Agent skill

Tailscale Helper

by shepherdjerred in shepherdjerred/monorepo

Tailscale VPN and networking - CLI operations, MagicDNS, ACLs, SSH, funnel, serve, and network administration When user mentions Tailscale, tailscale commands, VPN, MagicDNS, tailnet, or Tailscale…

GPL-3.0Auto-check passedDevOps & Cloud

Install Tailscale Helper

skills CLI
$ npx skills add shepherdjerred/monorepo --skill tailscale-helper -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shepherdjerred/monorepo tailscale-helper --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shepherdjerred/monorepo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/dotfiles/dot_agents/skills/tailscale-helper .claude/skills/tailscale-helper && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tailscale-helper
GitHub stars
112
Token cost
~2.7k tokens
SKILL.md length
732 words
Files
5 (incl. references)
Skills in repo
63
Repo updated
First seen
Licence
GPL-3.0

At a glance

Tailscale VPN and networking - CLI operations, MagicDNS, ACLs, SSH, funnel, serve, and network administration When user mentions Tailscale, tailscale commands, VPN, MagicDNS, tailnet, or Tailscale…

  • Mentions Tailscale
  • SKILL.md covers What's New (2025-2026), Overview, Public Product Reference and CLI Quick Reference, plus 5 more sections
  • Calls docker, ssh and jq
  • Tailscale commands

What it does

Tailscale Helper is an agent skill from shepherdjerred/monorepo. Tailscale VPN and networking - CLI operations, MagicDNS, ACLs, SSH, funnel, serve, and network administration When user mentions Tailscale, tailscale commands, VPN, MagicDNS, tailnet, or Tailscale networking

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/acls-security.md`, `references/cli-reference.md` and `references/networking.md`).

It sits in DevOps & Cloud. The repository describes itself as: Monorepo for all of my projects. The licence is GPL-3.0.

When your agent uses it

  • Mentions Tailscale
  • Tailscale commands
  • Tailscale networking

Example prompts

  • “/tailscale-helper”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit da14ae9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • ssh
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tailscale Helper loads about 2.7k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 56 tokens; SKILL.md has 732 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~19k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shepherdjerred/monorepo at commit da14ae9, republished under its GPL-3.0 licence (© shepherdjerred). 732 words, ~2,697 tokens.

Download SKILL.mdSave it as .claude/skills/tailscale-helper/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
tailscale-helper
description
Tailscale VPN and networking - CLI operations, MagicDNS, ACLs, SSH, funnel, serve, and network administration When user mentions Tailscale, tailscale commands, VPN, MagicDNS, tailnet, or Tailscale networking

Tailscale Helper Agent

What's New (2025-2026)

Tailscale Services (GA, Jan 2026) - Decouple apps from hosting devices with stable TailVIPs and MagicDNS names. Define services via API or admin console with virtual IPs auto-accepted across platforms.

Peer Relays (Beta, Oct 2025) - Use tailnet nodes as high-throughput relay servers when direct connections fail. Throughput approaches direct connections; orders of magnitude faster than managed DERP relays. Two free peer relays on all plans. Requires v1.86+.

Tailnet Lock (GA, Jun 2025) - Verify that only trusted nodes join the tailnet via cryptographic signing. Shifts trust from Tailscale coordination server to your own signing nodes.

Grants (GA, May 2025) - Unified network and application-layer access controls replacing traditional ACLs. Combine network rules with app capabilities in a single policy.

Visual Policy Editor (GA, Oct 2025) - Graphical ACL management in the admin console.

4via6 Subnet Routers (GA, Jan 2025) - Handle overlapping IPv4 subnets by mapping them through IPv6.

Fast User Switching (GA, Jan 2025) - Switch between multiple Tailscale accounts on a single device.

Node Key Sealing (GA, v1.90) - Hardware-backed node key protection on Linux, Windows, and macOS using TPM.

v1.94 Highlights: Workload identity tokens auto-generated, Peer Relay performance improvements, container/K8s Operator updates.

v1.92 Highlights: State file encryption, TPM attestation defaults, K8s workload identity federation, Funnel/Serve PROXY protocol support, network flow logs auto-recording.

