Agent skill

Tailscale

by magnus919 in magnus919/agent-skills

Deploy and manage the self-hosted Tailscale/Headscale ecosystem: a Headscale control server, tailscale clients, ACL policies, node lifecycle, subnet routing, DERP relays, and backup/migration.

MITAuto-check passedDevOps & Cloud

Install Tailscale

skills CLI
$ npx skills add magnus919/agent-skills --skill tailscale -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills tailscale --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tailscale .claude/skills/tailscale && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tailscale
GitHub stars
116
Token cost
~2k tokens
SKILL.md length
765 words
Files
26 (incl. scripts, references)
Skills in repo
130
Repo updated
First seen
Licence
MIT

At a glance

Deploy and manage the self-hosted Tailscale/Headscale ecosystem: a Headscale control server, tailscale clients, ACL policies, node lifecycle, subnet routing, DERP relays, and backup/migration.

  • The user mentions Tailscale
  • SKILL.md covers Auto-Loading by Context, Sub-Skill Ordering &…, Root Scripts (Shared Utilities) and Available Scripts, plus 6 more sections
  • Runs Shell scripts from its folder; calls bash; needs HEADSCALE_API_KEY
  • Self-hosted VPN infrastructure

What it does

Tailscale is an agent skill from magnus919/agent-skills. Deploy and manage the self-hosted Tailscale/Headscale ecosystem: a Headscale control server, tailscale clients, ACL policies, node lifecycle, subnet routing, DERP relays, and backup/migration. Use when the user mentions Tailscale, Headscale, tailnet, mesh VPN, WireGuard mesh, or self-hosted VPN infrastructure. Do not use this skill for unrelated requests; route to the nearest named specialist.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 28 other files, including scripts and reference files (for example `AGENTS.md`, `README.md` and `evals/evals.json`). Compatibility notes: Requires bash, Python 3.10+, jq, curl, and access to a Headscale server or the headscale CLI. Tailscale client (tailscale) must be installed on target machines.

It sits in DevOps & Cloud. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • The user mentions Tailscale
  • Self-hosted VPN infrastructure
  • Unrelated requests
  • Route to the nearest named specialist

Example prompts

  • “/tailscale”

Requirements

  • Python 3
  • A Bash shell
  • Docker
  • A credential in HEADSCALE_API_KEY
  • Compatibility (from SKILL.md): Requires bash, Python 3.10+, jq, curl, and access to a Headscale server or the `headscale` CLI. Tailscale client (`tailscale`) must be installed on target machines.

What it can do on your machine

Read from SKILL.md and the folder at commit c545c2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • headscale.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HEADSCALE_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires bash, Python 3.10+, jq, curl, and access to a Headscale server or the `headscale` CLI. Tailscale client (`tailscale`) must be installed on target machines.

    From compatibility in the SKILL.md frontmatter.

Context cost

Tailscale loads about 2k tokens when it runs, and up to ~8.7k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 765 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit c545c2b, republished under its MIT licence (© magnus919). 765 words, ~1,956 tokens.

Download SKILL.mdSave it as .claude/skills/tailscale/SKILL.md (or your agent's skills folder). This skill also uses 25 other files; get the full folder from GitHub.
name
tailscale
description
Deploy and manage the self-hosted Tailscale/Headscale ecosystem: a Headscale control server, tailscale clients, ACL policies, node lifecycle, subnet routing, DERP relays, and backup/migration. Use when the user mentions Tailscale, Headscale, tailnet, mesh VPN, WireGuard mesh, or self-hosted VPN infrastructure. Do not use this skill for unrelated requests; route to the nearest named specialist.
compatibility
Requires bash, Python 3.10+, jq, curl, and access to a Headscale server or the `headscale` CLI. Tailscale client (`tailscale`) must be installed on target machines.
license
MIT
metadata.tags
tailscale, headscale, vpn, wireguard, mesh, networking, homelab
metadata.spec-version
1.0

Tailscale + Headscale Skill Bundle

This umbrella skill covers the self-hosted Tailscale ecosystem using Headscale as the open-source control server. It provides 7 sub-skills that are auto-loaded by context.

Auto-Loading by Context

When the user's message matches a trigger keyword, the corresponding sub-skill's SKILL.md is loaded. Multiple sub-skills can load together when triggers overlap.

