Agent skill

Shadowvpn Deploy Client

by madeye in madeye/shadowvpn

Deploy, install, and run the ShadowVPN client in a target environment — Linux (systemd), macOS (launchd), or Windows (Wintun, foreground launcher or scheduled-task service).

MITAuto-check: notesProductivity & Automation

Install Shadowvpn Deploy Client

skills CLI
$ npx skills add madeye/shadowvpn --skill shadowvpn-deploy-client -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install madeye/shadowvpn shadowvpn-deploy-client --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/madeye/shadowvpn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/shadowvpn-deploy-client .claude/skills/shadowvpn-deploy-client && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shadowvpn-deploy-client
GitHub stars
101
Token cost
~2.4k tokens
SKILL.md length
890 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Deploy, install, and run the ShadowVPN client in a target environment — Linux (systemd), macOS (launchd), or Windows (Wintun, foreground launcher or scheduled-task service).

  • Works in 3 steps: Build the binary for the target → Write client.json → Choose a routing mode
  • The user wants to set up
  • SKILL.md covers 1. Build the binary for the…, 2. Write client.json, 3a. Install — Linux (systemd) and 3b. Install — macOS (launchd), plus 4 more sections
  • Calls cargo and curl; reaches wintun.net

What it does

Shadowvpn Deploy Client is an agent skill from madeye/shadowvpn. Deploy, install, and run the ShadowVPN client in a target environment — Linux (systemd), macOS (launchd), or Windows (Wintun, foreground launcher or scheduled-task service). Use when the user wants to set up, install, deploy, cross-build, or run shadowvpn-client on a device; configure full-tunnel vs policy routing (gfwlist/chinadns); install it as a service/daemon/scheduled task; or troubleshoot the client (no connectivity, DNS left broken, Wintun error 193, poisoned DNS cache).

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Linux administration and Scheduled and recurring tasks. It works with Linux and macOS. The repository describes itself as: ShadowVPN: UDP PSK user-mode VPN with shadowsocks AEAD. The licence is MIT.

When your agent uses it

  • The user wants to set up
  • Run shadowvpn-client on a device
  • Configure full-tunnel vs policy routing (gfwlist/chinadns)
  • Install it as a service/daemon/scheduled task

Example prompts

  • “/shadowvpn-deploy-client”

Requirements

  • Docker

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Build the binary for the target
  2. Write client.json
  3. Choose a routing mode

What it can do on your machine

Read from SKILL.md and the folder at commit 1eb9a0d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • wintun.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Shadowvpn Deploy Client loads about 2.4k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 890 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:94
    sudo install -Dm755 target/release/shadowvpn-client /usr/local/bin/shadowvpn-client
  • NoteRuns commands with sudoSKILL.md:95
    sudo install -Dm600 client.json /etc/shadowvpn/client.json
  • NoteRuns commands with sudoSKILL.md:96
    sudo cp dist/systemd/shadowvpn-client.service /etc/systemd/system/
  • NoteRuns commands with sudoSKILL.md:97
    sudo systemctl daemon-reload && sudo systemctl enable --now shadowvpn-client
  • NoteRuns commands with sudoSKILL.md:99
    sudo systemctl stop shadowvpn-client     # graceful: restores DNS + routes, saves cache
  • NoteRuns commands with sudoSKILL.md:105
    sudo install -Dm755 target/release/shadowvpn-client /usr/local/bin/shadowvpn-client
  • NoteRuns commands with sudoSKILL.md:106
    sudo mkdir -p /etc/shadowvpn && sudo cp client.json /etc/shadowvpn/client.json
  • NoteRuns commands with sudoSKILL.md:107
    sudo cp dist/launchd/io.github.madeye.shadowvpn-client.plist /Library/LaunchDaemons/
  • NoteRuns commands with sudoSKILL.md:108
    sudo launchctl load -w /Library/LaunchDaemons/io.github.madeye.shadowvpn-client.plist
  • NoteRuns commands with sudoSKILL.md:110
    sudo launchctl unload -w /Library/LaunchDaemons/io.github.madeye.shadowvpn-client.plist  # graceful

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from madeye/shadowvpn at commit 1eb9a0d, republished under its MIT licence (© madeye). 890 words, ~2,372 tokens.

Download SKILL.mdSave it as .claude/skills/shadowvpn-deploy-client/SKILL.md (or your agent's skills folder).
name
shadowvpn-deploy-client
description
Deploy, install, and run the ShadowVPN client in a target environment — Linux (systemd), macOS (launchd), or Windows (Wintun, foreground launcher or scheduled-task service). Use when the user wants to set up, install, deploy, cross-build, or run shadowvpn-client on a device; configure full-tunnel vs policy routing (gfwlist/chinadns); install it as a service/daemon/scheduled task; or troubleshoot the client (no connectivity, DNS left broken, Wintun error 193, poisoned DNS cache).

