Agent skill

Tailscale Client

by magnus919 in magnus919/agent-skills

Install, configure, and troubleshoot the official Tailscale client when connected to a Headscale self-hosted control server.

MITAuto-check: notes

Install Tailscale Client

skills CLI
$ npx skills add magnus919/agent-skills --skill tailscale-client -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills tailscale-client --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tailscale/skills/tailscale-client .claude/skills/tailscale-client && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tailscale-client
GitHub stars
116
Token cost
~1.7k tokens
SKILL.md length
653 words
Files
7 (incl. scripts)
Skills in repo
130
Repo updated
First seen
Licence
MIT

At a glance

Install, configure, and troubleshoot the official Tailscale client when connected to a Headscale self-hosted control server.

  • Connecting a new device
  • SKILL.md covers Overview, Installation, Connection and Authentication, plus 6 more sections
  • Runs Shell and Python scripts from its folder; calls dnf, curl and apt-get; reaches pkgs.tailscale.com
  • Diagnosing connectivity

What it does

Tailscale Client is an agent skill from magnus919/agent-skills. Install, configure, and troubleshoot the official Tailscale client when connected to a Headscale self-hosted control server. Use when connecting a new device, diagnosing connectivity, checking peer status, or troubleshooting DERP relay issues.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `README.md`, `evals/evals.json` and `scripts/ts-connectivity-report.py`).

The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • Connecting a new device
  • Diagnosing connectivity
  • Checking peer status
  • Troubleshooting DERP relay issues

Example prompts

  • “/tailscale-client”

Requirements

  • Python 3
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit c545c2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • dnf
    • curl
    • apt-get
    • brew
    • choco
    • apk

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • pkgs.tailscale.com

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tailscale Client loads about 1.7k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 653 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:43
    le.com/stable/ubuntu/jammy.noarmor.gpg | sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg >/dev/null && curl -
  • NoteRuns commands with sudoSKILL.md:46
    | **Fedora/RHEL** | `sudo dnf install dnf-plugins-core && sudo dnf config-manager --add-repo https://pkgs.tailscale.com/
  • NoteRuns commands with sudoSKILL.md:56
    sudo tailscale up --login-server=https://headscale.example.com
  • NoteRuns commands with sudoSKILL.md:63
    sudo tailscale up \
  • NoteRuns commands with sudoSKILL.md:95
    sudo tailscale up \
  • NoteRuns commands with sudoSKILL.md:145
    CLI commands work. On systemd systems: `sudo systemctl start tailscaled`.
  • NoteRuns commands with sudoSKILL.md:146
    acOS: open the Tailscale GUI app or run `sudo tailscaled`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit c545c2b, republished under its MIT licence (© magnus919). 653 words, ~1,665 tokens.

Download SKILL.mdSave it as .claude/skills/tailscale-client/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
tailscale-client
description
Install, configure, and troubleshoot the official Tailscale client when connected to a Headscale self-hosted control server. Use when connecting a new device, diagnosing connectivity, checking peer status, or troubleshooting DERP relay issues.
metadata.category
devops

tailscale-client

Overview

Tailscale is a WireGuard-based mesh VPN that connects devices into a secure tailnet. When used with Headscale, a self-hosted open-source control server, the official Tailscale client connects via the --login-server flag instead of Tailscale's SaaS control plane.

This skill covers client-side installation, authentication, diagnostics, and troubleshooting.

Architecture
[Client A] ───── WireGuard ───── [Client B]
      │                               │
      └──────── Headscale URL ────────┘
                  (control/
                 coordination)

The Tailscale client (the tailscaled daemon) registers with the Headscale control server, exchanges WireGuard keys, and establishes direct peer-to-peer encrypted connections. When direct NAT traversal fails, traffic falls back through DERP (Detour Encrypted Relay Protocol) relays.

Installation

Install the official Tailscale client on the target device:

PlatformCommand
Debian/Ubuntu`curl -fsSL https://pkgs.tailscale.com/stable/ubuntu/jammy.noarmor.gpg
macOSbrew install tailscale
Windowschoco install tailscale
Fedora/RHELsudo dnf install dnf-plugins-core && sudo dnf config-manager --add-repo https://pkgs.tailscale.com/stable/fedora/tailscale.repo && sudo dnf install tailscale
Alpineapk add tailscale

See ts-install.sh for automated detection and installation.

