[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"workflow-asset-e1a749fb":3,"seo:featured-workflow:e1a749fb-4eca-11f1-9bc6-00163e2b0d79:en":87,"workflow-related-asset-e1a749fb-e1a749fb-4eca-11f1-9bc6-00163e2b0d79":88},{"id":4,"uuid":5,"slug":6,"title":7,"description":8,"author_id":9,"author_name":10,"author_avatar":11,"token_estimate":12,"time_saved":12,"model_used":13,"fork_count":12,"vote_count":12,"view_count":12,"parent_id":12,"parent_uuid":13,"lang_type":14,"steps":15,"tags":22,"has_voted":28,"visibility":18,"share_token":13,"is_featured":12,"content_hash":29,"asset_kind":30,"target_tools":31,"install_mode":35,"entrypoint":19,"risk_profile":36,"dependencies":38,"verification":47,"agent_metadata":50,"agent_fit":63,"trust":75,"provenance":84,"created_at":86,"updated_at":86},3613,"e1a749fb-4eca-11f1-9bc6-00163e2b0d79","asset-e1a749fb","sshuttle — VPN Over SSH Without Root on the Remote Server","sshuttle creates a transparent VPN tunnel through any SSH connection, routing your traffic through the remote host without requiring admin access or a VPN server on the other end.","8a911193-3180-11f1-9bc6-00163e2b0d79","AI Open Source","https:\u002F\u002Ftokrepo.com\u002Fapple-touch-icon.png",0,"","en",[16],{"id":17,"step_order":18,"title":19,"description":13,"prompt_template":20,"variables":13,"depends_on":21,"expected_output":13},4173,1,"sshuttle SSH VPN","# sshuttle — VPN Over SSH Without Root on the Remote Server\n\n## Quick Use\n```bash\n# Install\npip install sshuttle\n# or: brew install sshuttle \u002F apt install sshuttle\n\n# Route all traffic through a remote host\nsshuttle -r user@remote 0\u002F0\n\n# Route only a specific subnet\nsshuttle -r user@remote 10.0.0.0\u002F8\n```\n\n## Introduction\nsshuttle turns any SSH server into a VPN gateway. It works by setting up local firewall rules that transparently redirect traffic through an SSH tunnel, assembling packets on the remote side. No VPN software, configuration, or root access is needed on the remote server.\n\n## What sshuttle Does\n- Creates a transparent proxy that routes TCP traffic over an existing SSH connection\n- Supports full tunnel (all traffic) or split tunnel (specific subnets only)\n- Handles DNS forwarding to prevent leaks when tunneling all traffic\n- Works with any standard SSH server — no special software on the remote end\n- Automatically configures local iptables\u002Fpf rules and cleans up on exit\n\n## Architecture Overview\nsshuttle runs a small Python assembler on the remote host via SSH. Locally, it configures the firewall (iptables on Linux, pf on macOS) to intercept outgoing packets for the specified subnets. Intercepted TCP connections are multiplexed over the SSH channel, reassembled on the remote side, and forwarded as normal connections. This avoids the overhead of a full IP-over-TCP tunnel.\n\n## Self-Hosting & Configuration\n- Requires Python 3 and root\u002Fsudo locally for firewall manipulation\n- No installation or root needed on the remote server — only a working SSH account\n- Use --dns flag to also forward DNS queries through the tunnel\n- Exclude specific subnets with -x to keep local network traffic direct\n- Supports SSH config files, ProxyJump, and custom SSH options via -e\n\n## Key Features\n- Zero setup on the remote server — works with any SSH access\n- Transparent routing at the firewall level, no SOCKS proxy config needed\n- Split tunneling for selective subnet routing\n- DNS leak prevention with --dns flag\n- Lightweight Python implementation with no compiled dependencies\n\n## Comparison with Similar Tools\n- **WireGuard** — faster and handles UDP; requires server-side installation and key exchange\n- **OpenVPN** — full-featured VPN with broader protocol support; requires server setup and certificates\n- **Tailscale** — mesh VPN with identity-based access; requires account signup and client on both ends\n- **SSH SOCKS proxy** — simpler but requires per-application proxy configuration; sshuttle is transparent\n\n## FAQ\n**Q: Does sshuttle tunnel UDP traffic?**\nA: No. sshuttle tunnels TCP and optionally DNS. For full UDP support, use a dedicated VPN like WireGuard.