跳到主要内容
知仓学习社ZHICANG

onecli-gateway

>-

执行命令联网无严重或高危命中nanocoai/nanoclaw

它会碰到什么

扫了多少2 个文本文件,4 KB
它会碰到什么执行命令联网
命中总数3 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

OneCLI Gateway

Your outbound HTTPS traffic is transparently proxied through the OneCLI

gateway, which injects stored credentials at the proxy boundary. You never

see or handle credential values directly.

How to Access External Services

You have direct HTTP access to external APIs. OAuth apps (Gmail, GitHub,

Google Calendar, Google Drive, etc.) and API key services are all available

through the gateway. Just make the request directly; the gateway injects

credentials if the app is connected. If not, it returns an error with a

connect URL you can present to the user.

Making Requests

Call the real API URL. The gateway intercepts the request and injects

credentials automatically.

curl -s "https://gmail.googleapis.com/gmail/v1/users/me/messages?maxResults=5"
curl -s "https://api.github.com/user/repos?per_page=10"
curl -s "https://api.stripe.com/v1/charges?limit=5"

Standard HTTP clients (curl, fetch, requests, axios, Go net/http, git) all

honor the HTTPS_PROXY environment variable automatically. You do not need

to set any auth headers.

Credential Stubs for MCP Servers

Some MCP servers need local credential files to start. Stubs for connected

apps are pre-written automatically. Files containing "onecli-managed"

values are managed by OneCLI — do NOT modify or delete them.

If an MCP server won't start due to missing credentials, create stubs

before starting it. Use "onecli-managed" as the placeholder for all

secret values, with file permissions 0600. See the guide at:

https://www.onecli.sh/docs/guides/credential-stubs/general-app

When a Request Fails

If you get a 401, 403, or a gateway error (e.g., app_not_connected):

Step 1 — Show the user a connect link. Use the connect_url from the

error response:

> To connect [service], open this link:

> [connect_url from the error response]

If there is no connect_url in the error, tell the user to open the

OneCLI dashboard and connect the service there.

Step 2 — Retry after the user connects. Let the user know you will

retry once they have connected. When they confirm, retry the original

request. If the retry still fails, ask if they need help with the setup.

Rules

  • Never say "I don't have access to X" without first making the HTTP

request through the proxy.

  • Never use browser extensions, gcloud, or manual auth flows. The

gateway handles credentials for you.

  • Never ask the user for API keys or tokens directly. Direct them to

connect the service in the OneCLI dashboard.

  • Never suggest the user open Gmail/Calendar/GitHub in their browser

when they ask you to read or interact with those services. You have API

access. Use it.

  • If the gateway returns a policy error (403 with a JSON body), respect

the block. Do not retry or circumvent it.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 30,781
本站分层T1
该仓技能数61
原文件路径container/skills/onecli-gateway/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 61 个技能