Agent skill

Homelab Network Readiness

by affaan-m in affaan-m/ECC

Readiness checklist for homelab VLAN segmentation, local DNS filtering (Pi-hole, AdGuard Home), and WireGuard-style remote access.

MITAuto-check passedBackend & APIs

Install Homelab Network Readiness

skills CLI
$ npx skills add affaan-m/ECC --skill homelab-network-readiness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC homelab-network-readiness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/homelab-network-readiness .claude/skills/homelab-network-readiness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
homelab-network-readiness
GitHub stars
277k
Used in
1 other repo
Token cost
~1.9k tokens
SKILL.md length
1,017 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

Readiness checklist for homelab VLAN segmentation, local DNS filtering (Pi-hole, AdGuard Home), and WireGuard-style remote access.

  • Works in 5 steps: The gateway supports inter-VLAN routing… → The switch supports the required tagged… → The APs can map SSIDs to VLANs. → …
  • Reviewing home network changes — splitting a flat network into trusted
  • SKILL.md covers When to Use, Safety Rules, Required Inventory and VLAN And Trust-Zone Plan, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Homelab Network Readiness is an agent skill from affaan-m/ECC. Readiness checklist for homelab VLAN segmentation, local DNS filtering (Pi-hole, AdGuard Home), and WireGuard-style remote access. Use when planning or reviewing home network changes — splitting a flat network into trusted, IoT, guest, or management VLANs, moving DHCP to a local resolver, or adding VPN access — before changing router, firewall, DHCP, or VPN configuration.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering GraphQL. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Reviewing home network changes — splitting a flat network into trusted
  • Management VLANs
  • Moving DHCP to a local resolver
  • Adding VPN access — before changing router

Example prompts

  • “/homelab-network-readiness”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. The gateway supports inter-VLAN routing and firewall rules.
  2. The switch supports the required tagged and untagged port behavior.
  3. The APs can map SSIDs to VLANs.
  4. The operator knows which port they are connected through during the change.
  5. The management network remains reachable after trunk and SSID changes.

What it can do on your machine

Read from SKILL.md and the folder at commit 2d515e4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Homelab Network Readiness loads about 1.9k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 1,017 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 2d515e4, republished under its MIT licence (© affaan-m). 1,017 words, ~1,945 tokens.

Download SKILL.mdSave it as .claude/skills/homelab-network-readiness/SKILL.md (or your agent's skills folder).
name
homelab-network-readiness
description
Readiness checklist for homelab VLAN segmentation, local DNS filtering (Pi-hole, AdGuard Home), and WireGuard-style remote access. Use when planning or reviewing home network changes — splitting a flat network into trusted, IoT, guest, or management VLANs, moving DHCP to a local resolver, or adding VPN access — before changing router, firewall, DHCP, or VPN configuration.
metadata.origin
community

Homelab Network Readiness

Use this skill before changing a home or small-lab network that mixes VLANs, Pi-hole or another local DNS resolver, firewall rules, and remote VPN access.

This is a planning and review skill. Do not turn it into copy-paste router, firewall, or VPN configuration unless the target platform, current topology, rollback path, console access, and maintenance window are all known.

When to Use

  • Preparing to split a flat network into trusted, IoT, guest, server, or management VLANs.
  • Moving DHCP clients to Pi-hole, AdGuard Home, Unbound, or another local DNS resolver.
  • Adding WireGuard, Tailscale, ZeroTier, OpenVPN, or router-native VPN access.
  • Reviewing whether a homelab change can lock the operator out of the gateway, switch, access point, DNS server, or VPN server.
  • Turning an informal home-network idea into a staged migration plan with validation evidence.

Safety Rules

  • Keep the first answer read-only: inventory, risks, staged plan, validation, and rollback.
  • Do not expose gateway admin panels, DNS resolvers, SSH, NAS consoles, or VPN management UIs directly to the public internet.
  • Do not provide firewall, NAT, VLAN, DHCP, or VPN commands without a confirmed platform and a rollback procedure.
  • Require out-of-band or same-room console access before changing management VLANs, trunk ports, firewall default policies, or DHCP/DNS settings.
  • Keep a working path back to the internet before pointing the whole network at a new DNS resolver or VPN route.
  • Treat IoT, guest, camera, and lab-server networks as different trust zones until the operator explicitly chooses otherwise.