\n\n**Q: Will it work on macOS?**\nA: Yes. sshuttle supports macOS using the built-in pf firewall. Install via Homebrew.\n\n**Q: Does the remote server need root access?**\nA: No. sshuttle only needs a regular SSH login on the remote side. Root is needed locally to set up firewall rules.\n\n**Q: Can I use it with SSH key authentication?**\nA: Yes. It respects your SSH config, keys, and agent forwarding just like a normal SSH connection.\n\n## Sources\n- https:\u002F\u002Fgithub.com\u002Fapenwarr\u002Fsshuttle\n- https:\u002F\u002Fsshuttle.readthedocs.io","0",[23],{"id":24,"name":25,"slug":26,"icon":27},12,"Configs","config","⚙️",false,"64b805843f1d3ee4fc4ab8c5bbcfb29bcce838d0d93396c888b474f379e6e24d","skill",[32,33,34],"claude_code","codex","gemini_cli","single",{"executes_code":28,"modifies_global_config":28,"requires_secrets":37,"uses_absolute_paths":28,"network_access":28},[],{"npm":39,"pip":40,"brew":42,"system":46},[],[41],"sshuttle",[43,44,45,41],"\u002F","apt","install",[],{"commands":48,"expected_files":49},[],[19],{"asset_kind":30,"target_tools":51,"install_mode":35,"entrypoint":19,"risk_profile":52,"dependencies":54,"content_hash":29,"verification":59,"inferred":62},[32,33,34],{"executes_code":28,"modifies_global_config":28,"requires_secrets":53,"uses_absolute_paths":28,"network_access":28},[],{"npm":55,"pip":56,"brew":57,"system":58},[],[41],[43,44,45,41],[],{"commands":60,"expected_files":61},[],[19],true,{"target":33,"score":64,"status":65,"policy":66,"why":67,"asset_kind":30,"install_mode":35},98,"native","allow",[68,69,70,71,72,73,74],"target_tools includes codex","asset_kind skill","install_mode single","markdown-only","policy allow","safe markdown-only Codex install","trust established",{"author_trust_level":76,"verified_publisher":28,"asset_signed_hash":29,"signature_status":77,"install_count":12,"report_count":12,"dangerous_capability_badges":78,"review_status":79,"signals":80},"established","hash_only",[],"unreviewed",[81,82,83],"author has published assets","content hash available","no dangerous capability badges",{"owner_uuid":9,"owner_name":10,"source_url":85,"content_hash":29,"visibility":18,"created_at":86,"updated_at":86},"https:\u002F\u002Ftokrepo.com\u002Fen\u002Fworkflows\u002Fasset-e1a749fb","2026-05-13 20:54:30",null,[89,141,194,241],{"id":90,"uuid":91,"slug":92,"title":93,"description":94,"author_id":9,"author_name":10,"author_avatar":11,"token_estimate":12,"time_saved":12,"model_used":13,"fork_count":12,"vote_count":12,"view_count":95,"parent_id":12,"parent_uuid":13,"lang_type":14,"steps":96,"tags":97,"has_voted":28,"visibility":18,"share_token":13,"is_featured":12,"content_hash":99,"asset_kind":30,"target_tools":100,"install_mode":35,"entrypoint":101,"risk_profile":102,"dependencies":104,"verification":109,"agent_metadata":112,"agent_fit":124,"trust":126,"provenance":129,"created_at":131,"updated_at":132,"__relatedScore":133,"__relatedReasons":134,"__sharedTags":139},2141,"d56dff04-4105-11f1-9bc6-00163e2b0d79","chisel-fast-tcp-udp-tunnel-over-http-ssh-d56dff04","Chisel — Fast TCP\u002FUDP Tunnel Over HTTP and SSH","Chisel is a single-binary tool written in Go that creates encrypted tunnels for TCP and UDP traffic over HTTP or SSH. It works through firewalls and proxies, making it useful for accessing internal services, bypassing NAT, and securing connections without a full VPN.",41,[],[98],{"id":24,"name":25,"slug":26,"icon":27},"89a4cb8d6f18fd412efd02d9548c8f07e4856813d0f070575568792d4c02de18",[32,33,34],"Chisel Tunnel