Agent skill

Remote Mac

by steipete in steipete/agent-scripts

Remote Macs: MacBooks, Mac Studios, hosted claw Macs, Tailscale, SSH, and OpenClaw.

MITAuto-check passedDevOps & Cloud

Install Remote Mac

skills CLI
$ npx skills add steipete/agent-scripts --skill remote-mac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install steipete/agent-scripts remote-mac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/steipete/agent-scripts.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/remote-mac .claude/skills/remote-mac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
remote-mac
GitHub stars
7.3k
Token cost
~3.1k tokens
SKILL.md length
1,610 words
Files
1
Skills in repo
45
Repo updated
First seen
Licence
MIT

At a glance

Remote Macs: MacBooks, Mac Studios, hosted claw Macs, Tailscale, SSH, and OpenClaw.

  • Works in 8 steps: Start with live tailscale status --json;… → If one physical Mac exposes multiple… → For rented Macs, reconcile the live… → …
  • DevOps & Cloud work in your project
  • SKILL.md covers Peter's Topology, Discovery, SSH Rules and OpenClaw Checks, plus 4 more sections
  • Calls ssh; needs GOG_KEYRING_PASSWORD

What it does

Remote Mac is an agent skill from steipete/agent-scripts. Remote Macs: MacBooks, Mac Studios, hosted claw Macs, Tailscale, SSH, and OpenClaw.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The repository describes itself as: Scripts for agents, shared between my repositories. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/remote-mac”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Start with live tailscale status --json; match hostname/DNS name and use the node's current IP. Manager-cached Tailscale IPs may be stale.
  2. If one physical Mac exposes multiple Tailscale peers, do not choose by Active, PATH order, process name, or IP age. Verify ComputerName…
  3. For rented Macs, reconcile the live identity with the provider service/product record in computers.yaml. Provider-active does not mean…
  4. For clawmac, if MacStadium reports Active while the public IP, SSH/VNC, and Tailscale all fail, treat it as a provider network/hardware…
  5. In the corporate environment, default to Mac Studio for remote configuration work. Reach it through its live Tailscale node. MagicDNS may…
  6. In the personal environment, if Tailscale is down or SSH times out, try LAN discovery
  7. Try mDNS names such as HOST.local only when on the same LAN.
  8. If Mac Studio's live Tailscale node is offline from the corporate environment, stop: it must wake or reconnect before SSH or Screen…

What it can do on your machine

Read from SKILL.md and the folder at commit 79150cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GOG_KEYRING_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Remote Mac loads about 3.1k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 1,610 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from steipete/agent-scripts at commit 79150cf, republished under its MIT licence (© steipete). 1,610 words, ~3,094 tokens.

Download SKILL.mdSave it as .claude/skills/remote-mac/SKILL.md (or your agent's skills folder).
name
remote-mac
description
Remote Macs: MacBooks, Mac Studios, hosted claw Macs, Tailscale, SSH, and OpenClaw.

Remote Mac

Use when the user says MacBook, Mac Studio, clawmac, foundationclaw, foundationmac, megaclaw, miniclaw, Molty, Tailscale, or asks to run/check something on one of Peter's Macs.