Overview

Tailscale is a WireGuard-based mesh VPN that creates a secure overlay network (tailnet) connecting devices across any network topology. Every device gets a stable Tailscale IP from the CGNAT range (100.64.0.0/10) that persists regardless of physical location. Tailscale handles NAT traversal, key management, and peer discovery automatically through a coordination server, while all data flows directly between devices via encrypted WireGuard tunnels.

Public Product Reference

The upstream Tailscale skill is an Alpha reference index, not an authority for this workstation or homelab. Use references/public-product-reference.md for the broader product map (grants, device management, Kubernetes, Taildrop, Taildrive, Serve, Funnel, session recording, and tsnet) and fetch the linked official documentation when syntax or product availability may have changed.

Local rules remain mandatory: probe authentication with the exact read-only operation needed, verify live state before claiming a change worked, treat Serve/Funnel as exposure changes, and preserve the homelab's encryption and access-control requirements. Do not install or invoke an MCP server for this reference.

CLI Quick Reference

bash
# Authentication & Connection
tailscale up                          # Connect and authenticate
tailscale up --auth-key=<key>         # Connect with pre-auth key
tailscale down                        # Disconnect from tailnet
tailscale login                       # Authenticate without connecting
tailscale logout                      # Disconnect and expire session
tailscale switch <account>            # Switch Tailscale account
tailscale switch --list               # List available accounts

# Status & Info
tailscale status                      # Show connection status
tailscale status --json               # JSON output
tailscale ip                          # Show Tailscale IP
tailscale ip --4                      # IPv4 only
tailscale ip --6                      # IPv6 only
tailscale whois <ip>                  # Identify device/user by IP
tailscale version                     # Show version
tailscale netcheck                    # Network diagnostics

# Connectivity
tailscale ping <hostname>             # Ping over Tailscale
tailscale ping --icmp <hostname>      # ICMP ping
tailscale ssh user@host               # SSH via Tailscale

# Configuration
tailscale set --hostname=<name>       # Set device hostname
tailscale set --ssh                   # Enable Tailscale SSH
tailscale set --advertise-exit-node   # Advertise as exit node
tailscale set --exit-node=<ip|name>   # Use exit node
tailscale set --advertise-routes=<cidr> # Advertise subnet routes
tailscale set --accept-routes         # Accept subnet routes
tailscale set --accept-dns            # Accept MagicDNS
tailscale set --shields-up            # Block incoming connections

# File Sharing (Taildrop)
tailscale file cp <file> <host>:      # Send file
tailscale file get <dir>              # Receive files

# Service Exposure
tailscale serve <port>                # Serve to tailnet (HTTPS)
tailscale serve --http=80 <port>      # Serve HTTP
tailscale serve status                # Show serve config
tailscale serve reset                 # Clear serve config
tailscale funnel <port>               # Expose to internet
tailscale funnel status               # Show funnel config

# Drive Sharing
tailscale drive share <name> <path>   # Share directory
tailscale drive unshare <name>        # Stop sharing
tailscale drive list                  # List shares

# Certificates
tailscale cert <domain>               # Generate TLS cert
tailscale cert --cert-file=<f> --key-file=<f> <domain>

# Exit Nodes
tailscale exit-node list              # List available exit nodes
tailscale exit-node suggest           # Suggest optimal node

# Tailnet Lock
tailscale lock init                   # Initialize Tailnet Lock
tailscale lock status                 # View lock status
tailscale lock sign nodekey:<key>     # Sign a node
tailscale lock add tlpub:<key>        # Add signing node
tailscale lock remove tlpub:<key>     # Remove signing node
tailscale lock disable <secret>       # Disable Tailnet Lock

# Diagnostics
tailscale bugreport                   # Generate bug report
tailscale bugreport --diagnose        # With diagnostics
tailscale dns status                  # DNS resolver status
tailscale metrics print               # Show client metrics

# Updates
tailscale update                      # Update client
tailscale update --dry-run            # Check for updates

Key Features

MagicDNS

Automatically registers DNS names for tailnet devices. Access machines by hostname (ssh user@myserver) instead of IP. Full domain: <machine>.<tailnet-name>.ts.net. Enabled by default for new tailnets.

