agentCLAWHUBUnverified

pr0xteus

Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and controller-fronted proxies. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.

OpenClaw

Rank

62

Safety

84

Downloads

1.0k

Updated

Oct 11, 2026

Version

0.11.4

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1K downloadsadoption · observed Oct 11, 2026
Latest release
0.11.4release · observed Sep 6, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:pr0xteus
  1. Install using `clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:pr0xteus` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/psyb0t/pr0xteus before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/snapshot"

Run-check

$0.02 USD

1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.

Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.

Documentation

CLAWHUB

148,122 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: pr0xteus
description: Give a trusted self-hosted workload configured WireGuard-backed SOCKS5 and HTTP exits through pr0xteus's bearer-protected private API. Request an operator-approved ISO country or logical pool, inspect leased-cell state, replace a failed assignment with excludeProxy, or integrate the Go client with VPN-only or public-first retry behavior. It uses operator-owned WireGuard bundles, Docker-spawned cells, country routing, fallback pools, and controller-fronted proxies. Use when a service needs controlled country-specific egress without exposing an open proxy or accepting caller-supplied Docker and provider configuration.
homepage: https://github.com/psyb0t/pr0xteus
user-invocable: true
metadata:
  openclaw:
    emoji: "🧬"
    primaryEnv: PR0XTEUS_URL
    requires:
      bins: [bash, curl, docker, jq]
permissions:
  network: "Runtime control-API calls go only to the user-configured PR0XTEUS_URL. Traffic sent through allocated SOCKS5 or HTTP URLs exits through operator-configured WireGuard infrastructure; use only trusted private control endpoints and operator-approved destination URLs. pkg/client's preflight check additionally makes direct, unproxied calls to api.ipify.org and ifconfig.me to confirm the exit IP actually changed. Setup time (references/setup.md) also reaches raw.githubusercontent.com for the installer and Docker Hub for the pinned image."
  shell: "bash, curl, jq, and explicit Docker commands from references/setup.md for user-requested setup or verification."
  filesystem: "Normal use reads PR0XTEUS_URL and PR0XTEUS_API_TOKEN from the environment. Operator setup writes only gitignored local WireGuard, pool, routing, token, and .env files."
---

# pr0xteus

pr0xteus is the not-an-open-proxy bit between a trusted service and
WireGuard-backed SOCKS5 and HTTP exits. The operator owns the local pool policy. Callers
can ask for an approved country or pool; they cannot smuggle Docker flags,
host paths, images, or arbitrary provider configs into the daemon.

For the actual setup, local config, a complete pool example, and proof that a
controller-fronted proxy exit works, read
[references/setup.md](references/setup.md) before touching the stack.

## Security and safety

- This skill is for an instance the user already runs and trusts. Do not hunt
  through the workspace for tokens, provider bundles, or Docker config. Take
  `PR0XTEUS_URL` and `PR0XTEUS_API_TOKEN` from the environment or ask.
- Allocating a proxy starts or reuses a configured WireGuard cell. It can spend
  provider capacity and sends later traffic through the operator's exit, so
  only request the country, pool, and task the user actually named.
- Returned `socks5://` and `http://` URLs are short-lived bearer capabilities
  for the controller's proxy gateways. Keep them out of logs, issue trackers,
  and public services. Trusted host and container clients can use either; only
  the controller talks to the selected cell's private address.
- pr0xteu

_meta.json

{
  "ownerId": "kn79dhvmpjng4rp2jjk8k0v5xx80ccbk",
  "slug": "pr0xteus",
  "version": "0.11.4",
  "publishedAt": 1788678437786
}

references/setup.md

# pr0xteus setup

Pr0xteus is private egress plumbing. A trusted client receives SOCKS5 and HTTP
proxy URLs only after the controller has started a WireGuard-backed cell and
confirmed a handshake. It is not an internet-facing proxy. Keep the controller on loopback,
remove host bindings for an authenticated private-network gateway, or
deliberately configure another protected bind address. Use WireGuard material
you are allowed to use.

For the full operator walkthrough, see
[docs/complete-example.md](../../../../docs/complete-example.md). This page is
the agent fast path: use the published image and its installer; do not invent
paths, tokens, or Docker flags.

