Orchardcore Admin Edit Views
OrchardCMS/OrchardCore
Creates and updates OrchardCore admin edit views using the ocat- CSS class conventions.
Tailscale admin from the terminal, with safe route and policy edits an agent can plan before it writes.
$ npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mvanhorn/printing-press-library pp-tailscale --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-skills/pp-tailscale .claude/skills/pp-tailscale && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pp-tailscale" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-tailscale into .claude/skills/pp-tailscale/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-tailscale", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-tailscaleType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mvanhorn/printing-press-library pp-tailscale --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .agents/skills && cp -r skills-src/cli-skills/pp-tailscale .agents/skills/pp-tailscale && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pp-tailscale" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-tailscale into .agents/skills/pp-tailscale/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-tailscale", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mvanhorn/printing-press-library pp-tailscale --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/cli-skills/pp-tailscale .cursor/skills/pp-tailscale && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pp-tailscale" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-tailscale into .cursor/skills/pp-tailscale/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-tailscale", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mvanhorn/printing-press-library.git --path cli-skills/pp-tailscale--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mvanhorn/printing-press-library pp-tailscale --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/cli-skills/pp-tailscale .gemini/skills/pp-tailscale && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pp-tailscale" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-tailscale into .gemini/skills/pp-tailscale/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-tailscale", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mvanhorn/printing-press-library pp-tailscaleInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .github/skills && cp -r skills-src/cli-skills/pp-tailscale .github/skills/pp-tailscale && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pp-tailscale" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-tailscale into .github/skills/pp-tailscale/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-tailscale", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mvanhorn/printing-press-library pp-tailscale --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/cli-skills/pp-tailscale .opencode/skills/pp-tailscale && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pp-tailscale" agent skill from https://github.com/mvanhorn/printing-press-library/tree/main/cli-skills/pp-tailscale into .opencode/skills/pp-tailscale/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pp-tailscale", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pp-tailscaleTailscale admin from the terminal, with safe route and policy edits an agent can plan before it writes.
Pp Tailscale is an agent skill from mvanhorn/printing-press-library. Tailscale admin from the terminal, with safe route and policy edits an agent can plan before it writes. Trigger phrases: approve the exit node, check tailscale key expiry, add a tailscale policy entry, who has this machine shared, who can reach the nas on port 445, use tailscale, run tailscale-pp-cli.
Its SKILL.md is about 11k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Official library of CLIs generated by the CLI Printing Press. Endorsed, tested, and community-contributed. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 0fdcc7a. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBashFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
goclaudenpxFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
login.tailscale.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
TAILSCALE_API_KEYTAILSCALE_OAUTH_CLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pp Tailscale loads about 11k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 5,029 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mvanhorn/printing-press-library at commit 0fdcc7a, republished under its Apache-2.0 licence (© mvanhorn). 5,029 words, ~11,150 tokens.
.claude/skills/pp-tailscale/SKILL.md (or your agent's skills folder).<!-- GENERATED FILE — DO NOT EDIT.
This file is a verbatim mirror of library/cloud/tailscale/SKILL.md,
regenerated post-merge by tools/generate-skills/. Hand-edits here are
silently overwritten on the next regen. Edit the library/ source instead.
See the repository agent guide, section "Generated artifacts: registry.json, cli-skills/". -->
This skill drives the tailscale-pp-cli binary. You must verify the CLI is installed before invoking any command from this skill. If it is missing, install it first:
$HOME/.local/bin on macOS/Linux and %LOCALAPPDATA%\Programs\PrintingPress\bin on Windows:npx -y @mvanhorn/printing-press-library install tailscale --cli-onlytailscale-pp-cli --version$PATH for the agent/runtime that will invoke this skill.If the npx install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.6 or newer). This installs into $GOPATH/bin (default $HOME/go/bin), so add that directory to $PATH instead:
go install github.com/mvanhorn/printing-press-library/library/cloud/tailscale/cmd/tailscale-pp-cli@latestIf --version reports "command not found" after install, the runtime cannot see the binary directory on $PATH. Do not proceed with skill commands until verification succeeds.
Nearly every Tailscale admin API endpoint (tailnet deletion is deliberately left out), plus commands that make the two dangerous whole-object writes safe: routes approve keeps the routes a device already has, and policy add-entry keeps comments, backs up, validates, diffs, and writes with an ETag check. Those safe-write commands (routes approve and unapprove, shares revoke, policy add-entry and restore) write only with --yes and are plan-only as MCP tools; in --agent mode every other mutation is a dry run unless --yes. devices expiry, routes overview, and shares audit answer fleet questions the admin console shows one machine at a time, and access check and devices inspect give an agent one target's full picture before it acts.
Use this CLI when an agent or operator needs to administer a tailnet: approve routes and exit nodes, edit the policy file, audit or revoke machine shares, check key expiry, or ask which rules allow a connection. It is the right choice when a change must not clobber existing routes or policy content. The device selector self means this machine and needs the local tailscale command; otherwise pass a hostname, MagicDNS name, Tailscale IP, or nodeId.
Do not use this CLI for:
These capabilities aren't available in any other tool for this API.
routes approve — Approve a subnet route or exit node on one device without dropping the routes it already has.
Reach for this instead of the raw routes endpoint whenever an agent is asked to enable an exit node or subnet route.
tailscale-pp-cli routes approve self --all-advertisedroutes unapprove — Remove approval for one route or the exit-node pair while leaving every other approved route in place.