Trigger KeywordsSub-Skill(s) Loaded
"deploy headscale", "install headscale", "setup headscale server", "headscale config"headscale-deploy
"ACL", "policy file", "tailnet policy", "access control", "grant", "tag owners"tailnet-policy
"install tailscale", "connect to headscale", "tailscale client", "tailscale up", "tailscale status", "diagnose tailscale", "connectivity"tailscale-client
"auth key", "preauthkey", "register node", "approve node", "tag node", "node list", "decommission node"headscale-node-lifecycle
"subnet router", "exit node", "advertise route", "approve route"headscale-routing
"DERP", "relay", "peer relay", "STUN"headscale-derp
"backup headscale", "restore headscale", "migrate headscale", "headscale backup"headscale-backup
"Tailscale", "Headscale", "tailnet", "mesh VPN", "WireGuard mesh", "self-hosted VPN"Loads this umbrella SKILL.md for navigation

Sub-Skill Ordering & Dependencies

headscale-deploy ─────┬──> tailnet-policy ───> headscale-routing
                       │
                       ├──> headscale-node-lifecycle
                       │
                       ├──> tailscale-client
                       │
                       ├──> headscale-derp
                       │
                       └──> headscale-backup (prerequisite: a running headscale instance)
  • headscale-deploy must be completed first — the others require a running Headscale server
  • tailnet-policy (configures ACLs) is recommended before opening the tailnet to other users
  • headscale-derp is optional but recommended for reliability across NATs
  • headscale-backup should be run regularly on any production deployment

Root Scripts (Shared Utilities)

These live in scripts/ at the bundle root and are available to all sub-skills.

Available Scripts

ScriptPurposeInvocation
scripts/headscale-health-check.shProbe Headscale server health: version, node count, and DB integrity. Run it after any control-server change and as the first diagnostic when nodes or clients misbehave.scripts/headscale-health-check.sh --json
scripts/headscale-backup.shCreate a checksummed manifest-backed Headscale archive from configured SQLite and recovery paths. Run before upgrades or migrations; --dry-run previews without writing.scripts/headscale-backup.sh --dry-run --json
scripts/headscale-restore.shValidate and restore a supported manifest-backed archive to its recorded destinations. Run it during recovery; always verify node list and policy afterwards.scripts/headscale-restore.sh --backup headscale-backup-2026-01-01.tar.gz --dry-run --json
scripts/tailscale-status-json.shStructured wrapper around tailscale status --json with peer diagnostics. Run it from any client to check connectivity, peers, and relay/direct paths in machine-readable form.scripts/tailscale-status-json.sh
scripts/test-all.shSmoke test across all bundle scripts (--help, syntax, executability) without requiring a running Headscale. Run it after modifying any bundled script; CI runs it via scripts/check-skill-tests.py.bash scripts/test-all.sh

Templates

Templates live in templates/ and cover common deployment patterns:

  • templates/docker-compose-headscale.yaml — Headscale + embedded DERP + Traefik TLS
  • templates/headscale-config.yaml — Annotated full headscale configuration
  • templates/policy-allow-all.json — Minimal allow-all policy
  • templates/policy-deny-all.json — Locked-down deny-all policy
  • templates/policy-tagged-segmented.json — Tag-based access model
  • templates/derp-map.json — Custom DERP relay map

Environment Variables

VariableUsed ByPurpose
HEADSCALE_URLAllHeadscale server URL (e.g. https://headscale.example.com)
HEADSCALE_API_KEYAllHeadscale API key (created via headscale apikeys create)
TAILSCALE_AUTHKEYtailscale-clientPre-authenticated key for non-interactive client setup

Use the CLI tools

All scripts use --json, --dry-run, and have informative --help output. Scripts relative to bundle root: scripts/<tool> or skills/<sub-skill>/scripts/<tool>.

See the individual sub-skill SKILL.md for detailed usage.

Show full SKILL.md (315 more words)Show less

Prerequisites

  • bash, Python 3.10+, jq, and curl on the host running the scripts (per compatibility).
  • A running Headscale server with HEADSCALE_URL and HEADSCALE_API_KEY set for server-side operations (API key created via headscale apikeys create); TAILSCALE_AUTHKEY for non-interactive client enrollment.
  • The tailscale client installed on target machines for status and routing sub-skills; the headscale CLI (or API access) for control-server administration.
  • For headscale-backup/restore: filesystem access to the server's sqlite DB, config, policy, and cert paths, plus storage for archives off the control-server host.
  • For migration: install the verified restore helper on the destination at the same path as the source helper, or set HEADSCALE_REMOTE_RESTORE_SCRIPT to the destination path; prepare the recorded archive paths and directory ownership before restoring.

