Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Author, test, and deploy Tailscale-compatible huJSON policy files for Headscale tailnets — ACLs, Grants, Tags, Auto Approvers, Tailscale SSH rules.
$ npx skills add magnus919/agent-skills --skill tailnet-policy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install magnus919/agent-skills tailnet-policy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tailscale/skills/tailnet-policy .claude/skills/tailnet-policy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tailnet-policy" agent skill from https://github.com/magnus919/agent-skills/tree/main/tailscale/skills/tailnet-policy into .claude/skills/tailnet-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tailnet-policy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/magnus919/agent-skills/tree/main/tailscale/skills/tailnet-policyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add magnus919/agent-skills --skill tailnet-policy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install magnus919/agent-skills tailnet-policy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/tailscale/skills/tailnet-policy .agents/skills/tailnet-policy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tailnet-policy" agent skill from https://github.com/magnus919/agent-skills/tree/main/tailscale/skills/tailnet-policy into .agents/skills/tailnet-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tailnet-policy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add magnus919/agent-skills --skill tailnet-policy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install magnus919/agent-skills tailnet-policy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/tailscale/skills/tailnet-policy .cursor/skills/tailnet-policy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tailnet-policy" agent skill from https://github.com/magnus919/agent-skills/tree/main/tailscale/skills/tailnet-policy into .cursor/skills/tailnet-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tailnet-policy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/magnus919/agent-skills.git --path tailscale/skills/tailnet-policy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add magnus919/agent-skills --skill tailnet-policy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install magnus919/agent-skills tailnet-policy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/tailscale/skills/tailnet-policy .gemini/skills/tailnet-policy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tailnet-policy" agent skill from https://github.com/magnus919/agent-skills/tree/main/tailscale/skills/tailnet-policy into .gemini/skills/tailnet-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tailnet-policy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install magnus919/agent-skills tailnet-policyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add magnus919/agent-skills --skill tailnet-policy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/tailscale/skills/tailnet-policy .github/skills/tailnet-policy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tailnet-policy" agent skill from https://github.com/magnus919/agent-skills/tree/main/tailscale/skills/tailnet-policy into .github/skills/tailnet-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tailnet-policy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add magnus919/agent-skills --skill tailnet-policy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install magnus919/agent-skills tailnet-policy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/tailscale/skills/tailnet-policy .opencode/skills/tailnet-policy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tailnet-policy" agent skill from https://github.com/magnus919/agent-skills/tree/main/tailscale/skills/tailnet-policy into .opencode/skills/tailnet-policy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tailnet-policy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tailnet-policyAuthor, test, and deploy Tailscale-compatible huJSON policy files for Headscale tailnets — ACLs, Grants, Tags, Auto Approvers, Tailscale SSH rules.
Tailnet Policy is an agent skill from magnus919/agent-skills. Author, test, and deploy Tailscale-compatible huJSON policy files for Headscale tailnets — ACLs, Grants, Tags, Auto Approvers, Tailscale SSH rules. Use when configuring access control, writing policy files, or troubleshooting connectivity issues caused by ACLs.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `README.md`, `evals/evals.json` and `scripts/migrate-acls-to-grants.py`).
It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.
Read from SKILL.md and the folder at commit 22b4723. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python and Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tailnet Policy loads about 2k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 532 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from magnus919/agent-skills at commit 22b4723, republished under its MIT licence (© magnus919). 532 words, ~1,958 tokens.
.claude/skills/tailnet-policy/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Headscale uses Tailscale-compatible policy files written in huJSON (Human JSON — standard JSON with trailing commas and // comments). Policy files control:
{action, users, ports} rules{src, dst, ip, proto, via} rulestag:dev, tag:prod)ssh.users and ssh.action| Feature | ACLs (legacy) | Grants (modern) |
|---|---|---|
| Format | {action: "accept", users: [...], ports: [...]} | {src: [...], dst: [...], ip: [...], proto: "tcp"} |
| Port filtering | Embedded in ports: ["*:*"] | Separate ip field for ports |
| Protocol filtering | Not supported | proto field (tcp, udp, icmp) |
| Destination routing | Not supported | via field for relay/exit nodes |
| Status | Deprecated by Tailscale | Current recommended syntax |
Use Grants wherever possible. The migrate-acls-to-grants.py script can convert legacy ACL files automatically.