Use it to turn off an exit node without breaking the subnet routes on the same machine.
tailscale-pp-cli routes unapprove self --exit-nodepolicy add-entry — Append one nodeAttrs, grants, acls, or ssh entry to the policy file with comments preserved, a local backup, validation, a diff, and a concurrency check.
Use it whenever an agent needs to add Taildrive, Funnel, or access grants without rewriting the whole policy file.
tailscale-pp-cli policy add-entry nodeAttrs --entry '{"target":["autogroup:member"],"attr":["drive:access"]}' --dry-runpolicy restore — Roll the policy file back to a local backup after validating it and showing the diff.
This is the undo for every policy write the CLI makes.
tailscale-pp-cli policy restore --listroutes overview — See approved, pending, and stale routes and exit-node state for every device in one table.
Run it before approving anything to see what is actually waiting.
tailscale-pp-cli routes overview --pendingdevices expiry — List every device by days until its key expires and flag the ones inside a window.
Use it as a weekly check or a CI gate so nobody gets logged out by surprise.
tailscale-pp-cli devices expiry --within 14shares audit — List every machine-share invite across the tailnet with who accepted it and which invites are still redeemable.
Answer who has access to a shared machine in one call.
tailscale-pp-cli shares audit --pendingshares revoke — Revoke machine-share invites by ID or by device and acceptor, with a plan before any delete.
Use it to revoke a contractor's share invites without hunting IDs device by device, then confirm in the admin console that an accepted share is gone.
tailscale-pp-cli shares revoke --device self --pendingaccess check — Show which policy rules let a user reach a device and port, against the live policy or a candidate file.
Check access before and after a policy change without guessing at rule evaluation.
tailscale-pp-cli access check --to self:22devices inspect — Get one device's identity, routes, key expiry, shares, and recent changes in a single record.
Make this the first call in any task about a specific machine.
tailscale-pp-cli devices inspect self --agentEvery Tailscale admin API endpoint except tailnet deletion, grouped by resource. Writes (POST/PUT/PATCH/DELETE) run as dry runs under --agent unless --yes is passed. Add --help to any command for its flags.
device
tailscale-pp-cli device attributes delete <deviceId> <attributeKey> (DELETE): Delete a posture attribute from the specified device.tailscale-pp-cli device attributes list <deviceId> (GET): Retrieve all posture attributes for the specified device.tailscale-pp-cli device attributes set <deviceId> <attributeKey> (POST): Create or update a custom posture attribute on the specified device.tailscale-pp-cli device authorized set <deviceId> (POST): This call marks a device as authorized or revokes its authorization for tailnets where device authorization is required.tailscale-pp-cli device delete <deviceId> (DELETE): Deletes the device from its tailnet.tailscale-pp-cli device device-invites create <deviceId> (POST): Create new share invites for a device.tailscale-pp-cli device device-invites list <deviceId> (GET): List all share invites for a device. OAuth Scope: device_invites:read.tailscale-pp-cli device expire key <deviceId> (POST): Mark a device's node key as expired.tailscale-pp-cli device get <deviceId> (GET): Retrieve the details for the specified device. OAuth Scope: devices:core:read.tailscale-pp-cli device ip set <deviceId> (POST): When a device is added to a tailnet, its Tailscale IPv4 address is set at random either from the CGNAT range.tailscale-pp-cli device key set <deviceId> (POST): When a device is added to a tailnet, its key expiry is set according to the tailnet's key expiry setting.tailscale-pp-cli device name set <deviceId> (POST): When a device is added to a tailnet, its Tailscale device name.tailscale-pp-cli device routes list <deviceId> (GET): Retrieve the list of subnet routes that a device is advertising, as well as those that are enabled for it.tailscale-pp-cli device routes set <deviceId> (POST): Set a device's enabled subnet routes by replacing the existing list of subnet routes with the supplied parameters.tailscale-pp-cli device tags set <deviceId> (POST): Tags let you assign an identity to a device that is separate from human users.device-invites
tailscale-pp-cli device-invites accept (POST): Accepts the invitation to share a device into the requesting user's tailnet.tailscale-pp-cli device-invites delete <deviceInviteId> (DELETE): Delete a specific device invite. OAuth Scope: device_invites.tailscale-pp-cli device-invites get <deviceInviteId> (GET): Retrieve a specific device invite. OAuth Scope: device_invites:read.tailscale-pp-cli device-invites resend device-invite <deviceInviteId> (POST): Resend a device invite by email.organizations
tailscale-pp-cli organizations tailnets create <organization> (POST): Create an API-only tailnet in the organization.tailscale-pp-cli organizations tailnets list <organization> (GET): List all tailnets in the organization, including the original tailnet and any API-only tailnets.posture
tailscale-pp-cli posture delete <id> (DELETE): Delete a specific posture integration. OAuth Scope: feature_settings.tailscale-pp-cli posture get <id> (GET): Gets the posture integration identified by {id}. OAuth Scope: feature_settings:read.tailscale-pp-cli posture update <id> (PATCH): Updates the posture integration identified by {id}.tailnet