Deploy the ShadowVPN client

The client owns a TUN device and a single UDP socket connected to the server. It needs elevated privileges (root on Linux, sudo on macOS, Administrator on Windows — Wintun + route/DNS changes).

Repo references — read these for the canonical artifacts:

  • dist/README.md, dist/systemd/shadowvpn-client.service, dist/launchd/io.github.madeye.shadowvpn-client.plist — Linux/macOS service install.
  • scripts/README.md, scripts/shadowvpn-client.ps1/.cmd — Windows self-elevating launcher.
  • README.md §Configuration, §Running, §"Policy routing (gfwlist / chinadns)", §"Client: route traffic through the tunnel".

1. Build the binary for the target

Native: cargo build --release --bin shadowvpn-client → target/release/shadowvpn-client.

Cross-build from a dev box (preferred for remote targets — Zig linker, no Docker):

sh
# Linux x86_64 / aarch64 (pin glibc to the target, e.g. 2.31 for Pi / older distros)
cargo zigbuild --release --target aarch64-unknown-linux-gnu.2.31 --bin shadowvpn-client
# Windows x64
cargo zigbuild --release --target x86_64-pc-windows-gnu      --bin shadowvpn-client
# Windows on ARM (ARM64)
cargo zigbuild --release --target aarch64-pc-windows-gnullvm --bin shadowvpn-client

Windows arch gotcha (error 193): the exe and wintun.dll must match the host CPU arch. An x64 exe on an ARM64 Windows box runs under emulation but cannot load an ARM64 wintun.dll → LoadLibraryExW … error 193 (%1 is not a valid Win32 application) at TUN creation. Verify the PE machine type before shipping (0x8664 = x64, 0xAA64 = ARM64) and pair it with the matching wintun.dll.

Getting wintun.dll (Windows only)

Official release zips already bundle it. The Windows release packages (shadowvpn-<ver>-<target>-pc-windows-msvc.zip) ship the matching-arch wintun.dll next to the exe and a GeoLite2-Country.mmdb for chinadns geoip mode — so a release download is self-contained, nothing else to fetch.

You only need the steps below when you built the client yourself (the repo source does not contain wintun.dll — separate license, arch-specific). Download the official signed release from WireGuard and pull the DLL for the host's CPU arch out of it:

sh
# 1. Download the release zip (pin a known version; 0.14.1 is the latest as of writing)
curl -fLO https://www.wintun.net/builds/wintun-0.14.1.zip
# (optional, recommended) verify the download against the SHA-256 on https://www.wintun.net/

# 2. The zip lays the DLLs out by architecture:
#    wintun/bin/amd64/wintun.dll   <- x64        (PE 0x8664)
#    wintun/bin/arm64/wintun.dll   <- ARM64      (PE 0xAA64)
#    wintun/bin/x86/wintun.dll     <- 32-bit x86
#    wintun/bin/arm/wintun.dll     <- 32-bit ARM
unzip -j wintun-0.14.1.zip 'wintun/bin/amd64/wintun.dll' -d .   # pick the arch you need

On Windows/PowerShell: Expand-Archive wintun-0.14.1.zip -DestinationPath wintun then copy wintun\wintun\bin\<arch>\wintun.dll next to shadowvpn-client.exe.

The DLL is loaded at runtime from the same folder as the exe (it is not installed system-wide). Match it to the exe you built: an x86_64-pc-windows-* exe needs amd64, an aarch64-pc-windows-* exe needs arm64 — mismatch is the error-193 above. Source + checksums: https://www.wintun.net/.

2. Write client.json

json
{
  "server": "vpn.example.com:8388",
  "password": "correct horse battery staple",
  "cipher": "chacha20-poly1305",
  "tun_ip": "10.9.0.2",
  "tun_netmask": "255.255.255.0",
  "peer_ip": "10.9.0.1",
  "mtu": 1400,
  "obfs": "quic"
}
  • server = the server's public host:port. The client resolves the hostname with its own built-in DNS client (querying dns_remote/dns_local directly), not the OS resolver — so a dirty/127.0.0.1-pinned system resolver no longer blocks startup (PR #27). A literal ip:port skips resolution entirely.
  • password, cipher, obfs must match the server.
  • tun_ip/peer_ip mirror the server's. If the server runs --nat, every client can share this identical config; otherwise give each client a distinct tun_ip.