Peter's Topology

  • Primary workstation for interactive approvals and day-to-day work: Peter's SF Mac Studio, local/Tailscale name steipete-studio-sf. Peter's MacBook Pro (steipete-mbp) is the portable/fallback workstation; do not route prompts there merely because it is online.
  • London workhorse: Mac Studio, Tailscale peters-mac-studio-1, usually best reached as steipete@steipete-macstudio.local when on its LAN.
  • SF primary workstation: steipete-studio-sf. Its current Tailscale target and retired-node state live in private manager computers.yaml; do not choose a peer merely because it appears online.
  • clawstudio is the separate SF data server and personal OpenClaw Gateway host, formerly mac-studio-sf2. Its exact current peer IDs, addresses, hardware identity, and reconciliation state live only in private manager inventory and docs/tailnet-portal.md. If multiple peers appear, pin each backend command, verify the physical host locally, preserve a rollback path, and follow the private reconciliation gate. Do not publish or copy the private topology into public runbooks.
  • SF Mini: local/Tailscale name steipete-mini-sf. Its current kernel and retired GUI targets live in private manager inventory. The Mini uses classic key-only OpenSSH over the tailnet TCP 22 grant because GUI Tailscale builds cannot host Tailscale SSH. Its own key is installed on both SF Studios, MegaClaw, and MiniClaw; see private manager docs/fleet-setup.md for live proof and offline/provider-blocked directions. Do not confuse it with FoundationClaw.
  • Personal cloud OpenClaw: clawmac (Peter may typo/say crabmac), MacStadium service 100121942, Tailscale/SSH steipete@clawmac, gateway via LaunchAgent ai.openclaw.gateway, loopback 127.0.0.1:18789, Telegram connected. The current 2026-08-01 provider network outage is tracked by Atlanta remote hands on tickets #11481/#11484; one hard reboot restored SSH only briefly, so do not repeat power cycles.
  • Network split:
    • corporate: Peter's work-managed environment. Treat Mac Studio as the main remote Mac to configure and inspect there.
    • personal: Peter's personal LAN / personal cloud environment, including clawmac.
  • Network boundary: clawmac and the personal LAN are unreachable from Peter's corporate Mac. Never use clawmac as a relay or LAN vantage from there.
  • Molty's former Mac Studio gateway is retired and must remain disabled; real Molty runs separately on Hetzner. Do not use the old Mac Studio runtime as a healthy-state expectation.
  • megaclaw: Virtualized.gg product 22 (Mac Studio M4 Max, Phoenix), the active alternate Mac worker. Tailscale/SSH steipete@megaclaw. No OpenClaw gateway by design; the personal Gateway runs on clawstudio. Do not configure or start one on megaclaw.
  • miniclaw: Virtualized.gg product 24 (Mac mini M4 Pro, Phoenix), public SSH steipete@131.143.4.3. Live 2026-08-01 state regressed: the privileged Homebrew daemon owns stale duplicate miniclaw-1 and cannot reach coordination, while canonical miniclaw is unusable. Use public SSH until the stored personal admin credential is explicitly authorized for a privileged repair; do not claim the canonical tailnet path is healthy from provider SSH alone.
  • foundationclaw: MacStadium service 100124960, M2.L in Atlanta, public address recorded in computers.yaml. Provider SSH verified a Mac14,12 M2 Pro Mac mini, hardware UUID, and the administrator admin account; its canonical local hostname is foundationclaw. Signed Tailscale and Jump Desktop Connect v10 are installed, but the previously working provider credential stopped authenticating and a data-preserving reset is pending on ticket #11386 before Tailscale enrollment and first-run GUI permissions can continue. Do not merge it with the separate SF Mini.

Non-Mac fleet nodes (full detail in computers.yaml):

  • gorillaclaw: personal Ubuntu Linux node at GorillaServers (Los Angeles), Tailscale 100.93.99.79; SSH user steipete.
  • steipetesurface: Peter's personal Windows Surface, Tailscale 100.118.219.64, SSH user steip. Corporate Windows laptop CPC-steip-11ENO is separate and work-managed.

Not Peter's Macs (do not configure/brand as his):

  • crabhammer: Scaleway M4-XL given to vince; on Peter's tailnet + billing but provisioned for vince (no SSH access). Listed under handed_off: in computers.yaml.

Manager repo source of truth (canonical inventory of all nodes, Mac and non-Mac):

  • /Users/steipete/Projects/manager/computers.yaml
  • /Users/steipete/Projects/manager/agents.yaml

Discovery

  1. Start with live tailscale status --json; match hostname/DNS name and use the node's current IP. Manager-cached Tailscale IPs may be stale.
  2. If one physical Mac exposes multiple Tailscale peers, do not choose by Active, PATH order, process name, or IP age. Verify ComputerName, LocalHostName, hardware UUID, stable node ID, and backend-pinned status. On clawstudio, macsys is /Applications/Tailscale.app/Contents/MacOS/Tailscale; Homebrew kernel requires /opt/homebrew/bin/tailscale --socket=/var/run/tailscaled.socket. Preserve a proven fallback or timed automatic reconnect before stopping either backend.
  3. For rented Macs, reconcile the live identity with the provider service/product record in computers.yaml. Provider-active does not mean fleet-configured, and a public IP alone is not enough to merge identities.
  4. For clawmac, if MacStadium reports Active while the public IP, SSH/VNC, and Tailscale all fail, treat it as a provider network/hardware incident. Check the current incident note in computers.yaml, update the existing ticket, and request console, NIC-link, and switch-port inspection. Do not repeat hard reboots or authorize reimage, erase, reinstall, storage replacement, credential resets, or other data-affecting work without Peter's approval.
  5. In the corporate environment, default to Mac Studio for remote configuration work. Reach it through its live Tailscale node. MagicDNS may be disabled; use the current TailscaleIPs[0] directly. Do not try clawmac, mDNS, or personal-LAN discovery from there.
  6. In the personal environment, if Tailscale is down or SSH times out, try LAN discovery:
bash
dns-sd -B _ssh._tcp local
arp -a
  1. Try mDNS names such as HOST.local only when on the same LAN.
  2. If Mac Studio's live Tailscale node is offline from the corporate environment, stop: it must wake or reconnect before SSH or Screen Sharing diagnosis can continue.

