Agent skill

Shadowvpn Deploy Server

by madeye in madeye/shadowvpn

Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd).

MITAuto-check: notesDevOps & Cloud

Install Shadowvpn Deploy Server

skills CLI
$ npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install madeye/shadowvpn shadowvpn-deploy-server --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/madeye/shadowvpn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/shadowvpn-deploy-server .claude/skills/shadowvpn-deploy-server && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shadowvpn-deploy-server
GitHub stars
101
Token cost
~1.5k tokens
SKILL.md length
531 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd).

  • Works in 5 steps: Build the binary for the target → Write server.json → Install + enable (systemd) → …
  • The user wants to set up
  • SKILL.md covers 1. Build the binary for the…, 2. Write server.json, 3. Install + enable (systemd) and 4. Open the UDP port, plus 3 more sections
  • Calls cargo and curl

What it does

Shadowvpn Deploy Server is an agent skill from madeye/shadowvpn. Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd). Use when the user wants to set up, install, deploy, cross-build, or run the shadowvpn-server on a host (VPS, droplet, Raspberry Pi), enable internet egress for tunneled clients (IP forwarding + NAT/MASQUERADE), wire up the systemd unit, open the UDP port, or troubleshoot a server that clients cannot reach.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Linux administration. It works with Linux and Docker. The repository describes itself as: ShadowVPN: UDP PSK user-mode VPN with shadowsocks AEAD. The licence is MIT.

When your agent uses it

  • The user wants to set up
  • Run the shadowvpn-server on a host (VPS
  • Enable internet egress for tunneled clients (IP forwarding + NAT/MASQUERADE)
  • Wire up the systemd unit

Example prompts

  • “/shadowvpn-deploy-server”

Requirements

  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Build the binary for the target
  2. Write server.json
  3. Install + enable (systemd)
  4. Open the UDP port
  5. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 1eb9a0d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Shadowvpn Deploy Server loads about 1.5k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 531 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:67
    sudo install -Dm755 target/release/shadowvpn-server /usr/local/bin/shadowvpn-server
  • NoteRuns commands with sudoSKILL.md:68
    sudo install -Dm600 server.json /etc/shadowvpn/server.json
  • NoteRuns commands with sudoSKILL.md:69
    sudo cp dist/systemd/shadowvpn-server.service /etc/systemd/system/
  • NoteRuns commands with sudoSKILL.md:70
    sudo systemctl daemon-reload && sudo systemctl enable --now shadowvpn-server
  • NoteRuns commands with sudoSKILL.md:80
    After editing: `sudo systemctl daemon-reload && sudo systemctl restart shadowvpn-server`.
  • NoteRuns commands with sudoSKILL.md:87
    sudo ufw allow 8388/udp          # or nftables/iptables equivalent
  • NoteRuns commands with sudoSKILL.md:104
    sudo sysctl -w net.ipv4.ip_forward=1                                   # persist in /etc/sysctl.d/
  • NoteRuns commands with sudoSKILL.md:106
    sudo iptables -t nat -A POSTROUTING -s 10.9.0.0/24 -o "$WAN" -j MASQUERADE
  • NoteRuns commands with sudoSKILL.md:107
    sudo iptables -A FORWARD -s 10.9.0.0/24 -j ACCEPT
  • NoteRuns commands with sudoSKILL.md:108
    sudo iptables -A FORWARD -d 10.9.0.0/24 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from madeye/shadowvpn at commit 1eb9a0d, republished under its MIT licence (© madeye). 531 words, ~1,460 tokens.

Download SKILL.mdSave it as .claude/skills/shadowvpn-deploy-server/SKILL.md (or your agent's skills folder).
name
shadowvpn-deploy-server
description
Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd). Use when the user wants to set up, install, deploy, cross-build, or run the shadowvpn-server on a host (VPS, droplet, Raspberry Pi), enable internet egress for tunneled clients (IP forwarding + NAT/MASQUERADE), wire up the systemd unit, open the UDP port, or troubleshoot a server that clients cannot reach.

Deploy the ShadowVPN server

The server terminates the encrypted UDP tunnel onto a TUN device and (optionally) NATs tunneled clients to the internet. It needs root (TUN creation) and runs on Linux in practice (the systemd unit ships in dist/).

Repo references — read these for the canonical artifacts:

  • dist/README.md + dist/systemd/shadowvpn-server.service — the install recipe and unit.
  • README.md §Configuration, §Building, §"Server: enable IP forwarding + NAT".
  • docker/server.json, docker/run-server-nat.sh — working config + NAT example.