3a. Install — Linux (systemd)

sh
sudo install -Dm755 target/release/shadowvpn-client /usr/local/bin/shadowvpn-client
sudo install -Dm600 client.json /etc/shadowvpn/client.json
sudo cp dist/systemd/shadowvpn-client.service /etc/systemd/system/
sudo systemctl daemon-reload && sudo systemctl enable --now shadowvpn-client
journalctl -u shadowvpn-client -f
sudo systemctl stop shadowvpn-client     # graceful: restores DNS + routes, saves cache

3b. Install — macOS (launchd)

sh
sudo install -Dm755 target/release/shadowvpn-client /usr/local/bin/shadowvpn-client
sudo mkdir -p /etc/shadowvpn && sudo cp client.json /etc/shadowvpn/client.json
sudo cp dist/launchd/io.github.madeye.shadowvpn-client.plist /Library/LaunchDaemons/
sudo launchctl load -w /Library/LaunchDaemons/io.github.madeye.shadowvpn-client.plist
tail -f /var/log/shadowvpn-client.log
sudo launchctl unload -w /Library/LaunchDaemons/io.github.madeye.shadowvpn-client.plist  # graceful

3c. Install — Windows

Lay out one folder with shadowvpn-client.exe, the matching-arch wintun.dll, and client.json (+ any policy data files). Two ways to run:

Foreground (interactive): from an elevated PowerShell, .\shadowvpn-client.exe -c client.json, or use the self-elevating launcher scripts\shadowvpn-client.cmd (see scripts/README.md). Stop with Ctrl-C — graceful (restores DNS, removes routes, saves cache). Never taskkill /F (see DNS gotcha below).

Headless service (runs with no user logged on) — register a Scheduled Task:

  • Action: shadowvpn-client.exe -c <abs path to config>, working dir = the folder.
  • LogonType = Password (store the box's creds) — Interactive can't start at the login screen. RunLevel = Highest (Wintun needs elevation).
  • Triggers: AtStartup + AtLogon; restart a few times on failure.
  • full mode programs no routes itself — wrap the exe in a script that adds the routes + sets DNS on the tun adapter after the tun comes up (see the gotchas).
  • Control: Start-ScheduledTask / Stop-ScheduledTask -TaskName <name>. A Stop-ScheduledTask is a hard kill (no Ctrl-C) — pair it with a teardown script that restores DNS/routes.
Show full SKILL.md (358 more words)Show less

4. Choose a routing mode

ModeBehaviourNeeds
full (default)every packet routed into the tun is tunneled; you add the routes yourself—
gfwlisttunnel only names in a gfwlist file; everything else direct--gfwlist <file>
chinadnstunnel anything not resolving to an in-China IP; optional gfwlist is a force-tunnel override--chnroute <cidr> or --geoip <mmdb> (+ optional --gfwlist)

gfwlist/chinadns run a built-in split-DNS proxy and add per-destination /32 routes automatically — set them via "mode" in the JSON or --mode on the CLI. For full mode you must route traffic yourself (README §"Client: route traffic through the tunnel"): keep a host route to the server via the physical gateway, then default everything via the tun peer_ip.

Critical gotchas (operational)

  • Forced kill leaves DNS broken. In gfwlist/chinadns mode the client points the system resolver at its proxy (127.0.0.1:53). A graceful stop (SIGTERM / launchd unload / Ctrl-C) restores it; a forced kill (taskkill /F, Stop-ScheduledTask, hard reboot) leaves DNS pinned at 127.0.0.1 with nothing listening → all name resolution fails. Fix on Windows: Set-DnsClientServerAddress -InterfaceIndex <idx> -ServerAddresses ('223.5.5.5','119.29.29.29') (target by index — the alias may be WLAN 12 etc.; find it with Get-DnsClientServerAddress | ? {$_.ServerAddresses -contains '127.0.0.1'}). The client's internal resolver (PR #27) means a stale pin no longer blocks the client's own bootstrap, but it still breaks every other app until reset.
  • Poisoned dns-cache.json persists across restarts. The cache is loaded at startup and short-circuits the gfwlist/clean-upstream logic, so a bad entry cached in an earlier run is served verbatim (and even gets a tun route). If a name resolves wrong after a mode switch, stop the client, delete dns-cache.json (next to the binary), restart.
  • Windows VPN bring-up can drop the LAN session. Bringing up Wintun + route changes can momentarily reset the box's network; if you drive it over SSH/RDP on the same link, you may lose the session. Prefer the scheduled-task service or a teardown-safe wrapper, and have console/out-of-band access before a remote start.

Verify

ping 10.9.0.1 (the server's in-tunnel IP) answers; the egress IP (curl ifconfig.me / a foreign-IP check) becomes the server's. In chinadns mode, confirm a China domain resolves to a China IP and stays direct while a foreign domain tunnels.

© madeye, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/shadowvpn-deploy-client of madeye/shadowvpn.