Tool",{"executes_code":28,"modifies_global_config":28,"requires_secrets":103,"uses_absolute_paths":28,"network_access":28},[],{"npm":105,"pip":106,"brew":107,"system":108},[],[],[],[],{"commands":110,"expected_files":111},[],[101],{"asset_kind":30,"target_tools":113,"install_mode":35,"entrypoint":101,"risk_profile":114,"dependencies":116,"content_hash":99,"verification":121},[32,33,34],{"executes_code":28,"modifies_global_config":28,"requires_secrets":115,"uses_absolute_paths":28,"network_access":28},[],{"npm":117,"pip":118,"brew":119,"system":120},[],[],[],[],{"commands":122,"expected_files":123},[],[101],{"target":33,"score":64,"status":65,"policy":66,"why":125,"asset_kind":30,"install_mode":35},[68,69,70,71,72,73,74],{"author_trust_level":76,"verified_publisher":28,"asset_signed_hash":99,"signature_status":77,"install_count":12,"report_count":12,"dangerous_capability_badges":127,"review_status":79,"signals":128},[],[81,82,83],{"owner_uuid":9,"owner_name":10,"source_url":130,"content_hash":99,"visibility":18,"created_at":131,"updated_at":132},"https:\u002F\u002Ftokrepo.com\u002Fen\u002Fworkflows\u002Fchisel-fast-tcp-udp-tunnel-over-http-ssh-d56dff04","2026-04-26 08:21:13","2026-05-14 00:59:14",126.43487393559685,[135,136,137,138],"topic-match","same-kind","same-target","same-author",[26,140],"configs",{"id":142,"uuid":143,"slug":144,"title":145,"description":146,"author_id":9,"author_name":10,"author_avatar":11,"token_estimate":12,"time_saved":12,"model_used":13,"fork_count":12,"vote_count":12,"view_count":147,"parent_id":12,"parent_uuid":13,"lang_type":14,"steps":148,"tags":149,"has_voted":28,"visibility":18,"share_token":13,"is_featured":12,"content_hash":151,"asset_kind":30,"target_tools":152,"install_mode":35,"entrypoint":153,"risk_profile":154,"dependencies":156,"verification":161,"agent_metadata":164,"agent_fit":176,"trust":183,"provenance":187,"created_at":189,"updated_at":190,"__relatedScore":191,"__relatedReasons":192,"__sharedTags":193},961,"d339dece-3530-11f1-9bc6-00163e2b0d79","headscale-open-source-self-hosted-tailscale-control-server-d339dece","Headscale — Open Source Self-Hosted Tailscale Control Server","Headscale is an open-source implementation of the Tailscale control server. Run your own private mesh VPN with WireGuard, no Tailscale subscription needed.",84,[],[150],{"id":24,"name":25,"slug":26,"icon":27},"da3e5a7ddbe41ef503881809fda1dc144729d6bd49089b2c7333d3deef32628f",[32,33,34],"SKILL.md",{"executes_code":28,"modifies_global_config":28,"requires_secrets":155,"uses_absolute_paths":62,"network_access":28},[],{"npm":157,"pip":158,"brew":159,"system":160},[],[],[],[],{"commands":162,"expected_files":163},[],[13],{"asset_kind":30,"target_tools":165,"install_mode":35,"entrypoint":153,"risk_profile":166,"dependencies":168,"content_hash":151,"verification":173},[32,33,34],{"executes_code":28,"modifies_global_config":28,"requires_secrets":167,"uses_absolute_paths":62,"network_access":28},[],{"npm":169,"pip":170,"brew":171,"system":172},[],[],[],[],{"commands":174,"expected_files":175},[],[13],{"target":33,"score":177,"status":178,"policy":179,"why":180,"asset_kind":30,"install_mode":35},64,"needs_confirmation","confirm",[68,69,70,181,182,74],"policy confirm","risk_profile.uses_absolute_paths is true",{"author_trust_level":76,"verified_publisher":28,"asset_signed_hash":151,"signature_status":77,"install_count":12,"report_count":12,"dangerous_capability_badges":184,"review_status":79,"signals":186},[185],"uses_absolute_paths",[81,82],{"owner_uuid":9,"owner_name":10,"source_url":188,"content_hash":151,"visibility":18,"created_at":189,"updated_at":190},"https:\u002F\u002Ftokrepo.com\u002Fen\u002Fworkflows\u002Fheadscale-open-source-self-hosted-tailscale-control-server-d339dece","2026-04-11 06:58:44","2026-05-13 18:13:20",91.89412838857145,[135,136,137,138],[26,140],{"id":195,"uuid":196,"slug":197,"title":198,"description":199,"author_id":9,"author_name":10,"author_avatar":11,"token_estimate":12,"time_saved":12,"model_used":13,"fork_count":12,"vote_count":12,"view_count":200,"parent_id":12,"parent_uuid":13,"lang_type":14,"steps":201,"tags":202,"has_voted":28,"visibility":18,"share_token":13,"is_featured":12,"content_hash":204,"asset_kind":30,"target_tools":205,"install_mode":35,"entrypoint":206,"risk_profile":207,"dependencies":209,"verification":214,"agent_metadata":217,"agent_fit":229,"trust":231,"provenance":234,"created_at":236,"updated_at":237,"__relatedScore":238,"__relatedReasons":239,"__sharedTags":240},1793,"8573b764-3c0d-11f1-9bc6-00163e2b0d79","pomerium-identity-aware-zero-trust-access-proxy-8573b764","Pomerium — Identity-Aware Zero Trust