bore

Installation
SKILL.md

bore

Tiny Rust TCP tunneling tool by Eric Zhang (ekzhang/bore, ~10k LOC). The client opens a control connection to a relay server, registers a remote port, and proxies every accepted TCP connection back to a local service. Default public relay is bore.pub; self-hosting on an owned VPS is a one-line command.

Pure TCP only — no HTTP parsing, no TLS termination, no header rewriting, no auth on visitors. Strengths are simplicity, speed, deterministic ports, and a single static binary.

Scope Guard

  • Confirm the exposed service, audience, time window, and authorization before mapping any local port to a public relay.
  • Treat bore.pub as untrusted infrastructure: anyone can connect to the assigned remote port. Always layer app-level auth, short runtime, and IP allowlists at the OS firewall.
  • Do not expose admin interfaces, databases, MCP/AI tools, shells, or unauthenticated dev services to the internet without owner approval.
  • For sensitive engagements, self-host the server on owned infrastructure and enable --secret HMAC auth so only the operator's clients can register tunnels.
  • bore does not encrypt application traffic. If confidentiality matters, terminate TLS at the local service or wrap with stunnel/socat openssl/SSH.

When to Pick bore

Installs
5
GitHub Stars
22
First Seen
Jun 16, 2026
bore — aeondave/malskill