Open the folder on GitHubat commit 1eb9a0d

Compare with similar skills

Shadowvpn Deploy Client next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shadowvpn Deploy Client compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shadowvpn Deploy Client this skillmadeye/shadowvpn101—~2.4kAutomated safety check: NotesMIT
Nextclaw AutostartPeiiii/nextclaw260—~943Automated safety check: NotesMIT
Daily Briefleiting-eric/DailyBrief364—~3kAutomated safety check: NotesMIT
Managekenneth-liao/ai-launchpad-marketplace126—~4.1kAutomated safety check: PassNone
Daily UpdateAr9av/obsidian-wiki3.5k—~2.4kAutomated safety check: NotesMIT
Env Doctorcat-xierluo/legal-skills717—~756Automated safety check: PassMIT

Similar skills

  • Nextclaw Autostart

    Peiiii/nextclaw

    A skill your agent uses when the user asks about NextClaw autostart, auto-start on login or reboot, daemon/service registration, LaunchAgent, systemd, Windows Scheduled Task, service autostart…

    260 GitHub stars~943 tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Daily Brief

    leiting-eric/DailyBrief

    Operational knowledge for the daily-brief digest pipeline (this project).

    364 GitHub stars~3k tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Manage

    kenneth-liao/ai-launchpad-marketplace

    Manage scheduled Claude Code tasks — add (recurring or one-off), list, pause, resume, remove, view results, and test execution of skills, prompts, and scripts with safety controls and notifications.

    126 GitHub stars~4.1k tokensUpdated 6 mo ago
    Productivity & AutomationAuto-check passed
  • Daily Update

    Ar9av/obsidian-wiki

    Run or configure the daily wiki maintenance cycle: check source freshness, refresh the index and hot.md, and manage its scheduled 9 AM launchd/systemd/cron reminder.

    3.5k GitHub stars~2.4k tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Env Doctor

    cat-xierluo/legal-skills

    本机开发环境与全局包的体检、账本与安装纪律,覆盖所有包管理器(npm/npx、nvm、pip/pipx、uv、brew、bun)与运行时环境面(~/.local/bin 垫片、PATH、python 解释器版图、LaunchAgents、cron、shell rc 漂移对照)。当用户问「node/python 为什么是这个版本」「npm/pip…

    717 GitHub stars~756 tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed

More from madeye/shadowvpn

  • Shadowvpn Deploy Server

    madeye/shadowvpn

    Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd).

    101 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Questions about Shadowvpn Deploy Client

What does Shadowvpn Deploy Client do?

Deploy, install, and run the ShadowVPN client in a target environment — Linux (systemd), macOS (launchd), or Windows (Wintun, foreground launcher or scheduled-task service). Shadowvpn Deploy Client is an agent skill from madeye/shadowvpn. Deploy, install, and run the ShadowVPN client in a target environment — Linux (systemd), macOS (launchd), or Windows (Wintun, foreground launcher or scheduled-task service).

When should I use Shadowvpn Deploy Client?

Shadowvpn Deploy Client fits situations like: the user wants to set up; run shadowvpn-client on a device; configure full-tunnel vs policy routing (gfwlist/chinadns); install it as a service/daemon/scheduled task.

How do I install Shadowvpn Deploy Client in Claude Code?

Run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-client -a claude-code`. Or copy the skill folder (.claude/skills/shadowvpn-deploy-client in madeye/shadowvpn) into .claude/skills/shadowvpn-deploy-client in your project. Claude Code loads it when a task matches its description.

How do I install Shadowvpn Deploy Client in Codex?

Run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-client -a codex`. Or copy the skill folder (.claude/skills/shadowvpn-deploy-client in madeye/shadowvpn) into .agents/skills/shadowvpn-deploy-client in your project. Codex loads it when a task matches its description.

Can I use Shadowvpn Deploy Client in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-client -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shadowvpn-deploy-client, .gemini/skills/shadowvpn-deploy-client, .github/skills/shadowvpn-deploy-client and .opencode/skills/shadowvpn-deploy-client in your project.

What does Shadowvpn Deploy Client need to run?

Going by SKILL.md and its folder, Shadowvpn Deploy Client needs the command-line tools its instructions call (cargo and curl). Our summary lists: Docker.

Does Shadowvpn Deploy Client access the network?

SKILL.md names 1 domain. In commands or code: wintun.net; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Shadowvpn Deploy Client safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Shadowvpn Deploy Client use?

Shadowvpn Deploy Client is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shadowvpn Deploy Client use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Shadowvpn Deploy Client?

Skills that share tags, products or a category with Shadowvpn Deploy Client: Nextclaw Autostart (Peiiii/nextclaw, 260 stars), Daily Brief (leiting-eric/DailyBrief, 364 stars), Manage (kenneth-liao/ai-launchpad-marketplace, 126 stars) and Daily Update (Ar9av/obsidian-wiki, 3.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shadowvpn Deploy Client?

madeye (a GitHub user) maintains it in madeye/shadowvpn, which has 101 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on August 30, 2026.

Source: madeye/shadowvpn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.