tailscale-pp-cli tailnet acl get (GET): Retrieves the current policy file for the given tailnet.tailscale-pp-cli tailnet acl preview (POST): When given a user or IP port to match against, returns the tailnet policy rules that apply to that resource.tailscale-pp-cli tailnet acl set (POST): Sets the ACL for the given tailnet.tailscale-pp-cli tailnet acl validate (POST): This endpoint works in one of two modes, neither of which modifies your current tailnet policy file: - Run ACL tests.tailscale-pp-cli tailnet aws-external-id create-or-get (POST): Get an AWS external id to use for streaming tailnet logs to S3 using role-based authentication.tailscale-pp-cli tailnet aws-external-id validate <id> (POST): Validate that Tailscale can assume your IAM role with (and only with) this external ID. OAuth Scope: log_streaming.tailscale-pp-cli tailnet contacts get (GET): Retrieve the tailnet's current contacts. OAuth Scope: account_settings:read.tailscale-pp-cli tailnet contacts resend-verification-email (POST): Resends the verification email for this contact, if and only if verification is still pending.tailscale-pp-cli tailnet contacts update (PATCH): Update the preferences for this type of contact.tailscale-pp-cli tailnet device-attributes batch-update (PATCH): Batch updates posture attributes across devices in a tailnet.tailscale-pp-cli tailnet devices list (GET): Lists the devices in a tailnet. OAuth Scope: devices:core:read.tailscale-pp-cli tailnet dns get-configuration (GET): Retrieves the full DNS configuration for a tailnet, including global nameservers, split DNS routes, search paths.tailscale-pp-cli tailnet dns get-preferences (GET): Retrieves the DNS preferences that are currently set for the given tailnet.tailscale-pp-cli tailnet dns get-split (GET): Retrieves the split DNS settings, which is a map from domains to lists of nameservers.tailscale-pp-cli tailnet dns list-nameservers (GET): Lists the global DNS nameservers for a tailnet.tailscale-pp-cli tailnet dns list-search-paths (GET): Retrieves the list of search paths, also referred to as search domains, that is currently set for the given tailnet.tailscale-pp-cli tailnet dns set-configuration (POST): Replaces the DNS configuration for the given tailnet.tailscale-pp-cli tailnet dns set-nameservers (POST): Replaces the list of global DNS nameservers for the given tailnet with the list supplied in the request.tailscale-pp-cli tailnet dns set-preferences (POST): Set the DNS preferences for a tailnet; specifically, the MagicDNS setting.tailscale-pp-cli tailnet dns set-search-paths (POST): Replaces the list of search paths for the given tailnet.tailscale-pp-cli tailnet dns set-split (PUT): Replaces the split DNS settings for a given tailnet.tailscale-pp-cli tailnet dns update-split (PATCH): Performs partial updates of the split DNS settings for a given tailnet.tailscale-pp-cli tailnet keys create (POST): Creates a new auth key.tailscale-pp-cli tailnet keys delete <keyId> (DELETE): Deletes a specific api access token or auth key.tailscale-pp-cli tailnet keys get <keyId> (GET): Returns a JSON object with information about a specific api access token, OAuth client, federated identity, or auth key.tailscale-pp-cli tailnet keys list (GET): Returns a list of active auth keys, API access tokens and trust credentials.tailscale-pp-cli tailnet keys set <keyId> (PUT): Set the configuration for an existing OAuth client or federated identity.tailscale-pp-cli tailnet logging disable-log-streaming (DELETE): Delete the log streaming configuration for the provided log type. OAuth Scope: log_streaming.tailscale-pp-cli tailnet logging get-log-streaming-configuration (GET): Retrieve the log streaming configuration for the provided log type. OAuth Scope: log_streaming:read.tailscale-pp-cli tailnet logging get-log-streaming-status (GET): Retrieve the log streaming status for the provided log type. OAuth Scope: log_streaming:read.tailscale-pp-cli tailnet logging list-configuration-audit-logs (GET): List all configuration audit logs for a tailnet. OAuth Scope: logs:configuration:read.tailscale-pp-cli tailnet logging list-network-flow-logs (GET): List all network flow logs for a tailnet. OAuth Scope: logs:network:read.tailscale-pp-cli tailnet logging set-log-streaming-configuration (PUT): Set the log streaming configuration for the provided log type. OAuth Scope: log_streaming.tailscale-pp-cli tailnet oauth-apps create (POST): Create an OAuth app within a tailnet.tailscale-pp-cli tailnet oauth-apps delete <appId> (DELETE): Delete a specific OAuth app. OAuth Scope: oauth_apps.tailscale-pp-cli tailnet oauth-apps get <appId> (GET): Retrieve a specific OAuth app. OAuth Scope: oauth_apps:read.tailscale-pp-cli tailnet oauth-apps list (GET): List all OAuth apps for a tailnet. OAuth Scope: oauth_apps:read.tailscale-pp-cli tailnet oauth-apps update <appId> (PUT): Update a specific OAuth app.tailscale-pp-cli tailnet posture create (POST): Create a posture integration, returning the resulting PostureIntegration.tailscale-pp-cli tailnet posture list (GET): List all of the posture integrations for a tailnet. OAuth Scope: feature_settings:read.tailscale-pp-cli tailnet services delete <serviceName> (DELETE): Delete the specified Service from the tailnet. OAuth Scope: services.tailscale-pp-cli tailnet services get <serviceName> (GET): Retrieve the details for the specified Service. OAuth Scope: services:read.tailscale-pp-cli tailnet services get-device-approval <serviceName> <deviceId> (GET): Retrieve the approval status of the specified Service on a specific device. OAuth Scope: services.tailscale-pp-cli tailnet services list (GET): List all Services configured for the tailnet.tailscale-pp-cli tailnet services list-hosts <serviceName> (GET): List all devices that are hosting the specified Service. OAuth Scope: services.tailscale-pp-cli tailnet services update <serviceName> (PUT): Update or create the specified Service.tailscale-pp-cli tailnet services update-device-approval <serviceName> <deviceId> (POST): Update the approval status of the specified Service on a specific device. OAuth Scope: services.tailscale-pp-cli tailnet settings get (GET): Retrieve the settings for a specific tailnet.tailscale-pp-cli tailnet settings update (PATCH): Update the settings for a specific tailnet.tailscale-pp-cli tailnet user-invites create (POST): Create, and optionally email out, new user invites to join the tailnet.tailscale-pp-cli tailnet user-invites list (GET): List all open (not yet accepted) user invites to the tailnet.tailscale-pp-cli tailnet users list (GET): List all users of a tailnet. OAuth Scope: users:read.tailscale-pp-cli tailnet webhooks create (POST): Create a webhook within a tailnet. OAuth Scope: webhooks.tailscale-pp-cli tailnet webhooks list (GET): List all webhooks for a tailnet. OAuth Scope: webhooks:read.user-invites