Required Inventory

Collect this before giving implementation steps:

AreaQuestions
Internet edgeWhat is the modem or ONT? Is the ISP router bridged or still routing?
GatewayWhat routes, firewalls, handles DHCP, and terminates VPNs?
SwitchingWhich switch ports are uplinks, access ports, trunks, or unmanaged?
Wi-FiWhich SSIDs map to which networks, and are APs wired or mesh?
AddressingWhat subnets exist today, and which ranges conflict with VPN sites?
DNS/DHCPWhich service currently hands out leases and resolver addresses?
ManagementHow will the operator reach the gateway, switch, and AP after changes?
RecoveryWhat can be reverted locally if DNS, DHCP, VLANs, or VPN routes break?

VLAN And Trust-Zone Plan

Start with intent rather than vendor syntax.

ZoneTypical contentsDefault policy
TrustedLaptops, phones, admin workstationsCan reach shared services and management only when needed
ServersNAS, Home Assistant, lab hosts, DNS resolverAccepts narrow inbound flows from trusted clients
IoTTVs, smart plugs, cameras, speakersInternet access plus explicit exceptions only
GuestVisitor devicesInternet-only, no LAN reachability
ManagementGateway, switches, APs, controllersReachable only from trusted admin devices
VPNRemote clientsSame or narrower access than trusted clients

Before recommending VLAN IDs or subnets, confirm:

  1. The gateway supports inter-VLAN routing and firewall rules.
  2. The switch supports the required tagged and untagged port behavior.
  3. The APs can map SSIDs to VLANs.
  4. The operator knows which port they are connected through during the change.
  5. The management network remains reachable after trunk and SSID changes.

DNS Filtering Readiness

Pi-hole or another local resolver should be introduced as a dependency, not as a single point of failure.

  1. Give the resolver a reserved address before using it in DHCP options.
  2. Confirm it can resolve public DNS and local home.arpa names.
  3. Keep the gateway or a second resolver available as a temporary fallback.
  4. Test one client or one VLAN before changing every DHCP scope.
  5. Document which networks may bypass filtering and why.
  6. Check that blocking rules do not break captive portals, work VPNs, firmware updates, or medical/security devices.

Useful validation evidence:

text
Client gets expected DHCP lease
Client receives expected DNS resolver
Public DNS lookup succeeds
Local home.arpa lookup succeeds
Blocked test domain is blocked only where intended
Gateway and DNS admin interfaces are not reachable from guest or IoT networks
Show full SKILL.md (423 more words)Show less

Remote Access Readiness

For WireGuard-style access, decide what the VPN is allowed to reach before generating keys or opening ports.

ModeUse whenRisk notes
Split tunnel to one subnetRemote admin for NAS or lab hostsKeep route list narrow
Split tunnel to trusted servicesAccess selected apps by IP or DNSRequires precise firewall rules
Full tunnelUntrusted networks or travelMore bandwidth and DNS responsibility
Overlay VPNSimpler remote access with identity controlsStill needs ACL review

Do not recommend port forwarding until the operator confirms:

  • The VPN endpoint is patched and actively maintained.
  • The forwarded port goes only to the VPN service, not an admin UI.
  • Dynamic DNS, public IP behavior, and ISP CGNAT status are understood.
  • Peer keys can be revoked without rebuilding the whole network.
  • Logs or connection status can verify who connected and when.

Change Sequence

Prefer small, reversible changes:

  1. Snapshot the current topology, IP plan, DHCP settings, DNS settings, and firewall rules.
  2. Reserve infrastructure addresses for gateway, DNS, controller, APs, NAS, and VPN endpoint.
  3. Create the new zone or VLAN without moving critical devices.
  4. Move one test client and validate DHCP, DNS, routing, internet, and block behavior.
  5. Add narrow firewall exceptions for required flows.
  6. Move one low-risk device group.
  7. Add VPN access with the narrowest route and firewall policy that satisfies the use case.
  8. Document final state, known exceptions, and rollback commands or UI steps.

Review Checklist

  • Each network has a reason to exist and a clear trust boundary.
  • No management interface is reachable from guest, IoT, or the public internet.
  • DNS failure does not take down the operator's ability to recover locally.
  • DHCP scope changes were tested on one client before broad rollout.
  • VPN clients receive only the routes and DNS settings they need.
  • Firewall rules are default-deny between zones, with named exceptions.
  • The operator can still reach gateway, switch, AP, DNS, and VPN admin surfaces.
  • Rollback is documented in the same vocabulary as the chosen platform UI or CLI.