Access Proxy","Pomerium is an open source reverse proxy that provides secure, identity-aware access to internal applications without a VPN, implementing BeyondCorp-style zero trust networking with SSO integration.",80,[],[203],{"id":24,"name":25,"slug":26,"icon":27},"98104385ad300fbc95b1d8e891c632da861ee9c3bc94df94821cca2b0fae7781",[32,33,34],"Pomerium Overview",{"executes_code":28,"modifies_global_config":28,"requires_secrets":208,"uses_absolute_paths":28,"network_access":28},[],{"npm":210,"pip":211,"brew":212,"system":213},[],[],[],[],{"commands":215,"expected_files":216},[],[206],{"asset_kind":30,"target_tools":218,"install_mode":35,"entrypoint":206,"risk_profile":219,"dependencies":221,"content_hash":204,"verification":226},[32,33,34],{"executes_code":28,"modifies_global_config":28,"requires_secrets":220,"uses_absolute_paths":28,"network_access":28},[],{"npm":222,"pip":223,"brew":224,"system":225},[],[],[],[],{"commands":227,"expected_files":228},[],[206],{"target":33,"score":64,"status":65,"policy":66,"why":230,"asset_kind":30,"install_mode":35},[68,69,70,71,72,73,74],{"author_trust_level":76,"verified_publisher":28,"asset_signed_hash":204,"signature_status":77,"install_count":12,"report_count":12,"dangerous_capability_badges":232,"review_status":79,"signals":233},[],[81,82,83],{"owner_uuid":9,"owner_name":10,"source_url":235,"content_hash":204,"visibility":18,"created_at":236,"updated_at":237},"https:\u002F\u002Ftokrepo.com\u002Fen\u002Fworkflows\u002Fpomerium-identity-aware-zero-trust-access-proxy-8573b764","2026-04-20 00:33:39","2026-05-13 13:33:10",83.86272752831798,[135,136,137,138],[26,140],{"id":242,"uuid":243,"slug":244,"title":245,"description":246,"author_id":247,"author_name":248,"author_avatar":11,"token_estimate":12,"time_saved":12,"model_used":13,"fork_count":12,"vote_count":12,"view_count":249,"parent_id":12,"parent_uuid":13,"lang_type":14,"steps":250,"tags":251,"has_voted":28,"visibility":18,"share_token":13,"is_featured":12,"content_hash":257,"asset_kind":30,"target_tools":258,"install_mode":35,"entrypoint":259,"risk_profile":260,"dependencies":262,"verification":267,"agent_metadata":270,"agent_fit":282,"trust":284,"provenance":288,"created_at":290,"updated_at":291,"__relatedScore":292,"__relatedReasons":293,"__sharedTags":294},2368,"84011bb0-43e8-11f1-9bc6-00163e2b0d79","softether-vpn-multi-protocol-open-source-vpn-server-84011bb0","SoftEther VPN — Multi-Protocol Open-Source VPN Server","A powerful multi-protocol VPN server and client supporting SSL-VPN, L2TP\u002FIPsec, OpenVPN, and SSTP in a single unified solution.","8a910e34-3180-11f1-9bc6-00163e2b0d79","Script Depot",139,[],[252],{"id":253,"name":254,"slug":255,"icon":256},11,"Scripts","script","📜","ec37027d7d59c3b9e5fb3fb857f8d0a382e31fe365713bba24cca799b14da8bb",[32,33,34],"SoftEther VPN",{"executes_code":28,"modifies_global_config":28,"requires_secrets":261,"uses_absolute_paths":28,"network_access":28},[],{"npm":263,"pip":264,"brew":265,"system":266},[],[],[],[],{"commands":268,"expected_files":269},[],[259],{"asset_kind":30,"target_tools":271,"install_mode":35,"entrypoint":259,"risk_profile":272,"dependencies":274,"content_hash":257,"verification":279},[32,33,34],{"executes_code":28,"modifies_global_config":28,"requires_secrets":273,"uses_absolute_paths":28,"network_access":28},[],{"npm":275,"pip":276,"brew":277,"system":278},[],[],[],[],{"commands":280,"expected_files":281},[],[259],{"target":33,"score":64,"status":65,"policy":66,"why":283,"asset_kind":30,"install_mode":35},[68,69,70,71,72,73,74],{"author_trust_level":76,"verified_publisher":28,"asset_signed_hash":257,"signature_status":77,"install_count":12,"report_count":12,"dangerous_capability_badges":285,"review_status":79,"signals":286},[],[287,81,82,83],"asset has usage views",{"owner_uuid":247,"owner_name":248,"source_url":289,"content_hash":257,"visibility":18,"created_at":290,"updated_at":291},"https:\u002F\u002Ftokrepo.com\u002Fen\u002Fworkflows\u002Fsoftether-vpn-multi-protocol-open-source-vpn-server-84011bb0","2026-04-30 00:28:55","2026-05-14 01:26:08",83.21919205351736,[135,136,137],[]]