iron-proxy-gateway
Use Iron Proxy for external accounts and APIs, including GitHub through gh. Connect credentials through the operator console and diagnose blocked requests without exposing tokens or adding unnecessary MCP servers.
Install / Use
npx skills add nanocoai/nanoclaw --skill iron-proxy-gatewayInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of iron-proxy-gateway
iron-proxy-gateway scores 90/100 on our quality scale, 497th of 2,860 Development & Engineering skills we index (top 18%).
Its SKILL.md is 2.3 KB long, split into 4 sections with 1 code example: moderately detailed.
With 30,846 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 3 days ago, so iron-proxy-gateway is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
iron-proxy-gateway compared with similar skills
All 4 of these similar skills score higher than iron-proxy-gateway; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| iron-proxy-gateway (this skill)by nanocoai | 90 | 30.8k | 3d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 85.7k | 12d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 73.9k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.4k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.1k | today | CLAUDE.md |
Frequently asked questions
- How do I install iron-proxy-gateway?
- Run
npx skills add nanocoai/nanoclaw --skill iron-proxy-gateway. The install tabs above show the steps for each supported agent. - Which AI agents does iron-proxy-gateway work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is iron-proxy-gateway safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is iron-proxy-gateway still maintained?
- The repository was last updated 3 days ago, so iron-proxy-gateway is actively maintained.
Skill content
View source on GitHubname: iron-proxy-gateway description: Use Iron Proxy for external accounts and APIs, including GitHub through gh. Connect credentials through the operator console and diagnose blocked requests without exposing tokens or adding unnecessary MCP servers. compatibility: Requires HTTP_PROXY, HTTPS_PROXY, and the Iron Proxy CA injected by NanoClaw. metadata: author: nanoclaw version: "1.0.0"
Iron Proxy gateway
Your outbound HTTP and HTTPS requests pass through your session's Iron Proxy. A policy-selected credential request waits for human approval before the proxy inserts a credential. You receive only a useless placeholder.
Policy failures
A bare 403 does not prove which layer rejected the request. It may be the destination rule, credential grant, human approval, or upstream API. Respect the block, report the hostname and observed error, and request a host-side check instead of guessing that credentials were never injected.
Connect an account
Run the shared command for the API hostname requested by the user:
ncl groups connect --host <API hostname>
Return the exact connect_url and describe its action. An operator_console
handoff requires the operator to configure the credential, grant, and destination
in the gateway; it is not an OAuth link. Do not invent a connection flow when the
result is unsupported. The command does not grant access or change policy.
Use the user's requested CLI or a direct HTTP client. Do not add an MCP server
merely to connect an account. Clients requiring local authentication may use
gateway-managed as a non-secret placeholder (for example GH_TOKEN for gh).
Never use a real token in the client. Never run a local login to store credentials.
Request approval and account connection are separate. A 401 is not proof that injection did not happen: the stored token may itself be invalid. Report the observed result, follow the shared handoff, and verify with a credentialed request after the operator completes configuration. Never claim connected before success.
Rules
- Never ask for, print, or store a raw API key or OAuth token.
- Never bypass the configured proxy or its CA validation.
- Never treat a pending approval as granted.
- Never claim a blocked destination is connected.
- Treat proxy errors as policy or operator-configuration errors, not as permission to weaken TLS.
Related Skills
Agent-Reach
85.7kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
73.9kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.4k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.1kOpen-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