Limitations

  • This bundle assumes a self-hosted Headscale control plane — it does not manage Tailscale's hosted SaaS (see When not to use).
  • Scripts check environment variables at runtime and error helpfully when missing; they do not create credentials themselves.
  • Backup/restore operates on the files present on the control-server host; it cannot recover data that was never backed up, and a restore should always be followed by health verification.
  • Restore accepts manifest version 1 archives and refuses older unmanifested tarballs. Migration requires the verified restore helper to be installed on the destination and does not fall back to raw extraction or report success without a verified restore result. Prepare the archived paths and target directory ownership before migration; root overrides that move files are rejected until config and service paths are separately updated and validated.
  • Sub-skill scripts live under skills/<sub-skill>/scripts/ and are documented in their own SKILL.md files, not here.

When not to use

Do not load this umbrella when a task maps to a single sub-skill — load the matching sub-skill directly (e.g. headscale-deploy, tailnet-policy, tailscale-client). It assumes a self-hosted Headscale control server; for Tailscale's hosted SaaS control plane, or for non-Tailscale VPN tooling, use the appropriate network skill instead.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 25 other files (scripts, references) in tailscale of magnus919/agent-skills.

  • SKILL.md
  • AGENTS.md
  • README.md
  • evals/evals.json
  • manifest.yaml
  • references/derp-architecture.md
  • references/headscale-cli-commands.md
  • references/headscale-rest-api.md
  • references/identity-model.md
  • references/policy-syntax-reference.md
  • references/routing-reference.md
  • references/tailscale-client-flags.md
  • references/troubleshooting-guide.md
  • scripts/headscale-backup.sh
  • scripts/headscale-health-check.sh
  • scripts/headscale-restore.sh
  • scripts/tailscale-status-json.sh
  • scripts/test-all.sh
  • … and 8 more

Open the folder on GitHubat commit c545c2b

Compare with similar skills

Tailscale next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tailscale compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tailscale this skillmagnus919/agent-skills116—~2kAutomated safety check: PassMIT
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from magnus919/agent-skills

All 130 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    116 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    116 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    116 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    116 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    116 GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    116 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Tailscale

What does Tailscale do?

Deploy and manage the self-hosted Tailscale/Headscale ecosystem: a Headscale control server, tailscale clients, ACL policies, node lifecycle, subnet routing, DERP relays, and backup/migration. Tailscale is an agent skill from magnus919/agent-skills. Deploy and manage the self-hosted Tailscale/Headscale ecosystem: a Headscale control server, tailscale clients, ACL policies, node lifecycle, subnet routing, DERP relays, and backup/migration.

When should I use Tailscale?

Tailscale fits situations like: the user mentions Tailscale; self-hosted VPN infrastructure; unrelated requests; route to the nearest named specialist.

How do I install Tailscale in Claude Code?

Run `npx skills add magnus919/agent-skills --skill tailscale -a claude-code`. Or copy the skill folder (tailscale in magnus919/agent-skills) into .claude/skills/tailscale in your project. Claude Code loads it when a task matches its description.

How do I install Tailscale in Codex?

Run `npx skills add magnus919/agent-skills --skill tailscale -a codex`. Or copy the skill folder (tailscale in magnus919/agent-skills) into .agents/skills/tailscale in your project. Codex loads it when a task matches its description.

Can I use Tailscale in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill tailscale -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tailscale, .gemini/skills/tailscale, .github/skills/tailscale and .opencode/skills/tailscale in your project.

What does Tailscale need to run?

Going by SKILL.md and its folder, Tailscale needs a shell for the scripts in its folder, the command-line tools its instructions call (bash) and credentials named HEADSCALE_API_KEY. Our summary lists: Python 3; A Bash shell; Docker; A credential in HEADSCALE_API_KEY. Compatibility (from SKILL.md): Requires bash, Python 3.10+, jq, curl, and access to a Headscale server or the `headscale` CLI. Tailscale client (`tailscale`) must be installed on target machines..

Does Tailscale access the network?

SKILL.md names 1 domain. As links in the text: headscale.net. This is read from the text; nothing was executed.

Is Tailscale safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tailscale use?

Tailscale is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tailscale use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.8k tokens, read only when the agent opens those files.

What are the alternatives to Tailscale?

Skills that share tags, products or a category with Tailscale: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tailscale?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 116 GitHub stars. The repository holds 130 skills in this directory. The repository was last updated on October 8, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.