# Cf Proxy

> Deploy a free VLESS proxy/VPN node on Cloudflare Pages using edgetunnel. Automates code download, UUID generation, Pages deployment, free domain registration (DNSExit), DNS configuration, custom domain binding, and client setup for Shadowrocket/v2rayN/Clash. Uses Cloudflare Pages (not Workers) because Pages supports CNAME-based custom domains from any DNS provider, avoiding the need to host DNS o…

- **Type:** Skill
- **Install:** `agentstack add skill-davepoon-buildwithclaude-cf-proxy`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [davepoon](https://agentstack.voostack.com/s/davepoon)
- **Installs:** 0
- **Category:** [Cloud & Infrastructure](https://agentstack.voostack.com/c/cloud-infrastructure)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [davepoon](https://github.com/davepoon)
- **Source:** https://github.com/davepoon/buildwithclaude/tree/main/plugins/all-skills/skills/cf-proxy
- **Website:** https://www.buildwithclaude.com

## Install

```sh
agentstack add skill-davepoon-buildwithclaude-cf-proxy
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Cloudflare Proxy (cf-proxy)

Deploy a free VLESS proxy node on Cloudflare Pages + edgetunnel, with WebSocket over TLS through Cloudflare's global CDN.

## When to Use This Skill

- Setting up a free proxy/VPN node on Cloudflare
- Deploying edgetunnel to Cloudflare Workers or Pages
- Building a VLESS/Trojan/Shadowsocks proxy on Cloudflare's free tier
- Configuring a custom domain for a Cloudflare proxy to bypass SNI blocking
- Managing, updating, or troubleshooting an existing Cloudflare proxy node
- Registering a free domain for proxy use

## What This Skill Does

1. **Downloads edgetunnel** — fetches the worker code from GitHub (cmliu/edgetunnel, 30k+ stars)
2. **Generates credentials** — creates UUID for VLESS authentication and admin password
3. **Deploys to Cloudflare Pages** — not Workers, because Pages supports CNAME-based custom domains
4. **Registers a free domain** — via DNSExit (free 2-year second-level domains like `*.linkpc.net`)
5. **Configures DNS** — creates CNAME record pointing subdomain to `*.pages.dev`
6. **Binds custom domain** — attaches the domain to the Cloudflare Pages project
7. **Verifies and configures** — tests the node and provides client configuration

## How to Use

### Basic Usage

```
Help me set up a free Cloudflare proxy node
```

```
/cf-proxy
```

### With Specific Requirements

```
Deploy a VLESS proxy on Cloudflare using my domain example.com
```

```
Fix my Cloudflare proxy — Shadowrocket can't connect
```

## Architecture

```
Client (Shadowrocket / v2rayN / Clash)
  ↓ VLESS over WebSocket over TLS (port 443)
Custom Domain (CNAME → *.pages.dev)
  ↓
Cloudflare CDN (global edge)
  ↓
Cloudflare Pages Function (edgetunnel _worker.js)
  ↓ TCP outbound
Target Website
```

### Why Pages Instead of Workers?

- `workers.dev` domains are blocked at the TLS SNI layer by some firewalls
- Workers custom domains require DNS hosted on Cloudflare — not viable for free domains
- **Pages supports CNAME-based custom domains** from any DNS provider — the key advantage

## Cloudflare Free Tier Limits

| Resource | Free Quota | Impact on Proxy |
|----------|-----------|----------------|
| Requests | 100,000/day | WebSocket connection = 1 request; messages free |
| Bandwidth | **Unlimited** | No egress fees — biggest advantage |
| CPU time | 10 ms/request | Proxy is I/O-bound, typically ` provides ready-to-scan QR codes for mobile clients
- If speed is insufficient, try different Cloudflare CDN IP addresses as the proxy endpoint
- Keep usage low-profile for personal use to avoid Cloudflare ToS issues

## Requirements

- Node.js 18+
- GitHub CLI (`gh`)
- Cloudflare account (free tier)
- A domain (free via DNSExit, or bring your own)

## Source

- GitHub: https://github.com/LewisLiu007/cf-proxy
- Install: `npx skills add LewisLiu007/cf-proxy`

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [davepoon](https://github.com/davepoon)
- **Source:** [davepoon/buildwithclaude](https://github.com/davepoon/buildwithclaude)
- **License:** MIT
- **Homepage:** https://www.buildwithclaude.com

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-davepoon-buildwithclaude-cf-proxy
- Seller: https://agentstack.voostack.com/s/davepoon
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