tailscale-pp-cli user-invites delete <userInviteId> (DELETE): Deletes a specific user invite.tailscale-pp-cli user-invites get <userInviteId> (GET): Retrieve a specific user invite.tailscale-pp-cli user-invites resend user-invite <userInviteId> (POST): Resend a user invite by email.users
tailscale-pp-cli users <userId> (GET): Retrieve details about the specified user. OAuth Scope: users:read.tailscale-pp-cli users approve user <userId> (POST): Approve a pending user's access to the tailnet.tailscale-pp-cli users delete user <userId> (POST): Delete a user from their tailnet.tailscale-pp-cli users restore user <userId> (POST): Restores a suspended user's access to their tailnet.tailscale-pp-cli users role set <userId> (POST): Update the role for the specified user. OAuth Scope: users.tailscale-pp-cli users suspend user <userId> (POST): Suspends a user from their tailnet.webhooks
tailscale-pp-cli webhooks delete <endpointId> (DELETE): Delete a specific webhook. OAuth Scope: webhooks.tailscale-pp-cli webhooks get <endpointId> (GET): Retrieve a specific webhook. OAuth Scope: webhooks:read.tailscale-pp-cli webhooks rotate webhook-secret <endpointId> (POST): Rotate and generate a new secret for a specific webhook.tailscale-pp-cli webhooks test webhook <endpointId> (POST): Test a specific webhook by sending out a test event to the endpoint URL.tailscale-pp-cli webhooks update <endpointId> (PATCH): Update a specific webhook. OAuth Scope: webhooks.When you know what you want to do but not which command does it, ask the CLI directly:
tailscale-pp-cli which "approve an exit node"which resolves a natural-language capability query to the best matching command from this CLI's curated feature index. Exit code 0 means at least one match; exit code 2 means no confident match — fall back to --help or use a narrower query. --json (and other machine formats) keep that exit-2 contract and write {"matches":[]} on stdout so agents can inspect the envelope without treating a miss as success.
tailscale-pp-cli routes approve home-mac --exit-node --dry-runPrints the before and after enabled routes; rerun with --yes to apply.
tailscale-pp-cli policy add-entry nodeAttrs --entry '{"target":["autogroup:member"],"attr":["drive:access"]}' --dry-runShows the diff and validation result; rerun with --yes to write with the ETag check.
tailscale-pp-cli devices expiry --within 30 --agent --select items.machine,items.days_left,items.flaggedNarrows the report to the three fields an agent needs.
tailscale-pp-cli access check --to nas:445Lists the policy rules that grant access to that device and port.
tailscale-pp-cli policy restore latestShows the diff and validation for restoring the newest local backup; add --yes to restore it, or use --list to pick an older one.
Create an API access token on the admin console Keys page (https://login.tailscale.com/admin/settings/keys) and export TAILSCALE_API_KEY, or set TAILSCALE_OAUTH_CLIENT_ID and TAILSCALE_OAUTH_CLIENT_SECRET to use a scoped OAuth client; the CLI exchanges the client for a short-lived token. The tailnet defaults to '-', meaning the token's own tailnet. Set TAILSCALE_TAILNET only to target a different one.
Run tailscale-pp-cli doctor to verify setup.
Add --agent to any command. Expands to: --json --compact --no-input --no-color.
Global format flags share one contract on promoted, novel, sync, and --deliver paths:
--json — one JSON document on stdout (sync progress events go to stderr)
--compact — keep identity/status/timestamp fields; does not change the document vs stream shape
--csv / --plain — tabular rows (collection envelopes unwrap to the row array)
--quiet — one identity value per row, no envelope
Pipeable — JSON on stdout, errors on stderr
Filterable — --select keeps a subset of fields. Dotted paths descend into nested structures; arrays traverse element-wise. Critical for keeping context small on verbose APIs:
tailscale-pp-cli device get n1234567890CNTRL --agent --select addresses,advertisedRoutes,authorizedPreviewable — --dry-run shows the request without sending; the safe-write commands still read live state and print a plan
Offline search — search reads only the local SQLite store filled by sync (Tailscale has no search endpoint); run sync first
Non-interactive — never prompts, every input is a flag
Explicit confirmation — --agent does not imply --yes; pass --yes separately only after the target, arguments, and side effects are clear
Safe writes — routes approve/unapprove, shares revoke, and policy add-entry/restore print a plan from live reads and write only with --yes, in every mode; as MCP tools they are plan-only. The MCP tailscale_execute tool returns the planned request for any write endpoint (policy validate and preview excepted) unless it is called with confirm: true. Under --agent, every other mutating command runs as a dry run unless --yes is passed
self — the device selector self means this machine and needs the local tailscale command; otherwise pass a hostname, MagicDNS name, Tailscale IP, or nodeId
Explicit retries — use --idempotent only when an already-existing create should count as success, and use --ignore-missing only when a missing delete target should count as success
The local store is kept per credential: each API key or OAuth client gets its own database file under the data directory, so two tailnets never share synced data, search results, or learnings.