1. Build the binary for the target

Native (build on the server itself, needs a stable Rust toolchain):

sh
cargo build --release --bin shadowvpn-server   # -> target/release/shadowvpn-server
cargo test --lib                               # optional sanity check

Cross-build from a dev box (preferred for remote Linux targets — uses Zig as the linker, no Docker, works from any path). Pin the glibc version to the target's:

sh
# x86_64 Ubuntu/Debian server (glibc 2.39 = Ubuntu 24.04; use 2.31 for older)
cargo zigbuild --release --target x86_64-unknown-linux-gnu.2.39 --bin shadowvpn-server
# aarch64 (Raspberry Pi etc.)
cargo zigbuild --release --target aarch64-unknown-linux-gnu.2.31 --bin shadowvpn-server

cargo install cargo-zigbuild if the subcommand is missing. Confirm the built binary's max GLIBC requirement is ≤ the target's before shipping.

2. Write server.json

json
{
  "server": "0.0.0.0:8388",
  "password": "correct horse battery staple",
  "cipher": "chacha20-poly1305",
  "tun_ip": "10.9.0.1",
  "tun_netmask": "255.255.255.0",
  "peer_ip": "10.9.0.2",
  "mtu": 1400,
  "obfs": "quic",
  "nat": true
}

Key points:

  • server is the UDP bind address (0.0.0.0:PORT). The client's server is this host's public host:port.
  • password, cipher, and obfs must match the client exactly (obfs defaults to none; both ends must agree). Wrong cipher/obfs = silent decrypt failure.
  • tun_ip/peer_ip are mirror images of the client's (server.tun_ip == client.peer_ip, and vice versa).
  • "nat": true lets many clients share one identical static config (the server keys each by UDP endpoint and maps it onto a distinct internal IP). Without NAT, every client needs a distinct tun_ip. With NAT, idle mappings are reclaimed after lease_ttl_secs (default 120). See README §"Multiple clients with --nat".

3. Install + enable (systemd)

sh
sudo install -Dm755 target/release/shadowvpn-server /usr/local/bin/shadowvpn-server
sudo install -Dm600 server.json /etc/shadowvpn/server.json
sudo cp dist/systemd/shadowvpn-server.service /etc/systemd/system/
sudo systemctl daemon-reload && sudo systemctl enable --now shadowvpn-server

The shipped unit's ExecStartPre lines enable IP forwarding + MASQUERADE so tunneled clients reach the internet. They are idempotent and re-applied on boot. You MUST edit the unit if your setup differs from the defaults:

  • WAN egress interface — the unit assumes eth0. Find yours with ip route get 1.1.1.1 (the dev …), and replace eth0 in the three iptables lines.
  • Tunnel subnet — the unit assumes 10.9.0.0/24; match your tun_ip/netmask.

After editing: sudo systemctl daemon-reload && sudo systemctl restart shadowvpn-server.

Show full SKILL.md (213 more words)Show less

4. Open the UDP port

The data plane is UDP on the server port. Allow it on the host firewall AND the cloud security group / provider firewall:

sh
sudo ufw allow 8388/udp          # or nftables/iptables equivalent

On DigitalOcean/AWS/GCP also open the port in the cloud firewall — a host that forwards fine but drops inbound UDP looks exactly like a wrong password to a client.

5. Verify

sh
journalctl -u shadowvpn-server -f          # startup log; NAT line shows "NAT : ENABLED" when "nat": true
ss -lunp | grep 8388                        # socket bound

From a connected client: ping 10.9.0.1 (the server's in-tunnel IP) should answer, and the client's public egress IP (e.g. curl ifconfig.me) should become this host.

Manual forwarding + NAT (if not using the unit's ExecStartPre)

sh
sudo sysctl -w net.ipv4.ip_forward=1                                   # persist in /etc/sysctl.d/
WAN=$(ip route get 1.1.1.1 | grep -oP 'dev \K\S+')
sudo iptables -t nat -A POSTROUTING -s 10.9.0.0/24 -o "$WAN" -j MASQUERADE
sudo iptables -A FORWARD -s 10.9.0.0/24 -j ACCEPT
sudo iptables -A FORWARD -d 10.9.0.0/24 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

Troubleshooting

  • Client connects but no internet → forwarding/NAT not applied, or wrong WAN interface / subnet in the iptables rules. Check sysctl net.ipv4.ip_forward and iptables -t nat -L POSTROUTING -n -v.
  • Client times out entirely → UDP port not open in the cloud firewall, or wrong public host:port in the client config.
  • Garbage / decrypt errors in the log → password, cipher, or obfs mismatch between server and client.
  • Updating the binary → back up the old one, systemctl stop, swap, systemctl start. Live clients reconnect within ~1 s (UDP, stateless handshake). Keep a timestamped .bak so you can roll back.

