Install a skill and let AI get Tailscale right for you
Every line you see in the Prompt Library — "change the policy for me / find the subnet router / show me who is online" — is a concrete use of something a skill wraps up. This handbook picks out the 5-10 skills that matter most for Tailscale and network automation, plus 4-6 popular collections, an install quick reference, safety rules and the SKILL.md spec.
What a skill is and how it relates to Tailscale
A skill is a working handbook written for an AI agent: one folder, one SKILL.md, which the agent opens and follows whenever it hits a matching situation. Ask it to "change my tailnet policy" with no skill installed and it can only read the documents you paste in; install the matching skill and the agent gets its own SOP, its own tool allowlist and its own safety rules.
- Network automation skills: wrap Tailscale/Headscale REST API calls, hard-code the read-before-you-write flow, and build ACL policy validation into the steps.
- DevOps/SRE skills: SSH policy management, network topology diagrams, certificate management — not Tailscale-specific, but used every day.
- Home-lab skills: they package up the operations knowledge for personal setups such as Home Assistant, Proxmox and NAS boxes, which makes them a close cousin for HA + Tailscale users.
How skills work — how they are scanned, how they reach the system prompt, how the AI decides whether to use one — is covered in full in the official Anthropic Skills docs. This handbook focuses on which ones to pick for Tailscale and how to install them.
How to install (the 3-minute version)
Skills work on agent platforms such as Claude Code, Cursor, Cline, Codex and pi-web. This walkthrough uses Claude Code:
-
Choose where to put it
Three common places: user scope (
~/.claude/skills/), project scope (.claude/skills/) and plugin scope (throughclaude plugin install). Put network skills in user scope so they work across projects. -
Clone it or install it
The simplest way:
cd ~/.claude/skills && git clone <repo>. With the plugin system (from Claude Code v2 on), use:claude plugin install <marketplace>/<plugin> # Example: claude plugin install obra/superpowers claude plugin install mattpocock/skills -
Restart the agent or open a new session
Skills are scanned when a session starts. After installing a new one, always open a new session and ask "which skills do you have loaded right now?" to confirm it appears.
-
Test the trigger with one sentence
Phrase a request that matches the skill's
description. For example, once the tailscale skill is in, say "list every subnet router on my tailnet right now" and see whether it reaches for the skill.
tailscale CLI or on an API token in an environment variable (TAILSCALE_API_KEY). Verify the environment is ready right after you install, so you do not find out mid-debug that the skill cannot get credentials.Featured skills (Tailscale and network automation)
Picked from GitHub trending and community recommendations: the skills that fit Tailscale, Home Assistant and home-lab users best. Network automation is a niche where the number of skills is still growing, so this section lists both kinds honestly: the dedicated ones and the general ones that are genuinely useful.
| Skill | What it does for you | How to install |
|---|---|---|
| HexmosTech/lama2 API skill | Turns REST API calls into .l2 syntax files, so that when you write Tailscale/Headscale API interactions the agent manages endpoints and payloads in one consistent file format. The most useful general-purpose API skill. |
git clone https://github.com/HexmosTech/lama2 |
| Official tailscale CLI docs (a homemade SKILL.md) | Collect how you use tailscale up / status / serve / netcheck / ping into a SKILL.md, with trigger keywords such as "tailnet, subnet router, DERP, magic DNS". You can write it yourself in 5 minutes. |
Hand-write SKILL.md → ~/.claude/skills/tailscale-cli/ |
| mcp-builder (one of anthropics/skills) | A skill for the practice of wrapping a REST API as an MCP server — worth having when you want to wrap the Tailscale API as a tailscale-mcp for several agents to share. | git:github.com/anthropics/skills |
| planning-with-files | Complex tailnet migrations (Tailscale → Headscale, single site → multi-site) often get interrupted mid-session; this one persists the plan to files so you can pick it up after an interruption. | git:github.com/OthmanAdi/planning-with-files |
| diagnosing-bugs (one of mattpocock/skills) | A systematic troubleshooting SOP for network connectivity problems: a tailnet node that will not connect, a subnet router that does not show up, traffic going through a DERP relay. Model-invoked. | git:github.com/mattpocock/skills |
| grill-me (one of mattpocock/skills) | Before you design an ACL policy, the agent grills you: who can reach what, what the exceptions are, what happens when something fails. It stops you from writing the wrong policy from the first line. | git:github.com/mattpocock/skills |
| home-assistant-manager | Lets the agent manage HA directly: write automations, read logs, build dashboards. Once Tailscale makes HA manageable remotely, this one starts to pay off. It changes live settings, so verify it in a test environment first. | git clone https://github.com/komal-SkyNET/claude-skill-homeassistant |
| aurora-smart-home | The only multi-skill smart home collection we found: home-assistant, esphome, node-red, ha-dashboard-design, ha-integration-dev. Few stars, but the closest fit. | git clone https://github.com/HugoWisers/aurora-smart-home |
| skill-creator (one of anthropics/skills) | Teaches the agent to turn the Tailscale operations you run at home into a new skill: package the SOP, write the description, add the safety rules. The fastest path to growing your own tailscale-ops skill. | git:github.com/anthropics/skills |
| devops / linux-shell-scripting (one of anthropics/skills) | Everyday automation: writing a systemd unit (registering tailscale serve as a service), a cron backup (backing up the tailnet policy daily) and the like. |
git:github.com/anthropics/skills |
tailscale-cli yourself as a SKILL.md is a 5-minute job; see the spec quick reference below.Catalog of popular collections
To install a whole bundle at once, or to browse and pick your own, start from these entry points. All figures are a 2026-08-20 snapshot.