Tailscale SSH

Replace SSH key management with identity-based access. Run tailscale set --ssh on destination, configure SSH ACLs in policy file. Supports check mode requiring periodic re-authentication.

Show full SKILL.md (300 more words)Show less
Funnel

Expose local services to the public internet through encrypted relay. Limited to ports 443, 8443, and 10000. Traffic is end-to-end encrypted through Funnel relay servers.

Serve

Share local services within the tailnet. Supports reverse proxy, file serving, static text, and TCP forwarding. Auto-provisions HTTPS certificates. Use -bg flag for persistence across reboots.

Taildrop

Peer-to-peer encrypted file transfer between tailnet devices. Send with tailscale file cp, receive with tailscale file get.

Exit Nodes

Route all internet traffic through a designated tailnet device. Use for travel security, geo-access, or compliance. Supports Mullvad exit nodes for commercial VPN integration.

Subnet Routers

Extend tailnet to devices without Tailscale installed. Advertise routes with tailscale set --advertise-routes=<cidr>, approve in admin console or via autoApprovers.

Peer Relays

Client-to-client relay fallback when direct connections fail. Higher throughput than DERP relays. Configure with tailscale set --advertise-peer-relay.

Tailscale Services

Define stable virtual services with TailVIPs and MagicDNS names, independent of hosting devices. Supports high availability and granular access controls.

Docker & Containers

bash
# Pull official image
docker pull tailscale/tailscale:latest

# Run with auth key
docker run -d \
  -e TS_AUTHKEY=tskey-auth-... \
  -e TS_HOSTNAME=my-container \
  -e TS_STATE_DIR=/var/lib/tailscale \
  -v ts-state:/var/lib/tailscale \
  tailscale/tailscale:latest

Key environment variables: TS_AUTHKEY, TS_HOSTNAME, TS_STATE_DIR, TS_ROUTES, TS_USERSPACE, TS_EXTRA_ARGS, TS_ACCEPT_DNS, TS_ENABLE_HEALTH_CHECK, TS_ENABLE_METRICS.

Use sidecar pattern with network_mode: service:tailscale for other containers.

ACL Policy Basics

jsonc
{
  // Groups for role-based access
  "groups": {
    "group:engineering": ["user@example.com"],
  },
  // Tag ownership
  "tagOwners": {
    "tag:server": ["group:engineering"],
  },
  // Access rules (deny-by-default)
  "acls": [
    {
      "action": "accept",
      "src": ["group:engineering"],
      "dst": ["tag:server:*"],
    },
  ],
  // SSH access
  "ssh": [
    {
      "action": "accept",
      "src": ["group:engineering"],
      "dst": ["tag:server"],
      "users": ["root"],
    },
  ],
  // Auto-approve routes
  "autoApprovers": {
    "routes": { "10.0.0.0/8": ["tag:server"] },
    "exitNode": ["tag:server"],
  },
}

Use huJSON format (comments and trailing commas allowed). Grants are the recommended modern alternative to ACLs.

Reference Files

  • references/cli-reference.md - Complete CLI command reference with all subcommands, flags, and usage patterns
  • references/networking.md - MagicDNS, subnet routers, exit nodes, DERP, NAT traversal, containers, Kubernetes
  • references/acls-security.md - ACL policy syntax, grants, groups, tags, SSH ACLs, auth keys, API, Tailnet Lock

Common Troubleshooting

IssueCommand
Check connection statustailscale status
Network diagnosticstailscale netcheck
Test peer connectivitytailscale ping <host>
DNS resolution issuestailscale dns status
Generate bug reporttailscale bugreport --diagnose
Check daemon logs (Linux)journalctl -u tailscaled
Check daemon logs (macOS)log show --predicate 'process=="tailscaled"'
Force reconnecttailscale down && tailscale up
Verify routestailscale status --json | jq '.Peer'

© shepherdjerred, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in packages/dotfiles/dot_agents/skills/tailscale-helper of shepherdjerred/monorepo.