## Operator setup

**Download the installer and read it before running it — never pipe `curl`
straight into a shell.** Confirm it only fetches the pinned image, runs the
image's `config init`, and installs the `pr0xteus` command — then run it.

```bash
# 1. Download (do not pipe curl into a shell).
curl -fsSL https://raw.githubusercontent.com/psyb0t/pr0xteus/main/install.sh -o pr0xteus-install.sh

# 2. Inspect — read the whole thing.
less pr0xteus-install.sh

# 3a. Per-user install (no root): command -> ~/.local/bin, config ->
#     ~/.config/pr0xteus, just for the current user.
bash pr0xteus-install.sh

# 3b. Or system-wide: command -> /usr/local/bin, config -> /etc/pr0xteus
#     (root-owned, readable by the `docker` group so any docker-group operator
#     drives the one shared stack).
sudo bash pr0xteus-install.sh --system
```

The mode auto-detects from who runs it (root → system-wide, otherwise
per-user); force it with `--user` or `--system`. Append `--rolling` to pin the
moving `:latest` instead of the latest release. A per-user install that finds
`~/.local/bin` off `PATH` prints the exact bash/zsh one-liner to add it.

The installer creates ignored local files only when absent (per-user paths
shown; a system-wide install uses `/etc/pr0xteus` instead of `~/.config/pr0xteus`):

```text
~/.config/pr0xteus/secrets/wireguard/*.conf      real provider or private-network files
~/.config/pr0xteus/secrets/pools.yaml            approved logical pools
~/.config/pr0xteus/config/egress-routing.yaml    country -> pool policy
~/.config/pr0xteus/.env                           bearer token, host path, image and ports
~/.config/pr0xteus/.env.example                   refreshed reference; safe to inspect
```

The bearer token is `PR0XTEUS_API_TOKEN` in owner-only `.env`, not a separate
secret file. The installer owns the absolute host path the controller needs
when it asks Docker to bind one chosen file into a cell.

Put an authorized `*.conf` file in `~/.config/pr0xteus/secrets/wireguard/`, then make
the policy match its basename. A file named `us-example.conf` uses `us-example`
below:

```yaml
pools:
  us:
    region: north-america
    purpose: private-service-egress
    configs: [us-example]
    exit_countries:
      us-example: US
```

```yaml
country_to_pool:
  US: us
default_pool: us
```

Start t

skill-card.md

## Description:

Helps trusted developers and operators use a self-hosted pr0xteus controller to allocate WireGuard-backed SOCKS5 or HTTP egress through a bearer-protected private API.

This skill is ready for commercial/non-commercial use.

## Publisher:

[psyb0t](https://clawhub.ai/user/psyb0t)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and operators use this skill to give a trusted workload controlled country-specific egress, inspect pools and active cells, replace failed proxy assignments, and integrate a Go client with VPN-only or public-first retry behavior.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The setup path asks users to run a mutable remote installer, with an optional sudo system-wide install path.

Mitigation: Download and inspect the installer before execution, prefer immutable releases or commit-pinned downloads, verify checksums or signatures when available, and avoid the sudo path unless system-wide installation is required.

Risk: Proxy URLs and PR0XTEUS_API_TOKEN are bearer credentials that can grant access to private egress capacity.

Mitigation: Store tokens in a secret store, keep returned proxy URLs out of logs and public issue trackers, and limit use to trusted clients and operator-approved destinations.

Risk: The controller starts Docker-backed WireGuard cells and can delete active cells on request.

Mitigation: Restrict agent and user access to Docker control paths, bind the controller only to loopback or a protected private network, and delete only cells associated with the current authorized task.

## Reference(s):

- [pr0xteus setup](references/setup.md)
- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/pr0xteus)
- [Project homepage](https://github.com/psyb0t/pr0xteus)

## Skill Output:

**Output Type(s):** [Guidance, Shell commands, Configuration, Code]

**Output Format:** [Markdown with inline bash, curl, Docker, YAML, JSON, and Go-oriented guidance]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Uses PR0XTEUS_URL and PR0XTEUS_API_TOKEN supplied by the operator; no MCP endpoint is provided.]

## Skill Version(s):

0.11.4 (source: server release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 2d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/psyb0t/skills/pr0xteus",
      "sourceUrl": "https://clawhub.ai/psyb0t/skills/pr0xteus",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T17:14:46.726Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T17:14:46.726Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1K downloads",
      "href": "https://clawhub.ai/psyb0t/pr0xteus",
      "sourceUrl": "https://clawhub.ai/psyb0t/pr0xteus",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T17:14:46.726Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.11.4",
      "href": "https://clawhub.ai/psyb0t/pr0xteus",
      "sourceUrl": "https://clawhub.ai/psyb0t/pr0xteus",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-06T07:07:17.786Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pr0xteus/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.11.4",
      "description": "- Removed the file skill-card.md. - No changes to core functionality or usage; documentation and instructions remain unchanged.",
      "href": "https://clawhub.ai/psyb0t/pr0xteus",
      "sourceUrl": "https://clawhub.ai/psyb0t/pr0xteus",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-06T07:07:17.786Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to pr0xteus and adjacent AI workflows.