Skill metadata
Reference: full SKILL.md
The following is the complete skill definition that Mibyan loads when this skill is triggered. This is what the agent sees as instructions when the skill is active.
Pinggy Tunnel Skill
Expose a local service (dev server, webhook receiver, MCP endpoint, demo) to the public internet using a Pinggy SSH reverse tunnel. No daemon to install — the user’s stock SSH client connects toa.pinggy.io:443 and Pinggy hands back a public HTTP/HTTPS URL.
Free tier: 60-minute tunnels, random subdomain, no signup. Pro tier ($3/mo) is an opt-in with a token.
When to Use
- User asks to “expose this locally”, “share my dev server”, “make this URL public”, “tunnel port N”, “get a public URL for a webhook”
- Need to receive a webhook callback during a local task (Stripe, GitHub, Discord, AgentMail)
- Sharing a one-off HTTP demo (MCP server, Ollama/vLLM endpoint, dashboard) with a remote party
- The host has SSH but no
cloudflared/ngrokbinary, and installing one would be overkill
cloudflared configured, prefer the cloudflared-quick-tunnel skill — Cloudflare quick tunnels don’t expire after 60 minutes.
Prerequisites
sshon PATH (ssh -V). Default on Linux, macOS, and Windows 10+. No other install.- A local service listening on
127.0.0.1:<port>before the tunnel starts. Pinggy will return URLs but they’ll 502 until the local origin is up.
PINGGY_TOKENenv var for paid Pro features (persistent subdomain, custom domain, multiple tunnels, no 60-minute cap). Free tier needs no credentials.
Quick Reference
Procedure — Start a Tunnel and Get the URL
The model SHOULD use theterminal tool. The tunnel must stay alive for the duration of the share, so run it as a background process and parse the public URL from stdout.
1. Confirm a local origin is up
python -m http.server 8000 --bind 127.0.0.1). Pinggy will happily return a URL pointed at nothing — the user will see 502 until the origin comes up.
2. Launch the tunnel as a background process
Useterminal(background=True) and capture output to a logfile (Pinggy prints the URLs on stdout, then keeps the connection open):
StrictHostKeyChecking=no + UserKnownHostsFile=/dev/null skips the first-run host-key prompt. ServerAliveInterval=30 keeps the SSH session from getting torn down by an idle NAT.
3. Parse the URL out of the log
https://...pinggy.link URL to the user.
4. Verify
502 Bad Gateway, the SSH session is up but the local origin isn’t listening — fix step 1 first.
5. Teardown
terminal(background=True), prefer process(action='kill', session_id=...).
Access Control via Username Keywords
Pinggy stacks control flags into the SSH username separated by+. Always quote the whole user@host argument when it contains a +:
Combine freely:
"b:admin:secret+co+x:https+free@a.pinggy.io".
Web Debugger (optional)
Pinggy can mirror the inbound traffic tolocalhost:4300 for inspection. Add a local forward to the SSH command:
http://localhost:4300 in a browser to see live request/response pairs.
Pitfalls
- 60-minute hard cap on the free tier. The SSH session terminates at the 60-minute mark; the URL goes dead. For longer shares, either use
PINGGY_TOKEN(Pro) or auto-restart with a shell loop (note that the URL changes on every restart for free-tier). - Free-tier URL is random and changes on restart. Don’t bookmark it, don’t paste it into a config file. Re-parse from the log each time.
- Concurrent free tunnels are limited to one per source IP. Starting a second tunnel from the same machine usually kills the first. Pro tier lifts this.
+in usernames must be quoted. Baressh ... b:admin:secret+free@a.pinggy.ioworks in bash but breaks under shells that treat+specially or when assembled programmatically. Always wrap in double quotes.- Don’t tunnel anything sensitive without an access-control flag. A bare HTTP tunnel is reachable by anyone with the URL. Use
b:,k:, orw:for non-public services. process(action='log')may miss SSH banner output. Pinggy prints the URLs and then the SSH session goes interactive. Always redirect to a logfile andgrepthe file directly — same pattern ascloudflared-quick-tunnel.- Host-key prompt on first run. Default OpenSSH config asks the user to accept Pinggy’s host key. Always pass
-o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/nullfor unattended runs. - TCP and TLS tunnels return a
<subdomain>.a.pinggy.online:<port>pair, not an https URL. Parse with a different regex (tcp://and a port). Don’t assume every Pinggy tunnel is HTTP. - Pro mode requires the token as the username, not a flag. Use
"$PINGGY_TOKEN+a.pinggy.io"(nofree@). With a token you can also add:persistentfor a stable subdomain — seepinggy.io/docs/.
Recipes
Composite patterns combining a local origin with a Pinggy tunnel. Each recipe is self-contained — start the origin, start the tunnel, parse the URL, hand it back to the user.Recipe 1 — Receive a webhook callback
Use this when an external service (Stripe, GitHub, Discord, AgentMail, etc.) needs to POST to a publicly reachable URL during a local task.$URL to the service that needs to call you. Teardown: kill $(cat ~/.mibyan/cache/scratch/webhook-server.pid) $(cat ~/.mibyan/cache/scratch/webhook-pinggy.pid).
Recipe 2 — Expose an MCP server over HTTP/SSE
Use when a remote MCP client (Claude Desktop on another machine, a teammate’s editor, etc.) needs to reach an MCP server running on the local box. Only works for MCP servers that speak HTTP transport — stdio-mode servers can’t be tunneled.$URL with Authorization: Bearer $TOKEN. Mibyan’ own native MCP client config: {"transport": "http", "url": "<URL>", "headers": {"Authorization": "Bearer <TOKEN>"}}.
Recipe 3 — Expose a local LLM endpoint (Ollama / vLLM / llama.cpp)
Share a local model with a remote caller (another agent, a phone, a teammate). Ollama listens on:11434, vLLM and llama.cpp typically on :8000.
co enables CORS so a browser caller can hit the endpoint. Drop co for backend-only callers. For an OpenAI-compatible vLLM/llama.cpp endpoint, callers use base URL $URL/v1 with Authorization: Bearer $TOKEN — but note Pinggy strips/replaces nothing in the body, so the model server itself sees Pinggy’s token; the local server should be configured to ignore auth (it’s already on 127.0.0.1) and let Pinggy do the gating.
Recipe 4 — Share a dev server with a one-shot password
The fastest “let a teammate poke at my running app” pattern. Random password, prints once, dies when you Ctrl-C.b:dev:$PASS gates the URL with HTTP Basic auth. x:https forces TLS. co adds CORS for SPA frontends.
Verification
pinggy.link URL and HTTP/2 200 on the curl head.
