Install
$ agentstack add skill-teddy563-mcwrench-proxy-network ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Proxy / Network
Default proxy: Velocity (by the Paper team; TOML config, modern forwarding). Waterfall is in maintenance mode; BungeeCord is legacy. See references/velocity-modern-forwarding.md for the exact forwarding handshake — getting it wrong is the #1 network setup failure.
The forwarding contract (must all line up)
For a Velocity network with modern forwarding:
- Proxy
velocity.toml:player-info-forwarding-mode = "modern"and
forwarding-secret-file = "forwarding.secret".
- Secret: the proxy's
forwarding.secretfile contents must exactly equal each
backend's paper-global.yml: proxies.velocity.secret.
- Backend
paper-global.yml:proxies.velocity.enabled: true, matchingsecret, and
proxies.velocity.online-mode equal to the proxy's online-mode.
- Backend
server.properties:online-mode=false(the proxy handles authentication). - Never also set
spigot.yml: settings.bungeecord: true— Velocity + BungeeCord forwarding
enabled together stops the backend from starting.
velocity.toml essentials
bind = "0.0.0.0:25565"
online-mode = true
player-info-forwarding-mode = "modern"
forwarding-secret-file = "forwarding.secret"
[servers]
lobby = "127.0.0.1:30066"
survival = "127.0.0.1:30067"
try = ["lobby"]
[forced-hosts]
"play.example.net" = ["lobby"]
[advanced]
compression-threshold = 256
login-ratelimit = 3000
- Backends bind to internal/loopback ports; only the proxy port is public. Firewall the
backend ports so players can't bypass the proxy (which would hit online-mode=false directly — a security hole).
trysets the initial-connect order;forced-hostsroutes by hostname.
Troubleshooting map
| Symptom | Cause → fix | |---|---| | "Unable to connect you… invalid forwarding" | secret mismatch or wrong forwarding mode → align secret + set modern both sides | | Players join as offline UUID / skins broken | backend online-mode=true, or proxies.velocity.online-mode mismatch → set backend online-mode=false, match proxy | | Backend won't start | BungeeCord and Velocity forwarding both enabled → disable one | | Anyone can join backend directly as op | backend port exposed publicly with online-mode=false → firewall to proxy only | | Legacy BungeeCord network | use ip_forward: true + bungeecord: true; do NOT also enable Velocity |
Method
- Confirm proxy software + version (Velocity 3.5.0-SNAPSHOT is current in 2026).
- Walk the 5-point forwarding contract above and verify each side.
- Lock down backend ports.
- For proxy-level permissions, run LuckPerms on the proxy too (see
permissions-helper).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Teddy563
- Source: Teddy563/mcwrench
- License: MIT
- Homepage: https://mcwrench.teddy.bar
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.