Commands that read from the local store or the API wrap output in a provenance envelope:
{
"meta": {"source": "live" | "local", "synced_at": "...", "reason": "..."},
"results": <data>
}With --agent, reads are wrapped this way. With --json alone, the hand-written commands (routes overview, devices expiry, shares audit, and the rest) print their object directly, usually an items array plus counts. Parse .results for data and .meta.source to know whether it's live or local. A human-readable N results (live) summary is printed to stderr only when stdout is a terminal AND no machine-format flag (--json, --csv, --compact, --quiet, --plain, --select) is set — piped/agent consumers and explicit-format runs get pure JSON on stdout.
Agents should treat the CLI's path resolver as part of the runtime contract:
Use --home <dir> for one invocation, or set TAILSCALE_HOME=<dir> to relocate all four path kinds under one root.
Use per-kind env vars only when a specific kind must diverge: TAILSCALE_CONFIG_DIR, TAILSCALE_DATA_DIR, TAILSCALE_STATE_DIR, TAILSCALE_CACHE_DIR.
Resolution order is per-kind env var, --home, TAILSCALE_HOME, XDG (XDG_CONFIG_HOME, XDG_DATA_HOME, XDG_STATE_HOME, XDG_CACHE_HOME), then platform defaults.
config contains settings like config.toml and profiles. data contains credentials.toml, data.db, cookies, and auth sidecars. state contains persisted queries, jobs, and teach.log. cache contains regenerable HTTP/cache files.
Stored secrets live in credentials.toml under the data dir. Existing legacy config.toml secrets are read for compatibility and leave config.toml on the first auth write.
Run tailscale-pp-cli doctor --fail-on warn to surface path and credential-location warnings. agent-context exposes a schema v4 paths block for agents that need the resolved dirs.
For MCP, pass relocation through the MCP host config. The MCP binary does not inherit CLI flags:
{
"mcpServers": {
"tailscale": {
"command": "tailscale-pp-mcp",
"env": {
"TAILSCALE_HOME": "/srv/tailscale"
}
}
}
}Fleet precedence: an inherited per-kind env var overrides an explicit --home for that kind. Use TAILSCALE_HOME or per-kind vars as durable fleet levers, and use --home only for a single invocation. Relocation is not reversible by unsetting env vars; move files manually before clearing TAILSCALE_HOME, or doctor will not find credentials left under the former root.
This CLI ships a self-capturing learning loop. The CLI does its own bookkeeping: every invocation is journaled locally, a failed flag followed by a corrected retry auto-derives a flag_alias candidate, and a teach on a query family without a playbook auto-synthesizes a playbook_candidate from the session's journal. Your job is judgment only: recall first, act on surfaced candidates, teach the final answer, playbook amend when you observe a correction. You never record failures by hand.
recall before any discoveryBefore list/search/drill commands on a new user question, pass the question as an argv or MCP tool argument to recall --agent. Do not interpolate user-controlled text into a shell command line.
Quoted recall "<question>" breaks on an apostrophe, which is ordinary English. A quoted heredoc breaks when a body line equals the delimiter, and that delimiter is published in these docs. Write the question with a non-shell file-writing tool, then read it back as data:
# Write the question verbatim with your file-writing tool (no shell involved).
# Command substitution on a file only ever yields data — the shell never
# parses the file's bytes as syntax.
QUERY=$(cat /path/to/question.txt)
tailscale-pp-cli recall "$QUERY" --agentPrefer MCP: pass the question as the tool's query argument. "$QUERY" after a file read is argv-safe; putting the question itself in the command text is not.
The response envelope:
{
"query": "...",
"normalized": "<normalized form>",
"query_entities": ["..."],
"found": true | false,
"match_score": 0.0,
"results": [
{ "resource_id": "...", "resource_type": "...", "venue": "...",
"confidence": 2, "entity_match": "exact|partial|unknown",
"source": "taught|preseed|pattern", "warnings": ["..."] }
],
"mismatches": [ /* only when --debug-mismatches */ ],
"warnings": [ /* top-level */ ],
"candidates": [
{ "id": 12, "class": "flag_alias | playbook_candidate",
"summary": "...", "sightings": 3, "last_seen": "...",
"rationale": "...",
"next_action": ["<trial command>", "tailscale-pp-cli learnings confirm 12"] }
],
"playbook": {
"query_family": "...",
"playbook": {
"steps": [ { "cmd": "<command with {slot} substitution>", "purpose": "..." } ],
"entity_slots": ["$ENTITY"],
"expected_tool_calls": 3
},
"slots_resolved": { "$ENTITY": { "token": "<live token>", "canonical": "<canonical>" } },
"notes": "<workarounds + gotchas for this query family>"
},
"notes": "<duplicate surface for non-playbook callers>"
}Empty-store short-circuit: if the store has no learnings, playbooks, or candidates yet (recall finds nothing and learnings list and learnings candidates are both empty), skip recall for the rest of this session instead of taxing every query; resume recall-first once something has been taught.