When deploying to a known live host, record the host, port, obfs, cipher, and the NAT subnet so the matching client config can be produced without guessing.

© madeye, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/shadowvpn-deploy-server of madeye/shadowvpn.

Open the folder on GitHubat commit 1eb9a0d

Compare with similar skills

Shadowvpn Deploy Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shadowvpn Deploy Server compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shadowvpn Deploy Server this skillmadeye/shadowvpn101—~1.5kAutomated safety check: NotesMIT
Minimegasandia-minimega/minimega160—~3.2kAutomated safety check: PassGPL-3.0-only
Setup Cpu Proxy Serverdrawthingsai/draw-things-community580—~3.8kAutomated safety check: PassGPL-3.0
Podmansickn33/agentic-awesome-skills47k1 repos~2.2kAutomated safety check: NotesMIT
Sshepherdsickn33/agentic-awesome-skills47k1 repos~1.6kAutomated safety check: WarnMIT
PodmanBagelHole/DevOps-Security-Agent-Skills1.1k—~1.9kAutomated safety check: NotesMIT

Similar skills

  • Minimega

    sandia-minimega/minimega

    This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…

    160 GitHub stars~3.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Setup Cpu Proxy Server

    drawthingsai/draw-things-community

    Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

    580 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Podman

    sickn33/agentic-awesome-skills

    Manage containers using Podman, the daemonless container engine.

    47k GitHub starsUsed in 1 repo~2.2k tokens
    DevOps & CloudAuto-check: notes
  • Sshepherd

    sickn33/agentic-awesome-skills

    Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.

    47k GitHub starsUsed in 1 repo~1.6k tokens
    DevOps & CloudAuto-check: warnings
  • Podman

    BagelHole/DevOps-Security-Agent-Skills

    Manage containers using Podman, the daemonless container engine.

    1.1k GitHub stars~1.9k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes
  • GitHub Runner

    magnus919/agent-skills

    Deploy, manage, and troubleshoot self-hosted GitHub Actions runners.

    113 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from madeye/shadowvpn

  • Shadowvpn Deploy Client

    madeye/shadowvpn

    Deploy, install, and run the ShadowVPN client in a target environment — Linux (systemd), macOS (launchd), or Windows (Wintun, foreground launcher or scheduled-task service).

    101 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Categories

Questions about Shadowvpn Deploy Server

What does Shadowvpn Deploy Server do?

Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd). Shadowvpn Deploy Server is an agent skill from madeye/shadowvpn. Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd).

When should I use Shadowvpn Deploy Server?

Shadowvpn Deploy Server fits situations like: the user wants to set up; run the shadowvpn-server on a host (VPS; enable internet egress for tunneled clients (IP forwarding + NAT/MASQUERADE); wire up the systemd unit.

How do I install Shadowvpn Deploy Server in Claude Code?

Run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a claude-code`. Or copy the skill folder (.claude/skills/shadowvpn-deploy-server in madeye/shadowvpn) into .claude/skills/shadowvpn-deploy-server in your project. Claude Code loads it when a task matches its description.

How do I install Shadowvpn Deploy Server in Codex?

Run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a codex`. Or copy the skill folder (.claude/skills/shadowvpn-deploy-server in madeye/shadowvpn) into .agents/skills/shadowvpn-deploy-server in your project. Codex loads it when a task matches its description.

Can I use Shadowvpn Deploy Server in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shadowvpn-deploy-server, .gemini/skills/shadowvpn-deploy-server, .github/skills/shadowvpn-deploy-server and .opencode/skills/shadowvpn-deploy-server in your project.

What does Shadowvpn Deploy Server need to run?

Going by SKILL.md and its folder, Shadowvpn Deploy Server needs the command-line tools its instructions call (cargo and curl). Our summary lists: Docker.

Does Shadowvpn Deploy Server access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Shadowvpn Deploy Server safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Shadowvpn Deploy Server use?

Shadowvpn Deploy Server is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shadowvpn Deploy Server use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Shadowvpn Deploy Server?

Skills that share tags, products or a category with Shadowvpn Deploy Server: Minimega (sandia-minimega/minimega, 160 stars), Setup Cpu Proxy Server (drawthingsai/draw-things-community, 580 stars), Podman (sickn33/agentic-awesome-skills, 47k stars) and Sshepherd (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shadowvpn Deploy Server?

madeye (a GitHub user) maintains it in madeye/shadowvpn, which has 101 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on August 30, 2026.

Source: madeye/shadowvpn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.