iron-proxy-gateway skillA
iron-proxy-gateway is agent-read markdown (skill) from nanocoai/nanoclaw: Use Iron Proxy for external accounts and APIs, including GitHub through gh. Connect credentials through the operator console and diagnose blocked requests without exposing tokens or adding unnecessary MCP servers..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified before it reaches your agent: the main file against the SHA-256 recorded here, the others against the git hashes of its source commit. The deterministic audit below grades the latest version, and the same checks always give the same file the same grade.
What the file says
# Iron Proxy gateway Your outbound HTTP and HTTPS requests pass through your session's Iron Proxy. A policy-selected credential request waits for human approval before the proxy inserts a credential. You receive only a useless placeholder. ## Policy failures A bare `403` does not prove which layer rejected the request. It may be the destination rule, credential grant, human approval, or upstream API. Respect the block, report the hostname and observed error, and request a host-side check instead of guessing that credentials were never injected. ## Connect an account Run the shared command for the API hostname requested by the user: ```bash ncl groups connect --host <API hostname> ``` Return the exact `connect_url` and describe its `action`. An `operator_console` handoff requires the operator to configure the credential, grant, and destination in the gateway; it is not an OAuth link. Do not invent a connection flow when the result is `unsupported`. The command does not grant access or change policy. Use the user's requested CLI or a direct HTTP client. Do not add an MCP server merely to connect an account. Clients requiring local authentication may use …
Read the whole file at its exact version.
How to install
mdr add nanocoai/nanoclaw/iron-proxy-gateway@v1.0.0mdr add nanocoai/nanoclaw/iron-proxy-gateway@sha256:19a36a1005ce4b8bPin to a label to follow the author's releases, or to a sha256 for exact bytes. Either way the resolved hash is written to mdr.lock, and mdr install fetches those bytes again and checks them, so it installs them exactly or fails.
[](https://markdownregistry.com/a/art_tket7zpwssr7m5tu)
2 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (2391 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
nanocoai/nanoclaw · 30,849 stars · license MIT · pushed 2026-09-27 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_tket7zpwssr7m5tu GET https://markdownregistry.com/api/v1/resolve?ref=nanocoai/nanoclaw/iron-proxy-gateway GET https://markdownregistry.com/api/v1/blob/19a36a1005ce4b8bdfa9dd774244889f38ed8abd5d8981d17afedf1605e74e78
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.