Read candidates, playbook, notes, results[0], and warnings in that order:
if Candidates present (warnings include "candidates_present"):
-> candidates are try-then-confirm, never facts. Follow each candidate's
two-step next_action verbatim: run the trial command first, then run
`learnings confirm <id>` only after the trial verified the behavior.
Reject a wrong candidate with `learnings reject <id>`.
-> NEVER re-teach something recall surfaced as a candidate; confirm or
reject that candidate instead of teaching a duplicate.
-> candidates ride alongside playbooks and resource hits, not instead of
them; continue with the branches below after acting on them.
if Playbook present:
-> READ Playbook.notes verbatim FIRST (workarounds + gotchas the CLI surface doesn't expose)
-> replay Playbook.steps in order, substituting Playbook.slots_resolved entries
for the entity slot tokens. If a step's slot is unresolved, fall back to
discovery for that step only.
-> the Playbook's expected_tool_calls is a budget; if you find yourself running
materially more, record the divergence via `tailscale-pp-cli playbook amend`
at end-of-session.
elif Notes present (no Playbook):
-> read Notes verbatim before any discovery step; they carry known gotchas
for this query family even when no structured choreography exists yet.
elif Found AND Results[0].EntityMatch == "exact" AND Results[0].Confidence >= 2:
-> skip discovery; fetch live data for Results[*].ResourceID in parallel
elif Found AND Results[0].EntityMatch == "partial":
-> candidate hint, NOT a hit; read the resource title to validate before trusting
elif (any row in Mismatches[] when --debug-mismatches was passed):
-> treat as cold start; the stored learning is for a different entity
(different canonical resolved from query_entities)
else: // Found == false, no playbook, no notes
-> cold start; run discovery normally; teach the answer afterward (Step 4).
If the family has no playbook yet, that teach auto-synthesizes a
playbook candidate from this session's journal - you do not need to
record one by hand.Playbook and Notes are orthogonal to the per-resource path. A recall response can carry both a Playbook AND a Results[] hit - use both: the Playbook tells you which choreography to run; the resource hits short-circuit specific steps. Default to skipping mismatches; pass --debug-mismatches only when investigating cold-start surprises.
Candidate judgment details: learnings confirm <id> prints the candidate's full payload before materializing it - check that the printed payload matches the behavior you verified. learnings reject <id> tombstones the derivation signature so the same candidate does not resurface. The envelope carries only the few candidates worth acting on now; tailscale-pp-cli learnings candidates lists the full open set.
Graceful degradation: if learnings confirm is an unknown command, you are driving an older binary - ignore the candidates guidance and follow the rest of the protocol.
warningslow_confidence: row exists at confidence<2. Treat as a hint, not a skip-discovery hit.resource_not_in_store: the local store doesn't have the resource the learning points at. The match validator couldn't classify entities — direct-fetch and re-evaluate.cross_alias_match (per-result): the row was taught under a different alias and matched the live query's canonical via entity_lookups (e.g., a "machines" teach satisfying a "devices" recall). Trust the resource_id.similar_shape_different_entity:<canonical> (top-level): a structurally matching row exists but its canonical entity differs from the live query's. Treated as cold start; the warning carries the conflicting canonical as a hint, but the row is NOT promoted into Results.ambiguous_alias (top-level): a single query entity resolved to multiple canonicals (e.g., "shares" resolving to both device invites and user invites). Surface the ambiguity from context before committing to a resource.candidates_present (top-level): the envelope carries a candidates section. Handle it via the candidates branch in Step 2 before anything else.lookup_refresh_available (top-level): an entity in the query has no lookup row yet, but synced data could provide one. Run tailscale-pp-cli sync to refresh entity lookups.no_learnings_for_query_family: the table had no rows above the Jaccard floor. Pure cold start.teach & after finalizing your response - alwaysTeaching is unconditional. After resolving a query the store could not answer, background-teach the final resource mapping - no call-count threshold, no judging whether it was "worth" learning. The teach is the anchor of the loop: it triggers playbook synthesis for a family without a playbook, and same-referent phrasings fold into one family so near-duplicate teaches do not fragment the store. Fire it after assembling your user-facing response but BEFORE emitting it, with a shell & so the call returns immediately. Pass the query the same way as recall — argv/MCP, or file-then-$QUERY. Do not splice the question into the command text:
QUERY=$(cat /path/to/question.txt)
tailscale-pp-cli teach --query "$QUERY" --resource-type <type> --resource <id1> --resource <id2>
# (append shell `&` to background it)Silent on success. Errors only land in teach.log under the resolved state dir. Teach the most specific resource - if the user asked a broad question and you walked through parent records to find the specific answer, teach the leaf id, not the parent. The CLI uses seeded entity_lookups for cross-alias resolution at recall time, so a teach under one alias (e.g., "acls") satisfies future queries under another alias (e.g., "policy file", "access controls") automatically.
PII rule: teach the structural question with identifiers stripped - never include names, emails, phone numbers, account ids, or other personal identifiers in taught queries or notes. The CLI scans teach queries for obvious email/phone shapes and warns, but does not block; strip before teaching rather than relying on the warning.
