. There is no flag that disables the probe. - Never add TCP, UDP, multi-hop, payment, or public metadata flags that the user did not request. `--hide` is the exception for listing: mention the default public listing, then add `--hide` or `hide = true` only when the user wants the tunnel unlisted. - For a paid route, follow `references/x402.md`. Keep payment policy on the smallest requested path, use an explicit network, and never place wallet or facilitator secrets in a command, log, committed file, or final response.
Before executing, show the exact public target and any important exposure consequence when it is not already obvious from the user's request.
### 5. Start and Observe the Tunnel
- Run a temporary `portal expose` in a foreground PTY or managed long-running command session. Do not hide it behind an untracked `nohup` process. - For persistent mode, inspect any existing agent config and running service first. `run`, `restart`, and `stop` are service-wide: they affect every `[[tunnels]]` entry that the selected service owns. Reuse and merge the existing config when the same agent should keep other tunnels. An isolated second agent needs its own config, `service_name`, `state_dir`, and loopback `control_addr`. Changing only `service_name` still shares the default state directory and `127.0.0.1:4018`. Do not stop or replace an agent that already owns unrelated tunnels. - Create or update only the selected agent config, then start it with `portal agent run --config <path>` after the user accepts OS-service installation, or `portal agent run --foreground --config <path>` when the current session should own the process. `--foreground` opens the interactive dashboard when stdin and stdout are TTYs. Run that command in a non-TTY managed session so logs stay capturable and the TUI does not start. - Do not run `portal agent dashboard`. It is an interactive TUI. Give the user that command in the handoff. - Capture bounded output. Redact tokens, identity material, signed payloads, and credentials. - HTTP tunnels are ready when a public URL is emitted. Raw TCP/UDP tunnels log `raw transport endpoints allocated` with `tcp_addr` and/or `udp_addr` instead of `service ready at <URL>`. Do not wait for an HTTPS URL on a raw transport.
### 6. Verify the Public Endpoint
- For HTTP, make a bounded HTTPS request to every public URL being handed off. A deliberately authenticated app may return `401` or `403`; explain that as reachable but protected. Treat unexpected `5xx`, TLS errors, or a Portal error page as a failed deployment. - For each paid route, make an unpaid request with a protected method and require `402 Payment Required` plus a payment-requirements header. Compare the returned network, asset, recipient, amount, and resource with the requested policy. Verify the method scope by requesting an intentionally unprotected method when one exists. Never spend funds merely to verify configuration. - For raw TCP or UDP, protocol-probe the allocated `tcp_addr`/`udp_addr` without mutating application data. A successful local port open is not enough. - When a browser-capable tool is available and the app has UI, load the primary page and check for an obvious render or runtime failure. Do not log in or submit data unless the user requested it. - Re-check the local health endpoint if the public request fails so the handoff distinguishes app failure from tunnel or relay failure.
### 7. Hand Off the Result
Report:
- Deployment mode and exact local target. - Public URL or allocated raw endpoint, and the verified status. - Whether the tunnel is listed on public relays or hidden with `--hide`. - Whether MITM handling is detect-only or `--ban-mitm`. - For x402, the protected paths and methods, human amount, network, public recipient, facilitator mode, and whether the unpaid `402` challenge was verified. State explicitly when settlement was not tested. - The identity path and that it must stay out of version control. - The app and Portal process/session or OS-service ownership. - The exact stop or restart command, and whether that command affects other tunnels on the same agent. - Anything that remains temporary, unavailable, or unverified.
Do not call the result permanent when the local machine, app process, or foreground tunnel must remain running.
## Failure Rules
- Local app unhealthy: stop before exposing it and report the failing check. - Portal absent and installation not approved: provide the official command without executing it. - No ready public URL or allocated raw endpoint: keep the bounded diagnostic output and report the relay/tunnel failure. - Paid route returns anything other than the expected `402` challenge: do not describe it as protected or hand it off as ready. Stop only the tunnel created by this workflow, preserve bounded diagnostics, and report the policy mismatch. - MITM self-probe warning without `--ban-mitm`: report the warning and offer `--ban-mitm`; do not claim the relay was blocked. - Requested name unavailable: offer an auto-generated or alternative name; do not silently hijack another identity. - Existing agent owns other tunnels: do not stop or replace it to publish this app. - Cancellation: stop only processes started by this workflow, unless the user explicitly asks to stop an existing app or agent.
技术详情
- 版本
- 1.0.0
- 许可证
- MIT
- 最近更新
- 2026年8月22日
- 发布时间
- 2026年8月22日
决策摘要
备选候选
仓库近期活跃
Agent 验证证据
Agent 验证证据
来自解析、审查、安装和一次小范围运行后的结果报告。
- 成功率
- —
- 近期失败
- —
- 结果
- 0
- 输出质量
- —
- 失败
- 0
- 不相关
- 0
- 安装次数
- 0
- 风险拦截
- 0
- 需要配置
- 0
- 生产环境
- 0
暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。
增长闭环
分享工具包
为 portal-expose 准备的场景化草稿,可手动发布到 X。
A practical pick for a web workflow: portal-expose: Expose, preview, protect with x402 payments, or keep a local web app, static site, HTTP route set, or explicitly requested... 263 stars https://www.openagentskill.com/skills/gosuda-portal-expose?ref=x
可选:带安装命令的回复
Listing + install path for portal-expose: https://www.openagentskill.com/skills/gosuda-portal-expose?ref=x Install: npx skills add gosuda/portal-tunnel --skill portal-expose
收录来源
Registry 收录
此列表来自公开来源,维护者认领获批前不会标记为官方。
- 创作者
- gosuda
- 收录方
- OpenAgentSkill 社区索引
归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。
认领此 Skill所有者认领
认领此 Skill 页面
这条 Registry 收录 列表归属于 gosuda,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。
创作者外链工具包
将证据徽章加入你的 README
在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。
[](https://www.openagentskill.com/skills/gosuda-portal-expose)
[](https://www.openagentskill.com/skills/gosuda-portal-expose)
[](https://www.openagentskill.com/skills/gosuda-portal-expose/audit)
[](https://www.openagentskill.com/skills/gosuda-portal-expose)作者
gosuda
@gosuda
健康信号
- GitHub Stars
- 263
- 质量评分
- 40/100
- 最近 GitHub 推送
- 2026年8月22日
- 框架提示
- 未知
- OpenAgentSkill 浏览量
- 0
- 复制安装命令
- 0
- 跳转点击
- 0
社区信号
告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。
信任与安全
仅限沙盒
- GitHub 采用度263 个 GitHub Stars信息
- Star/Fork 活跃度263 个 Star,29 个 Fork; 当前元数据中没有议题活跃度信息检查
- 近期维护今天有推送通过
- 许可证清晰度MIT通过
- README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
- 依赖与运行时风险command execution surface, external package install surface检查
相关 Skill
UI-TARS Desktop
Run multimodal agents that operate desktop interfaces
37.0K StarsMoneyPrinterTurbo
利用AI大模型,一键生成高清短视频 Generate short videos with one click using AI LLM.
88.5K StarsCua
Open-source infrastructure for Computer-Use Agents. Sandboxes, SDKs, and benchmarks to train and evaluate AI agents that can control full desktops (macOS, Linux, Windows).
21.4K Stars