Minimega
sandia-minimega/minimega
This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…
Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd).
$ npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install madeye/shadowvpn shadowvpn-deploy-server --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/madeye/shadowvpn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/shadowvpn-deploy-server .claude/skills/shadowvpn-deploy-server && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "shadowvpn-deploy-server" agent skill from https://github.com/madeye/shadowvpn/tree/main/.claude/skills/shadowvpn-deploy-server into .claude/skills/shadowvpn-deploy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shadowvpn-deploy-server", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/madeye/shadowvpn/tree/main/.claude/skills/shadowvpn-deploy-serverType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install madeye/shadowvpn shadowvpn-deploy-server --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/madeye/shadowvpn.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/shadowvpn-deploy-server .agents/skills/shadowvpn-deploy-server && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "shadowvpn-deploy-server" agent skill from https://github.com/madeye/shadowvpn/tree/main/.claude/skills/shadowvpn-deploy-server into .agents/skills/shadowvpn-deploy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shadowvpn-deploy-server", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install madeye/shadowvpn shadowvpn-deploy-server --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/madeye/shadowvpn.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/shadowvpn-deploy-server .cursor/skills/shadowvpn-deploy-server && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "shadowvpn-deploy-server" agent skill from https://github.com/madeye/shadowvpn/tree/main/.claude/skills/shadowvpn-deploy-server into .cursor/skills/shadowvpn-deploy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shadowvpn-deploy-server", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/madeye/shadowvpn.git --path .claude/skills/shadowvpn-deploy-server--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install madeye/shadowvpn shadowvpn-deploy-server --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/madeye/shadowvpn.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/shadowvpn-deploy-server .gemini/skills/shadowvpn-deploy-server && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "shadowvpn-deploy-server" agent skill from https://github.com/madeye/shadowvpn/tree/main/.claude/skills/shadowvpn-deploy-server into .gemini/skills/shadowvpn-deploy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shadowvpn-deploy-server", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install madeye/shadowvpn shadowvpn-deploy-serverInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/madeye/shadowvpn.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/shadowvpn-deploy-server .github/skills/shadowvpn-deploy-server && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "shadowvpn-deploy-server" agent skill from https://github.com/madeye/shadowvpn/tree/main/.claude/skills/shadowvpn-deploy-server into .github/skills/shadowvpn-deploy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shadowvpn-deploy-server", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install madeye/shadowvpn shadowvpn-deploy-server --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/madeye/shadowvpn.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/shadowvpn-deploy-server .opencode/skills/shadowvpn-deploy-server && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "shadowvpn-deploy-server" agent skill from https://github.com/madeye/shadowvpn/tree/main/.claude/skills/shadowvpn-deploy-server into .opencode/skills/shadowvpn-deploy-server/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shadowvpn-deploy-server", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
shadowvpn-deploy-serverDeploy, install, and run the ShadowVPN server in a target environment (Linux/systemd).
Shadowvpn Deploy Server is an agent skill from madeye/shadowvpn. Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd). Use when the user wants to set up, install, deploy, cross-build, or run the shadowvpn-server on a host (VPS, droplet, Raspberry Pi), enable internet egress for tunneled clients (IP forwarding + NAT/MASQUERADE), wire up the systemd unit, open the UDP port, or troubleshoot a server that clients cannot reach.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Linux administration. It works with Linux and Docker. The repository describes itself as: ShadowVPN: UDP PSK user-mode VPN with shadowsocks AEAD. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1eb9a0d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
cargocurlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Shadowvpn Deploy Server loads about 1.5k tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 531 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo install -Dm755 target/release/shadowvpn-server /usr/local/bin/shadowvpn-serversudo install -Dm600 server.json /etc/shadowvpn/server.jsonsudo cp dist/systemd/shadowvpn-server.service /etc/systemd/system/sudo systemctl daemon-reload && sudo systemctl enable --now shadowvpn-serverAfter editing: `sudo systemctl daemon-reload && sudo systemctl restart shadowvpn-server`.sudo ufw allow 8388/udp # or nftables/iptables equivalentsudo sysctl -w net.ipv4.ip_forward=1 # persist in /etc/sysctl.d/sudo iptables -t nat -A POSTROUTING -s 10.9.0.0/24 -o "$WAN" -j MASQUERADEsudo iptables -A FORWARD -s 10.9.0.0/24 -j ACCEPTsudo iptables -A FORWARD -d 10.9.0.0/24 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPTAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from madeye/shadowvpn at commit 1eb9a0d, republished under its MIT licence (© madeye). 531 words, ~1,460 tokens.