You do not need to decide whether a session "deserves" a playbook: a teach on a family without one auto-synthesizes a playbook_candidate from the session's journal, and the next session judges it via confirm/reject. Attach explicit playbook flags only when you already hold choreography worth recording verbatim - workarounds the CLI didn't surface (silently-dropped flags, undocumented params, pagination tricks, payload gotchas). Prefer the integrated one-call form - record the resource learning and the playbook in the same teach invocation:
# Common case: record both the resource learning AND the playbook in one call.
QUERY=$(cat /path/to/question.txt)
tailscale-pp-cli teach \
--query "$QUERY" \
--resource-type devices \
--resource <id> \
--playbook-file ~/playbooks/<shape>.json \
--playbook-notes-file ~/playbooks/<shape>-notes.md
# (append shell `&` to background it)
# Alternate: playbook-only (no resource to record alongside).
QUERY=$(cat /path/to/question.txt)
tailscale-pp-cli teach-playbook \
--query "$QUERY" \
--playbook-file ~/playbooks/<shape>.json \
--notes-file ~/playbooks/<shape>-notes.mdPlaybook files are JSON with steps, entity_slots, expected_tool_calls. Notes files are markdown carrying the gotchas verbatim. File-free callers (MCP-only agents) pass the same content inline: --playbook-json and --playbook-notes on the integrated teach form, --playbook-json and --notes on teach-playbook. On the integrated teach form, the playbook flags are optional - omit them entirely for a resource-only teach. On the standalone teach-playbook form, at least one of the playbook and notes flags must be set; both empty is rejected. Playbooks are keyed on the structural query family (entities stripped) so a recipe taught from one entity-shaped query applies to every other query of the same shape, with slots_resolved binding the live query's canonical at recall time.
When you DO find a playbook on a future recall, treat it as ground truth: replay the steps with slots_resolved substitutions, skip the discovery that the choreography already documents, and read notes before any step.
playbook amend & when your debug response identifies a correctionIf your debug-protocol response identifies a concrete correction the notes or playbook should know — a workaround, an undocumented endpoint shape, a stale field name, observed schema drift, an empty-payload fallback — fire playbook amend BEFORE emitting your user-facing response. Same fire-and-forget posture as teach. Pass the query and note as argv/MCP arguments, or write each with a non-shell file tool and read them back (QUERY=$(cat ...), NOTE=$(cat ...)). Do not interpolate either string into the command text:
QUERY=$(cat /path/to/question.txt)
NOTE=$(cat /path/to/note.txt)
tailscale-pp-cli playbook amend \
--query "$QUERY" \
--add-note "$NOTE"
# (append shell `&` to background it)What counts as worth amending: a behavior you OBSERVED this session that future-you would benefit from knowing. Examples worth amending:
{meta, results}, payload nested two levels deeper than the docs claim).What does NOT belong in notes:
The amend command appends to the family's existing notes with a timestamped marker ([amend YYYY-MM-DDTHH:MMZ]: <text>). Multiple amends accumulate; the audit trail is visible. If no playbook exists yet for the family, amend creates a notes-only one (so cold-start corrections still land).
playbook amend notes are designed to potentially flow upstream as shared knowledge in future versions of the Printing Press. Keep them clean of user-identifying content so the upstream-contribution path stays open without retroactive scrubbing:
If a correction is only meaningful with user-specific context, it belongs in a personal note, not in the playbook amend.
tailscale-pp-cli learnings stats reports recall hit rate, teach-to-reuse, playbook resolution rate, and candidate confirm/reject counts from the local learn_events table. Rates are null until they have a denominator; everything stays on this machine. Use it to check whether the loop is earning its keep for this CLI.
--no-learn on a single command short-circuits both recall and the teach write path. Use for deterministic agent flows or tests that must not be affected by accumulated learnings.TAILSCALE_NO_LEARN=true in the environment globally disables the pipeline.When you (or the agent) notice something off about this CLI, record it:
tailscale-pp-cli feedback "the --since flag is inclusive but docs say exclusive"
tailscale-pp-cli feedback --stdin < notes.txt
tailscale-pp-cli feedback list --json --limit 10Entries are stored locally as feedback.jsonl under the resolved data dir. They are never POSTed unless TAILSCALE_FEEDBACK_ENDPOINT is set AND either --send is passed or TAILSCALE_FEEDBACK_AUTO_SEND=true. Default behavior is local-only.
Write what surprised you, not a bug report. Short, specific, one line: that is the part that compounds.
Every command accepts --deliver <sink>. The output goes to the named sink in addition to (or instead of) stdout, so agents can route command results without hand-piping. Three sinks are supported:
| Sink | Effect |
|---|---|
stdout | Default; write to stdout only |
file:<path> | Atomically write output to <path> (tmp + rename). Binary-response commands write decoded payload bytes (not the base64 JSON envelope) and print a small JSON receipt on stdout; --json/--csv do not refuse when this sink is set. |
webhook:<url> | POST the output body to the URL (application/json) |
Unknown schemes are refused with a structured error naming the supported set. Webhook failures return non-zero and log the URL + HTTP status on stderr.