Connection

After installation, authenticate with your Headscale server:

bash
sudo tailscale up --login-server=https://headscale.example.com

This opens a browser for web-based authentication OR prints an auth URL at the terminal. For non-interactive (scripted) setups, use a pre-authentication key:

bash
sudo tailscale up \
  --login-server=https://headscale.example.com \
  --authkey=tskey-auth-xxxxx-xxxxxxxxxxxxxxxxxxxxxxxxxxxxx

See ts-up.sh for a wrapper with env-var defaults.

Authentication

Web Auth

The default tailscale up flow prints a URL (e.g. https://headscale.example.com/register/nodekey:xxxxx). Visit this URL in a browser (or pass it to the Headscale admin to approve).

Pre-Auth Keys

Generate on the Headscale server:

bash
headscale preauthkeys create --user myuser

Use the key with --authkey as shown above. Keys can be tagged for service/auth nodes that don't belong to a specific user:

bash
headscale preauthkeys create --user myuser --tags tag:ci-runner,tag:monitoring

Then on the client:

bash
sudo tailscale up \
  --login-server=https://headscale.example.com \
  --authkey=tskey-auth-xxxxx \
  --advertise-tags=tag:ci-runner

Diagnostics

CommandPurpose
tailscale status --jsonList all peers and their connection state
tailscale ping --verbose -c 3 <peer>Test direct vs. relay path to a peer
tailscale netcheckCheck NAT type and DERP relay connectivity
tailscale versionClient and daemon version info
tailscale debugLow-level debugging (derp-map, metrics, goroutines)

Run ts-diagnostics.sh for a comprehensive connectivity bundle that collects all of the above into a structured JSON output. Use ts-connectivity-report.py to interpret the diagnostics and produce a human-readable or structured report.

Features

FeatureHeadscale SupportNotes
MagicDNS✅ Supported--accept-dns must be passed to tailscale up
Taildrop / Taildrive✅ SupportedFile sharing between peers
Tailscale SSH✅ Supported--ssh flag on tailscale up
Serve✅ SupportedExpose local services via tailnet
Funnel❌ Not supportedFunnel requires Tailscale's SaaS control plane
Exit Nodes✅ SupportedAdvertise with --advertise-exit-node, use with --exit-node
Show full SKILL.md (267 more words)Show less

Environment Variables

VariablePurpose
HEADSCALE_URLDefault --login-server URL for ts-up.sh
TAILSCALE_AUTHKEYDefault --authkey for ts-up.sh

Gotchas

  • Port conflicts (8080, 8443): Tailscale Serve often uses 8080 or 8443. Check for conflicts with lsof -i :8080.
  • Subnet overlap: If the tailnet subnets overlap with local networks, routes may not work. Review advertised routes carefully.
  • DERP-only fallback: When NAT traversal fails, peers connect via DERP relays only. Latency increases significantly. Check with ts-diagnostics.sh or tailscale status --json and look for "relay":"..." instead of "txBytes"/"rxBytes" on the direct path.
  • tailscaled not running: The daemon must be started before tailscale CLI commands work. On systemd systems: sudo systemctl start tailscaled. On macOS: open the Tailscale GUI app or run sudo tailscaled.
  • DNS resolution: MagicDNS requires --accept-dns on tailscale up. Without it, nodes are only reachable by their Tailscale IP (100.x.x.x).
  • Key expiry: Node keys expire by default. Use --force-reauth or re-run tailscale up to re-authenticate. Pre-auth keys can be created with --expiry=false for non-expiring (long-lived) nodes.

Trigger Conditions

This skill should be loaded when the user mentions any of the following:

  • Installing or setting up Tailscale client on any platform
  • Connecting a device to a Headscale server
  • Tailscale authentication issues (auth key, web auth, node approval)
  • Checking tailscale status, ping, or connectivity
  • DERP relay problems or NAT traversal failures
  • Tailscale SSH, Serve, MagicDNS, or Taildrop configuration
  • Troubleshooting "tailscaled not running" or "no connection"
  • Interpreting tailscale status, tailscale ping, or tailscale netcheck output

When not to use

Do not use this skill for server-side Headscale deployment (load headscale-deploy instead) or for ACL/policy authoring (load tailnet-policy). It covers client installation, authentication, and diagnostics only.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts) in tailscale/skills/tailscale-client of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • scripts/ts-connectivity-report.py
  • scripts/ts-diagnostics.sh
  • scripts/ts-install.sh
  • scripts/ts-up.sh