Anti-Patterns

  • Segmenting networks before knowing which switch ports and SSIDs carry which VLANs.
  • Moving the admin workstation off the only reachable management network.
  • Pointing all DHCP scopes at a Pi-hole before testing fallback DNS.
  • Publishing NAS, DNS, router, or hypervisor management directly to the internet.
  • Treating VPN access as equivalent to full trusted-LAN access.
  • Adding allow-all firewall rules temporarily and forgetting to remove them.
  • Copying commands from another vendor or firmware version without checking the exact platform syntax.

See Also

  • Skill: homelab-network-setup
  • Skill: network-config-validation
  • Skill: network-interface-health

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/homelab-network-readiness of affaan-m/ECC.

Open the folder on GitHubat commit 2d515e4

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in affaan-m/ECC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Homelab Network Readiness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Homelab Network Readiness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Homelab Network Readiness this skillaffaan-m/ECC277k1 repos~1.9kAutomated safety check: PassMIT
Apollo Prod Checklistjeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: NotesMIT
Apollo Federationapollographql/skills117—~1kAutomated safety check: PassMIT
Openfdd Railway CLIbbartling/open-fdd173—~2.3kAutomated safety check: NotesCustom licence
China Mirror ResolverLeoYeAI/openclaw-master-skills2.2k—~4.6kAutomated safety check: NotesMIT
Detecting Debug Endpointsjeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT

Similar skills

  • Apollo Prod Checklist

    jeremylongshore/tons-of-skills-marketplace

    Execute Apollo.io production deployment checklist. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~1.6k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Apollo Federation

    apollographql/skills

    Guide for authoring Apollo Federation subgraph schemas. An agent skill from apollographql/skills.

    117 GitHub stars~1k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Openfdd Railway CLI

    bbartling/open-fdd

    A skill your agent uses when installing, authenticating, linking, or re-pinning the Open-FDD Railway hub (central/mqtt/web) via the Railway CLI on bensbench.

    173 GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • China Mirror Resolver

    LeoYeAI/openclaw-master-skills

    Self-healing China mirror source resolver. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.6k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Detecting Debug Endpoints

    jeremylongshore/tons-of-skills-marketplace

    Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…

    2.8k GitHub stars~2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Querying AWS Cloudwatch

    aws/agent-toolkit-for-aws

    Official

    Runs SQL queries on CloudWatch Logs data exported as Apache Iceberg tables in S3 Tables.

    2.8k GitHub stars~3.5k tokensUpdated yesterday
    DatabasesAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Questions about Homelab Network Readiness

What does Homelab Network Readiness do?

Readiness checklist for homelab VLAN segmentation, local DNS filtering (Pi-hole, AdGuard Home), and WireGuard-style remote access. Homelab Network Readiness is an agent skill from affaan-m/ECC. Readiness checklist for homelab VLAN segmentation, local DNS filtering (Pi-hole, AdGuard Home), and WireGuard-style remote access.

When should I use Homelab Network Readiness?

Homelab Network Readiness fits situations like: reviewing home network changes — splitting a flat network into trusted; management VLANs; moving DHCP to a local resolver; adding VPN access — before changing router.

How do I install Homelab Network Readiness in Claude Code?

Run `npx skills add affaan-m/ECC --skill homelab-network-readiness -a claude-code`. Or copy the skill folder (skills/homelab-network-readiness in affaan-m/ECC) into .claude/skills/homelab-network-readiness in your project. Claude Code loads it when a task matches its description.

How do I install Homelab Network Readiness in Codex?

Run `npx skills add affaan-m/ECC --skill homelab-network-readiness -a codex`. Or copy the skill folder (skills/homelab-network-readiness in affaan-m/ECC) into .agents/skills/homelab-network-readiness in your project. Codex loads it when a task matches its description.

Can I use Homelab Network Readiness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill homelab-network-readiness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/homelab-network-readiness, .gemini/skills/homelab-network-readiness, .github/skills/homelab-network-readiness and .opencode/skills/homelab-network-readiness in your project.

What does Homelab Network Readiness need to run?

SKILL.md names no scripts, command-line tools or credentials: Homelab Network Readiness is instructions for the agent only.

Does Homelab Network Readiness access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Homelab Network Readiness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Homelab Network Readiness use?

Homelab Network Readiness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Homelab Network Readiness use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Homelab Network Readiness?

Skills that share tags, products or a category with Homelab Network Readiness: Apollo Prod Checklist (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Apollo Federation (apollographql/skills, 117 stars), Openfdd Railway CLI (bbartling/open-fdd, 173 stars) and China Mirror Resolver (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Homelab Network Readiness?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,673 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 11, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.