  • SKILL.md
  • references/acls-security.md
  • references/cli-reference.md
  • references/networking.md
  • references/public-product-reference.md

Open the folder on GitHubat commit da14ae9

Compare with similar skills

Tailscale Helper next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tailscale Helper compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tailscale Helper this skillshepherdjerred/monorepo112—~2.7kAutomated safety check: PassGPL-3.0
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k9 repos~4.3kAutomated safety check: PassNone
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 9 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    DevOps & CloudAuto-check passed

More from shepherdjerred/monorepo

All 63 skills in this repo
  • Bun Runtime Best Practices

    shepherdjerred/monorepo

    Bun runtime APIs and current operational patterns for files, processes, modules, networking, databases, tests, and deployment.

    112 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Bun Test Patterns

    shepherdjerred/monorepo

    Current Bun test runner guidance for discovery, isolation, parallelism, sharding, changed tests, mocks, timers, snapshots, coverage, DOM Testing Library, and integration teardown.

    112 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Bun Workspaces

    shepherdjerred/monorepo

    Current Bun workspace guidance for isolated and hoisted linkers, catalogs, filters, scripts, dependency classes, lockfiles, lifecycle trust, caches, publishing, TypeScript package exports, and…

    112 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Deep Research

    shepherdjerred/monorepo

    This skill should be used when the user asks to "deep research", "research this topic", "investigate thoroughly", "do a deep dive on", "comprehensive research on", "find everything about", "survey…

    112 GitHub stars~4.7k tokensUpdated today
    Auto-check: notes
  • Figma Use

    shepherdjerred/monorepo

    This skill should be used when the user asks to "create a Figma design", "design in Figma", "make a Figma mockup", "create an app icon", "design UI", "render JSX to Figma", "export from Figma"…

    112 GitHub stars~946 tokensUpdated today
    Auto-check passed
  • Fish Helper

    shepherdjerred/monorepo

    Current Fish shell scripting, functions, abbreviations, completions, variables, events, configuration, plugins, testing, and safety guidance.

    112 GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Tailscale Helper

What does Tailscale Helper do?

Tailscale VPN and networking - CLI operations, MagicDNS, ACLs, SSH, funnel, serve, and network administration When user mentions Tailscale, tailscale commands, VPN, MagicDNS, tailnet, or Tailscale…. Tailscale Helper is an agent skill from shepherdjerred/monorepo.

When should I use Tailscale Helper?

Tailscale Helper fits situations like: mentions Tailscale; tailscale commands; tailscale networking.

How do I install Tailscale Helper in Claude Code?

Run `npx skills add shepherdjerred/monorepo --skill tailscale-helper -a claude-code`. Or copy the skill folder (packages/dotfiles/dot_agents/skills/tailscale-helper in shepherdjerred/monorepo) into .claude/skills/tailscale-helper in your project. Claude Code loads it when a task matches its description.

How do I install Tailscale Helper in Codex?

Run `npx skills add shepherdjerred/monorepo --skill tailscale-helper -a codex`. Or copy the skill folder (packages/dotfiles/dot_agents/skills/tailscale-helper in shepherdjerred/monorepo) into .agents/skills/tailscale-helper in your project. Codex loads it when a task matches its description.

Can I use Tailscale Helper in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shepherdjerred/monorepo --skill tailscale-helper -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tailscale-helper, .gemini/skills/tailscale-helper, .github/skills/tailscale-helper and .opencode/skills/tailscale-helper in your project.

What does Tailscale Helper need to run?

Going by SKILL.md and its folder, Tailscale Helper needs the command-line tools its instructions call (docker, ssh and jq). Our summary lists: Docker.

Does Tailscale Helper access the network?

SKILL.md contains no URLs. Its commands use docker and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Tailscale Helper safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tailscale Helper use?

Tailscale Helper is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tailscale Helper use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Tailscale Helper?

Skills that share tags, products or a category with Tailscale Helper: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Openclaw Live Updater (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tailscale Helper?

shepherdjerred (a GitHub user) maintains it in shepherdjerred/monorepo, which has 112 GitHub stars. The repository holds 63 skills in this directory. The repository was last updated on October 8, 2026.

Source: shepherdjerred/monorepo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.