SSH Rules

Use non-interactive SSH by default:

bash
ssh -o RequestTTY=no -o RemoteCommand=none HOST 'COMMAND'

The local SSH alias mac-studio auto-attaches tmux. For one-shot commands, either use steipete@steipete-macstudio.local or override both options above.

For long-running or interactive remote work, use tmux on the remote host and keep the session name obvious.

Show full SKILL.md (678 more words)Show less

OpenClaw Checks

Use login shells on remote Macs so Homebrew and pnpm are on PATH:

bash
ssh -o RequestTTY=no -o RemoteCommand=none steipete@steipete-macstudio.local \
  'zsh -lc "openclaw gateway status --json; openclaw channels status --json"'

clawstudio healthy shape:

  • Use the immutable manager-owned runtime, not a global openclaw binary: ~/.local/share/openclaw-clawstudio/run-current gateway status --deep --require-rpc --json.
  • lsof -nP -iTCP:18789 -sTCP:LISTEN shows the immutable release listener on *:18789.
  • The tailnet portal and Gateway are separate health layers. Prove deep Gateway RPC and tailnet HTTPS independently; one can remain healthy while the other is unavailable.
  • Never start gateway:watch, restart the Gateway, or alter its release while repairing Tailscale.

The London Studio's former Molty gateway remains retired and disabled; real Molty runs separately on Hetzner.

clawmac healthy shape:

  • launchctl list includes ai.openclaw.gateway.
  • lsof -nP -iTCP:18789 -sTCP:LISTEN shows loopback listeners.
  • openclaw channels status --json shows Telegram connected.

Codex Automations

  • Codex cron automations are host-local scheduler state, not generic cloud jobs.
  • In the corporate environment, configure or mirror those automations on Mac Studio unless Peter says otherwise.
  • Treat ~/.codex/automations/<automation-id>/automation.toml on the target host as the source of truth for the scheduled job definition on that machine.
  • If the goal is to move a cron automation from Peter's current corporate machine to Mac Studio, do the machine work on Mac Studio:
    • ensure the intended repo checkout exists there
    • sync the required repo-local policy files
    • create or update the matching ~/.codex/automations/... entry on Mac Studio
    • disable or pause the old corporate-host copy if Peter wants only one runner
  • Do not assume Codex app thread handoff moves cron scheduler ownership; thread movement and cron ownership are separate.

clawmac GUI Access

  • If computers.yaml records a provider network outage and public SSH/VNC plus Tailscale are all unreachable, GUI access is unavailable too. Continue through the existing MacStadium remote-hands ticket; do not power-cycle the host again.
  • Prefer direct clawmac automation over Tailscale/SSH first: open -a "Google Chrome", AppleScript, Chrome DOM JavaScript, and remote Peekaboo clicks.
  • For gog OAuth on clawmac, keep the browser on clawmac. Start gog auth add in remote tmux, open the printed URL on clawmac Chrome, click consent with AppleScript/DOM automation, then verify with zsh -lc 'gog auth list --check --json --no-input'.
  • If GOG_KEYRING_PASSWORD is exported by the remote shell environment, use the matching login shell for checks and tmux prompt feeding, and never print the value.
  • If SSH/cron hits GUI-only prompts that direct automation cannot handle, use local Peekaboo through Jump Desktop's clawmac window as fallback.
  • Find it with peekaboo list windows --app "Jump Desktop" --json; capture by --window-title clawmac or the reported --window-id.
  • Clicks use local global coordinates through the Jump Desktop window; verify with a raw window screenshot before clicking.
  • Chrome cookie/keychain issues: security may prompt for Chrome Safe Storage; Peter must enter the login keychain password, then click Always Allow.
  • After approval, verify over SSH with /Users/steipete/Projects/bird/bird check and /Users/steipete/.openclaw/bin/bird-gui check.

Live Testing Policy (OpenClaw)

  • Default for live tests on any of Peter's Macs: session-owned dev gateway — isolated OPENCLAW_STATE_DIR scratch dir + free port. Never bind 18789 while a real gateway runs; never launchctl kickstart/bootout/bootstrap or openclaw gateway stop/restart a service this session did not start.
  • clawmac = PRODUCTION. Any restart/stop, config/state write under ~/.openclaw, or live test against its gateway needs explicit per-task approval from Peter in chat. One approval = one task, never standing.
  • Any shared Mac Studio gateway or dev-watch session is semi-production: same approval rule; never stop a tmux session this task did not start.
  • Tunnel footgun (megaclaw AND Peter's MacBook Pro): 127.0.0.1:18789 on those hosts is an SSH tunnel into clawmac — "localhost" tests there hit production. Same approval rule applies. Neither host runs a local gateway service.
  • DB/state for testing or migration rehearsal: production copies need explicit per-task approval naming the destination and handling. Work only on the approved copy; writing back or migrating production in place needs separate approval.
  • Heavier cross-machine/OS live E2E routes through $crabbox, not Peter's personal gateways.