.claude/skills/shadowvpn-deploy-server/SKILL.md (or your agent's skills folder).The server terminates the encrypted UDP tunnel onto a TUN device and (optionally)
NATs tunneled clients to the internet. It needs root (TUN creation) and runs
on Linux in practice (the systemd unit ships in dist/).
Repo references — read these for the canonical artifacts:
dist/README.md + dist/systemd/shadowvpn-server.service — the install recipe and unit.README.md §Configuration, §Building, §"Server: enable IP forwarding + NAT".docker/server.json, docker/run-server-nat.sh — working config + NAT example.Native (build on the server itself, needs a stable Rust toolchain):
cargo build --release --bin shadowvpn-server # -> target/release/shadowvpn-server
cargo test --lib # optional sanity checkCross-build from a dev box (preferred for remote Linux targets — uses Zig as the linker, no Docker, works from any path). Pin the glibc version to the target's:
# x86_64 Ubuntu/Debian server (glibc 2.39 = Ubuntu 24.04; use 2.31 for older)
cargo zigbuild --release --target x86_64-unknown-linux-gnu.2.39 --bin shadowvpn-server
# aarch64 (Raspberry Pi etc.)
cargo zigbuild --release --target aarch64-unknown-linux-gnu.2.31 --bin shadowvpn-servercargo install cargo-zigbuild if the subcommand is missing. Confirm the built
binary's max GLIBC requirement is ≤ the target's before shipping.
server.json{
"server": "0.0.0.0:8388",
"password": "correct horse battery staple",
"cipher": "chacha20-poly1305",
"tun_ip": "10.9.0.1",
"tun_netmask": "255.255.255.0",
"peer_ip": "10.9.0.2",
"mtu": 1400,
"obfs": "quic",
"nat": true
}Key points:
server is the UDP bind address (0.0.0.0:PORT). The client's server is
this host's public host:port.password, cipher, and obfs must match the client exactly (obfs defaults
to none; both ends must agree). Wrong cipher/obfs = silent decrypt failure.tun_ip/peer_ip are mirror images of the client's (server.tun_ip ==
client.peer_ip, and vice versa)."nat": true lets many clients share one identical static config (the
server keys each by UDP endpoint and maps it onto a distinct internal IP). Without
NAT, every client needs a distinct tun_ip. With NAT, idle mappings are reclaimed
after lease_ttl_secs (default 120). See README §"Multiple clients with --nat".sudo install -Dm755 target/release/shadowvpn-server /usr/local/bin/shadowvpn-server
sudo install -Dm600 server.json /etc/shadowvpn/server.json
sudo cp dist/systemd/shadowvpn-server.service /etc/systemd/system/
sudo systemctl daemon-reload && sudo systemctl enable --now shadowvpn-serverThe shipped unit's ExecStartPre lines enable IP forwarding + MASQUERADE so
tunneled clients reach the internet. They are idempotent and re-applied on boot.
You MUST edit the unit if your setup differs from the defaults:
eth0. Find yours with
ip route get 1.1.1.1 (the dev …), and replace eth0 in the three iptables lines.10.9.0.0/24; match your tun_ip/netmask.After editing: sudo systemctl daemon-reload && sudo systemctl restart shadowvpn-server.
The data plane is UDP on the server port. Allow it on the host firewall AND
the cloud security group / provider firewall:
sudo ufw allow 8388/udp # or nftables/iptables equivalentOn DigitalOcean/AWS/GCP also open the port in the cloud firewall — a host that forwards fine but drops inbound UDP looks exactly like a wrong password to a client.
journalctl -u shadowvpn-server -f # startup log; NAT line shows "NAT : ENABLED" when "nat": true
ss -lunp | grep 8388 # socket boundFrom a connected client: ping 10.9.0.1 (the server's in-tunnel IP) should answer,
and the client's public egress IP (e.g. curl ifconfig.me) should become this host.