Open the folder on GitHubat commit c545c2b

Compare with similar skills

Tailscale Client next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tailscale Client compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tailscale Client this skillmagnus919/agent-skills116—~1.7kAutomated safety check: NotesMIT
ConnectComposioHQ/awesome-claude-skills77k3 repos~987Automated safety check: PassNone
Integration Connectivity Connected App Configureforcedotcom/sf-skills1.1k—~2.7kAutomated safety check: NotesApache-2.0
Configure Channelopenclaw/openclaw392k—~946Automated safety check: PassMIT
Node Connectopenclaw/openclaw392k—~1.6kAutomated safety check: PassMIT
ConfigurationBuilderIO/agent-native7.1k—~2.1kAutomated safety check: PassNone

Similar skills

  • Connect

    ComposioHQ/awesome-claude-skills

    Connect Claude to any app. An agent skill from ComposioHQ/awesome-claude-skills.

    77k GitHub starsUsed in 3 repos~987 tokens
    Productivity & AutomationAuto-check passed
  • Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring.

    1.1k GitHub stars~2.7k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes
  • Configure Channel

    openclaw/openclaw

    Configure and prove a chat channel with non-interactive one-liners; secrets only as SecretRefs.

    392k GitHub stars~946 tokensUpdated today
    Auto-check passed
  • Node Connect

    openclaw/openclaw

    Diagnose OpenClaw Control UI browser and native Android, iOS, or macOS node connection failures across route, auth, pairing, QR/setup-code, and reconnect states.

    392k GitHub stars~1.6k tokensUpdated today
    MobileAuto-check passed
  • Configuration

    BuilderIO/agent-native

    Where a configuration value belongs — app config schema, agent-native.config.ts, or an environment variable — and how the layers resolve.

    7.1k GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Openwork Connect

    different-ai/openwork

    Search and use the skills, MCP connections, and connected services available through the user's OpenWork organization.

    24k GitHub stars~370 tokensUpdated today
    Agent WorkflowsAuto-check passed

More from magnus919/agent-skills

All 130 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    116 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    116 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    116 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    116 GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Questions about Tailscale Client

What does Tailscale Client do?

Install, configure, and troubleshoot the official Tailscale client when connected to a Headscale self-hosted control server. Tailscale Client is an agent skill from magnus919/agent-skills. Install, configure, and troubleshoot the official Tailscale client when connected to a Headscale self-hosted control server.

When should I use Tailscale Client?

Tailscale Client fits situations like: connecting a new device; diagnosing connectivity; checking peer status; troubleshooting DERP relay issues.

How do I install Tailscale Client in Claude Code?

Run `npx skills add magnus919/agent-skills --skill tailscale-client -a claude-code`. Or copy the skill folder (tailscale/skills/tailscale-client in magnus919/agent-skills) into .claude/skills/tailscale-client in your project. Claude Code loads it when a task matches its description.

How do I install Tailscale Client in Codex?

Run `npx skills add magnus919/agent-skills --skill tailscale-client -a codex`. Or copy the skill folder (tailscale/skills/tailscale-client in magnus919/agent-skills) into .agents/skills/tailscale-client in your project. Codex loads it when a task matches its description.

Can I use Tailscale Client in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill tailscale-client -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tailscale-client, .gemini/skills/tailscale-client, .github/skills/tailscale-client and .opencode/skills/tailscale-client in your project.

What does Tailscale Client need to run?

Going by SKILL.md and its folder, Tailscale Client needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (dnf, curl, apt-get, brew, choco and apk). Our summary lists: Python 3; A Bash shell.

Does Tailscale Client access the network?

SKILL.md names 2 domains. In commands or code: pkgs.tailscale.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Tailscale Client safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tailscale Client use?

Tailscale Client is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tailscale Client use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tailscale Client?

Skills that share tags, products or a category with Tailscale Client: Connect (ComposioHQ/awesome-claude-skills, 77k stars), Integration Connectivity Connected App Configure (forcedotcom/sf-skills, 1.1k stars), Configure Channel (openclaw/openclaw, 392k stars) and Node Connect (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tailscale Client?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 116 GitHub stars. The repository holds 130 skills in this directory. The repository was last updated on October 8, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.