bore
Installation
SKILL.md
bore
Tiny Rust TCP tunneling tool by Eric Zhang (ekzhang/bore, ~10k LOC). The client opens a control connection to a relay server, registers a remote port, and proxies every accepted TCP connection back to a local service. Default public relay is bore.pub; self-hosting on an owned VPS is a one-line command.
Pure TCP only — no HTTP parsing, no TLS termination, no header rewriting, no auth on visitors. Strengths are simplicity, speed, deterministic ports, and a single static binary.
Scope Guard
- Confirm the exposed service, audience, time window, and authorization before mapping any local port to a public relay.
- Treat
bore.pubas untrusted infrastructure: anyone can connect to the assigned remote port. Always layer app-level auth, short runtime, and IP allowlists at the OS firewall. - Do not expose admin interfaces, databases, MCP/AI tools, shells, or unauthenticated dev services to the internet without owner approval.
- For sensitive engagements, self-host the server on owned infrastructure and enable
--secretHMAC auth so only the operator's clients can register tunnels. - bore does not encrypt application traffic. If confidentiality matters, terminate TLS at the local service or wrap with
stunnel/socat openssl/SSH.