sudo sysctl -w net.ipv4.ip_forward=1 # persist in /etc/sysctl.d/
WAN=$(ip route get 1.1.1.1 | grep -oP 'dev \K\S+')
sudo iptables -t nat -A POSTROUTING -s 10.9.0.0/24 -o "$WAN" -j MASQUERADE
sudo iptables -A FORWARD -s 10.9.0.0/24 -j ACCEPT
sudo iptables -A FORWARD -d 10.9.0.0/24 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPTsysctl net.ipv4.ip_forward and
iptables -t nat -L POSTROUTING -n -v.host:port in the client config.password, cipher, or obfs mismatch
between server and client.systemctl stop, swap, systemctl start. Live clients reconnect within ~1 s (UDP, stateless handshake). Keep a
timestamped .bak so you can roll back.When deploying to a known live host, record the host, port, obfs, cipher, and the NAT subnet so the matching client config can be produced without guessing.
© madeye, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/shadowvpn-deploy-server of madeye/shadowvpn.
Open the folder on GitHubat commit 1eb9a0d
Shadowvpn Deploy Server next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Shadowvpn Deploy Server this skillmadeye/shadowvpn | 101 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Minimegasandia-minimega/minimega | 160 | — | ~3.2k | Automated safety check: Pass | GPL-3.0-only | |
| Setup Cpu Proxy Serverdrawthingsai/draw-things-community | 580 | — | ~3.8k | Automated safety check: Pass | GPL-3.0 | |
| Podmansickn33/agentic-awesome-skills | 47k | 1 repos | ~2.2k | Automated safety check: Notes | MIT | |
| Sshepherdsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.6k | Automated safety check: Warn | MIT | |
| PodmanBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~1.9k | Automated safety check: Notes | MIT |
sandia-minimega/minimega
This skill should be used when the user asks how to configure, run, automate, integrate, or troubleshoot minimega (VMs, namespaces, VLANs, clusters, miniccc, miniweb, command socket or Python API…
drawthingsai/draw-things-community
Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.
sickn33/agentic-awesome-skills
Manage containers using Podman, the daemonless container engine.
sickn33/agentic-awesome-skills
Zero-knowledge SSH ops CLI — server health checks, docker/systemd control, log tailing, Postgres introspection, and declarative deploys, without ever exposing credentials to the agent.
BagelHole/DevOps-Security-Agent-Skills
Manage containers using Podman, the daemonless container engine.
magnus919/agent-skills
Deploy, manage, and troubleshoot self-hosted GitHub Actions runners.
madeye/shadowvpn
Deploy, install, and run the ShadowVPN client in a target environment — Linux (systemd), macOS (launchd), or Windows (Wintun, foreground launcher or scheduled-task service).
Categories
Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd). Shadowvpn Deploy Server is an agent skill from madeye/shadowvpn. Deploy, install, and run the ShadowVPN server in a target environment (Linux/systemd).
Shadowvpn Deploy Server fits situations like: the user wants to set up; run the shadowvpn-server on a host (VPS; enable internet egress for tunneled clients (IP forwarding + NAT/MASQUERADE); wire up the systemd unit.
Run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a claude-code`. Or copy the skill folder (.claude/skills/shadowvpn-deploy-server in madeye/shadowvpn) into .claude/skills/shadowvpn-deploy-server in your project. Claude Code loads it when a task matches its description.
Run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a codex`. Or copy the skill folder (.claude/skills/shadowvpn-deploy-server in madeye/shadowvpn) into .agents/skills/shadowvpn-deploy-server in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add madeye/shadowvpn --skill shadowvpn-deploy-server -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shadowvpn-deploy-server, .gemini/skills/shadowvpn-deploy-server, .github/skills/shadowvpn-deploy-server and .opencode/skills/shadowvpn-deploy-server in your project.
Going by SKILL.md and its folder, Shadowvpn Deploy Server needs the command-line tools its instructions call (cargo and curl). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Shadowvpn Deploy Server is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Shadowvpn Deploy Server: Minimega (sandia-minimega/minimega, 160 stars), Setup Cpu Proxy Server (drawthingsai/draw-things-community, 580 stars), Podman (sickn33/agentic-awesome-skills, 47k stars) and Sshepherd (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
madeye (a GitHub user) maintains it in madeye/shadowvpn, which has 101 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on August 30, 2026.
Source: madeye/shadowvpn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.