Safety

  • Do not assume host identity from a stale IP; verify hostname/user when possible.
  • Do not print secrets from remote files or shells.
  • If a host is unavailable after Tailscale + LAN fallback, say what was tried.
  • For OpenClaw Gateway on Peter's machines, follow repo docs/AGENTS; do not install/start/stop services unless asked.

© steipete, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/remote-mac of steipete/agent-scripts.

Open the folder on GitHubat commit 79150cf

Compare with similar skills

Remote Mac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Remote Mac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Remote Mac this skillsteipete/agent-scripts7.3k—~3.1kAutomated safety check: PassMIT
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k9 repos~4.3kAutomated safety check: PassNone
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 9 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    DevOps & CloudAuto-check passed

More from steipete/agent-scripts

All 45 skills in this repo
  • Mac Fleet Maintenance

    steipete/agent-scripts

    Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

    7.3k GitHub stars~4.8k tokensUpdated 3 days ago
    Auto-check passed
  • Agent Transcript for PRs

    steipete/agent-scripts

    Finds a coding agent's session log, trims and redacts it, and inserts it into a GitHub PR or issue only when the user has asked for a transcript.

    7.3k GitHub starsUsed in 1 repo~698 tokens
    Auto-check passed
  • Parallels macOS VM Lab

    steipete/agent-scripts

    Uses a clean Parallels macOS VM to test GUI automation, TCC permission prompts and screenshot tools like Peekaboo, verifying results from outside the guest.

    7.3k GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed
  • ClawSweeper Status

    steipete/agent-scripts

    Reports ClawSweeper's status with a bundled script: workflow health, active workers, queue health and recently merged, reviewed, commented and closed items.

    7.3k GitHub stars~972 tokensUpdated 3 days ago
    Auto-check passed
  • GitHub Project Triage

    steipete/agent-scripts

    Produces maintainer-facing triage cards for a project's GitHub issues and pull requests, each with its URL, risk, test state, blockers and a next action.

    7.3k GitHub stars~4k tokensUpdated 3 days ago
    Auto-check passed
  • Nano Banana Image Generation

    steipete/agent-scripts

    Generates and edits images with Google's Nano Banana 2 (Gemini 3.1 Flash Image) through a uv script, with a draft-then-final workflow and sizes from 512 to 4K.

    7.3k GitHub stars~1.4k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Remote Mac

What does Remote Mac do?

Remote Macs: MacBooks, Mac Studios, hosted claw Macs, Tailscale, SSH, and OpenClaw. Remote Mac is an agent skill from steipete/agent-scripts. Remote Macs: MacBooks, Mac Studios, hosted claw Macs, Tailscale, SSH, and OpenClaw.

When should I use Remote Mac?

Remote Mac fits situations like: devOps & Cloud work in your project.

How do I install Remote Mac in Claude Code?

Run `npx skills add steipete/agent-scripts --skill remote-mac -a claude-code`. Or copy the skill folder (skills/remote-mac in steipete/agent-scripts) into .claude/skills/remote-mac in your project. Claude Code loads it when a task matches its description.

How do I install Remote Mac in Codex?

Run `npx skills add steipete/agent-scripts --skill remote-mac -a codex`. Or copy the skill folder (skills/remote-mac in steipete/agent-scripts) into .agents/skills/remote-mac in your project. Codex loads it when a task matches its description.

Can I use Remote Mac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add steipete/agent-scripts --skill remote-mac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/remote-mac, .gemini/skills/remote-mac, .github/skills/remote-mac and .opencode/skills/remote-mac in your project.

What does Remote Mac need to run?

Going by SKILL.md and its folder, Remote Mac needs the command-line tools its instructions call (ssh) and credentials named GOG_KEYRING_PASSWORD.

Does Remote Mac access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Remote Mac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Remote Mac use?

Remote Mac is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Remote Mac use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Remote Mac?

Skills that share tags, products or a category with Remote Mac: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Openclaw Live Updater (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Remote Mac?

steipete (a GitHub user) maintains it in steipete/agent-scripts, which has 7,273 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on October 4, 2026.

Source: steipete/agent-scripts on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.