A profile is a saved set of flag values, reused across invocations. Use it when a scheduled or recurring agent reuses the same saved flags while providing different input each run.
tailscale-pp-cli profile save briefing --json
tailscale-pp-cli --profile briefing device get n1234567890CNTRL
tailscale-pp-cli profile list --json
tailscale-pp-cli profile show briefing
tailscale-pp-cli profile delete briefing --yesExplicit flags always win over profile values; profile values win over defaults. agent-context lists all available profiles under available_profiles so introspecting agents discover them at runtime.
| Code | Meaning |
|---|---|
| 0 | Success |
| 1 | General error; also devices expiry --fail-on-flagged when an item is inside the window |
| 2 | Usage error (wrong arguments) |
| 3 | Resource not found |
| 4 | Authentication required |
| 5 | API error (upstream issue) |
| 6 | Partial failure |
| 7 | Rate limited (wait and retry) |
| 10 | Config error |
Parse $ARGUMENTS:
help, or --help → show tailscale-pp-cli --help outputinstall → ends with mcp → MCP installation; otherwise → see Prerequisites above--agent)go install github.com/mvanhorn/printing-press-library/library/cloud/tailscale/cmd/tailscale-pp-mcp@latestclaude mcp add tailscale-pp-mcp -- tailscale-pp-mcpclaude mcp listwhich tailscale-pp-cli
If not found, offer to install (see Prerequisites at the top of this skill).--agent flag:tailscale-pp-cli <command> [subcommand] [args] --agent
# e.g.
tailscale-pp-cli routes overview --pending --agenttailscale-pp-cli <command> --help.© mvanhorn, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in cli-skills/pp-tailscale of mvanhorn/printing-press-library.
Open the folder on GitHubat commit 0fdcc7a
Pp Tailscale next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pp Tailscale this skillmvanhorn/printing-press-library | 2.1k | — | ~11k | Automated safety check: Notes | Apache-2.0 | |
| Orchardcore Admin Edit ViewsOrchardCMS/OrchardCore | 8.2k | — | ~3.7k | Automated safety check: Pass | BSD-3-Clause | |
| Implementing Policy As Code With Open Policy Agentmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Adminyc-software/qm | 15k | — | ~3.1k | Automated safety check: Pass | MIT | |
| Copy Editingcoreyhaines31/marketingskills | 54k | — | ~4.5k | Automated safety check: Pass | MIT | |
| OmniRoute Routing CLIdiegosouzapw/OmniRoute | 74k | 1 repos | ~342 | Automated safety check: Pass | MIT |
OrchardCMS/OrchardCore
Creates and updates OrchardCore admin edit views using the ocat- CSS class conventions.
mukul975/Anthropic-Cybersecurity-Skills
Implements policy-as-code enforcement with Open Policy Agent (OPA) and Gatekeeper for Kubernetes and CI/CD pipelines, covering writing Rego policies, deploying OPA Gatekeeper as a Kubernetes…
yc-software/qm
Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…
coreyhaines31/marketingskills
When the user wants to edit, review, or improve existing marketing copy, or refresh outdated content.
diegosouzapw/OmniRoute
Creates, switches, and inspects OmniRoute model-routing combos, plus a suggestion command with cost and latency constraints.
nexu-io/open-design
Image edits, upscaling, and background removal via the Venice.ai API.
mvanhorn/printing-press-library
Desktop automation through the real Rust agent-desktop CLI, published in Printing Press through a small bridge.
mvanhorn/printing-press-library
Search, browse, and download Google Fonts from the terminal via the gfonts CLI.
mvanhorn/printing-press-library
The free, offline Trigger phrases: search 1688 for, find a factory on 1688 for, wholesale price on 1688 for, who is the cheapest supplier on 1688 for, compare 1688 suppliers for, use 1688, run 1688.
mvanhorn/printing-press-library
Inspect known Activity Japan plan IDs or URLs, compare dated prices and sessions, check language-sitemap coverage, and hand off to canonical booking pages.
mvanhorn/printing-press-library
Every Admin By Request portal action, plus a local SQLite mirror of audit, events, inventory and requests for ad-hoc...
mvanhorn/printing-press-library
macOS screen capture, window recording, GIF conversion, and agent evidence bundles from the terminal.
Tailscale admin from the terminal, with safe route and policy edits an agent can plan before it writes. Pp Tailscale is an agent skill from mvanhorn/printing-press-library. Tailscale admin from the terminal, with safe route and policy edits an agent can plan before it writes.
Pp Tailscale fits situations like: phrases: approve the exit node; check tailscale key expiry; add a tailscale policy entry; who has this machine shared.
Run `npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a claude-code`. Or copy the skill folder (cli-skills/pp-tailscale in mvanhorn/printing-press-library) into .claude/skills/pp-tailscale in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a codex`. Or copy the skill folder (cli-skills/pp-tailscale in mvanhorn/printing-press-library) into .agents/skills/pp-tailscale in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mvanhorn/printing-press-library --skill pp-tailscale -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pp-tailscale, .gemini/skills/pp-tailscale, .github/skills/pp-tailscale and .opencode/skills/pp-tailscale in your project.
Going by SKILL.md and its folder, Pp Tailscale needs the command-line tools its instructions call (go, claude and npx) and credentials named TAILSCALE_API_KEY and TAILSCALE_OAUTH_CLIENT_SECRET. Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Bash.
SKILL.md names 1 domain. As links in the text: login.tailscale.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Pp Tailscale is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 11k tokens (SKILL.md is roughly 45k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pp Tailscale: Orchardcore Admin Edit Views (OrchardCMS/OrchardCore, 8.2k stars), Implementing Policy As Code With Open Policy Agent (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Admin (yc-software/qm, 15k stars) and Copy Editing (coreyhaines31/marketingskills, 54k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mvanhorn (a GitHub user) maintains it in mvanhorn/printing-press-library, which has 2,053 GitHub stars. The repository holds 505 skills in this directory. The repository was last updated on October 7, 2026.
Source: mvanhorn/printing-press-library on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.