The policy file path is configured in Headscale's config.yaml:
policy:
path: /etc/headscale/policy.hujsonAfter modifying the policy file, reload it on the Headscale server:
# Reload via SIGHUP
kill -HUP $(pgrep headscale)
# Or use the convenience script
./skills/tailnet-policy/reload-headscale-policy.sh{
// Grants that allow all traffic
"grants": [
{
"src": ["autogroup:member"],
"dst": ["autogroup:member"],
"ip": ["*:*"]
}
],
// Tag ownership
"tagOwners": {
"tag:dev": ["autogroup:admin"],
"tag:prod": ["autogroup:admin"]
}
}{
"grants": [
// Only allow ICMP (ping) between all members
{
"src": ["autogroup:member"],
"dst": ["autogroup:member"],
"ip": ["*"],
"proto": "icmp"
}
],
// Specific grants added per-service
"tagOwners": {
"tag:monitor": ["autogroup:admin"]
}
}{
"grants": [
// Dev can reach dev
{
"src": ["tag:dev"],
"dst": ["tag:dev"],
"ip": ["*:*"]
},
// Prod can reach prod
{
"src": ["tag:prod"],
"dst": ["tag:prod"],
"ip": ["*:*"]
},
// Admin access to all
{
"src": ["autogroup:admin"],
"dst": ["tag:dev", "tag:prod"],
"ip": ["*:*"]
}
],
"tagOwners": {
"tag:dev": ["autogroup:admin"],
"tag:prod": ["autogroup:admin"]
}
}Tags are node-level identifiers set via tailscale up --advertise-tags=tag:dev. They decouple policy from user identity.
{
"tagOwners": {
"tag:ci-runner": ["autogroup:admin"],
"tag:database": ["autogroup:admin"],
"tag:webserver": ["autogroup:admin"],
"tag:monitoring": ["autogroup:admin"]
},
"grants": [
{
"src": ["tag:monitoring"],
"dst": ["tag:webserver", "tag:database"],
"ip": ["*:*"]
},
{
"src": ["tag:webserver"],
"dst": ["tag:database"],
"ip": ["tcp:5432"]
}
]
}Grants are the modern policy primitive:
{
"grants": [
{
"src": ["tag:source", "user@example.com"],
"dst": ["tag:destination", "100.64.0.1"],
"ip": ["*:*"], // proto:port — "*:*" means all
"proto": "tcp", // optional protocol filter
"via": ["tag:exit-node"] // optional via/routing
}
]
}Fields:
src — Source entities (tags, users, autogroups, IPs)dst — Destination entitiesip — Protocol and port filter (e.g. tcp:80, udp:53, *:*, *)proto — Protocol constraint (tcp, udp, icmp)via — Route through a specific exit node or relayAuto-approvers let specific users approve subnet routes and exit nodes without manual intervention:
{
"autoApprovers": {
"routes": {
"10.0.0.0/8": ["autogroup:admin"],
"172.16.0.0/12": ["alice@example.com"]
},
"exitNode": ["autogroup:admin"]
}
}routes: Maps CIDR ranges to lists of users who can auto-approve those routesexitNode: Lists users who can advertise exit nodesAutogroups are dynamic groups resolved by Headscale/Tailscale at runtime:
| Autogroup | Description |
|---|---|
autogroup:member | All tailnet members |
autogroup:admin | Tailnet admins |
autogroup:tagged | All tagged nodes (any node with at least one tag) |
autogroup:internet | The public internet (used for exit node routing) |
Tailscale SSH rules are configured via the ssh section:
{
"ssh": [
{
"action": "accept", // "accept" or "check"
"src": ["autogroup:admin"],
"dst": ["tag:webserver"],
"users": ["root", "ubuntu"]
},
{
"action": "check", // "check" requires node-level SSH authorization
"src": ["autogroup:member"],
"dst": ["tag:dev"],
"users": ["*"]
}
]
}action: "accept" (allow directly) or "check" (require node-level auth)src: Source users/groupsdst: Destination tags/usersusers: Which OS users can be SSH'd intoPolicy files include test definitions that are validated when loaded:
{
"grants": [...],
"tests": [
{
"src": "alice@example.com",
"dst": "tag:webserver",
"ip": ["tcp:443"],
"action": "accept" // expected result
},
{
"src": "bob@example.com",
"dst": "tag:database",
"ip": ["tcp:22"],
"action": "drop" // expected result
}
]
}Validate tests with:
./skills/tailnet-policy/validate-policy.py --policy policy.hujsondevicePosture or device:managed are Tailscale-onlyipSets and ipprotocol are not supportedautogroup:admin and autogroup:member insteadtag: and contain only lowercase letters, numbers, and hyphensusers field and Grant src field are NOT interchangeable — grants use src/dst, legacy ACLs use users/portsThis skill is automatically loaded when the user's message contains any of these keywords:
Do not use this skill for deploying the Headscale server (load headscale-deploy instead) or for client connectivity issues unrelated to access control (load tailscale-client). It covers huJSON policy authoring and testing only.
© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts) in tailscale/skills/tailnet-policy of magnus919/agent-skills.
Open the folder on GitHubat commit 22b4723
Tailnet Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tailnet Policy this skillmagnus919/agent-skills | 115 | — | ~2k | Automated safety check: Pass | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| K8s Security PoliciesCybereason-Public/owLSM | 280 | 12 repos | ~2k | Automated safety check: Pass | GPL-2.0 | |
| Payloadpayloadcms/payload | 45k | 5 repos | ~6.2k | Automated safety check: Pass | MIT | |
| Convex Setup Authspokvulcan/poker-planning | 115 | 8 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Cognitoitsmostafa/aws-agent-skills | 1.2k | 1 repos | ~2.3k | Automated safety check: Pass | MIT |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Cybereason-Public/owLSM
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
payloadcms/payload
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
spokvulcan/poker-planning
Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
abpframework/abp
ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.
magnus919/agent-skills
Organize durable agent research outputs as summaries, analysis, and evidence dossiers.
magnus919/agent-skills
Build portable, first-person colored ASCII city engines and small GIS-derived city packs.
magnus919/agent-skills
Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.
magnus919/agent-skills
A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…
magnus919/agent-skills
Use Docker Compose to define, run, debug, and harden multi-container applications.
magnus919/agent-skills
Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.
Categories
Author, test, and deploy Tailscale-compatible huJSON policy files for Headscale tailnets — ACLs, Grants, Tags, Auto Approvers, Tailscale SSH rules. Tailnet Policy is an agent skill from magnus919/agent-skills. Author, test, and deploy Tailscale-compatible huJSON policy files for Headscale tailnets — ACLs, Grants, Tags, Auto Approvers, Tailscale SSH rules.
Tailnet Policy fits situations like: configuring access control; writing policy files; troubleshooting connectivity issues caused by ACLs.
Run `npx skills add magnus919/agent-skills --skill tailnet-policy -a claude-code`. Or copy the skill folder (tailscale/skills/tailnet-policy in magnus919/agent-skills) into .claude/skills/tailnet-policy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add magnus919/agent-skills --skill tailnet-policy -a codex`. Or copy the skill folder (tailscale/skills/tailnet-policy in magnus919/agent-skills) into .agents/skills/tailnet-policy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill tailnet-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tailnet-policy, .gemini/skills/tailnet-policy, .github/skills/tailnet-policy and .opencode/skills/tailnet-policy in your project.
Going by SKILL.md and its folder, Tailnet Policy needs Python and a shell for the scripts in its folder. Our summary lists: Python 3; A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Tailnet Policy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Tailnet Policy: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 115 GitHub stars. The repository holds 131 skills in this directory. The repository was last updated on October 10, 2026.
Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.