anthropics/skills
Home of the Agent Skills spec and the official templates. Its 19 skills include devops, mcp-builder, skill-creator, linux-shell-scripting and docx/pdf/pptx/xlsx. This is the first bundle a Tailscale user should install.
git:github.com/anthropics/skills
Warning: the four document skills are source-available, not open source; some skills ship scripts that need a Python or JS environment.
obra/superpowers
14 discipline skills: brainstorming, TDD, systematic-debugging, writing-plans, diagnosing-bugs. Run brainstorming and writing-plans once before you write a Tailscale ACL policy and the policy comes out a whole level better.
claude plugin install obra/superpowers
Warning: the full experience depends on hooks (which may degrade on some agents); the built-in telemetry can be turned off with an environment variable.
mattpocock/skills
grill-me, tdd, diagnosing-bugs, handoff, teach. Mostly engineering-oriented, but grill-me is a particularly close fit for decisions like "should we turn on Funnel?" and "has this policy been thought through?". Pure Markdown, works across models.
claude plugin install mattpocock/skills
The skills sit in two directories, skills/engineering and skills/productivity; an agent that scans recursively picks them up.
HugoWisers/aurora-smart-home
The smart home multi-skill collection we have found so far: home-assistant, esphome, node-red, ha-dashboard-design, ha-integration-dev. A close-cousin bundle for Tailscale + HA users.
git clone https://github.com/HugoWisers/aurora-smart-home
Warning: few stars means few reviewers, and it will direct the agent to change your HA settings — read the SKILL.md yourself before you import it.
ComposioHQ/awesome-claude-skills
An entry point with more than 1000 items. Browse it as a catalog, search the keywords "network / devops / infrastructure / homelab", then click through and install each source repo. It is the fastest way in when you are hunting for Tailscale-related skills.
# Use as a list; do not install the whole bundle
https://github.com/ComposioHQ/awesome-claude-skills
Quality varies and a fair number of items are tied to a SaaS account; review them one by one before installing.
VoltAgent/awesome-agent-skills
It lists only what official teams publish: the full Anthropic set, openai/slides, Google Workspace and cloudflare (including Cloudflare Tunnel/Zero Trust). Cloudflare Tunnel is often compared with Tailscale, and there is an official skill here to model your own on.
# Index only; install each source repo from its link
https://github.com/VoltAgent/awesome-agent-skills
Seen but not listed: K-Dense-AI/scientific-agent-skills (research-oriented, nothing to do with networking), mukul975/Anthropic-Cybersecurity-Skills (security-oriented; some red-team skills help with a tailnet audit, but use them carefully), calesthio/OpenMontage (video production; note the AGPL license).
Compatibility notes
The SKILL.md spec has been adopted by Claude Code, Codex, Gemini CLI, Cursor, Cline, Continue, OpenCode and others; a pure-Markdown skill runs almost anywhere. Where it degrades:
- It depends on Claude Code-specific machinery (hooks, the plugin marketplace, dispatching subagents) — the skill text is still readable, but the automatic triggering may be incomplete.
- It depends on the
tailscaleCLI or an API token — without them it does nothing. Before installing, confirm your agent is allowed to run a shell, or thatTAILSCALE_API_KEYis already set in the environment. scripts/needs a runtime the container does not have — watch for this in an HA add-on or a Docker container. Pure-Markdown skills are the most compatible.- The Tailscale API version — some skills mix the old 2024
aclsformat with the newer 2024+grantsformat; check which one a skill supports before you run it.
tailscale CLI freely, but your agent runs in a sandbox with no shell.Safety rules
- Read it before you install it: open the SKILL.md and read it through first. Pay particular attention to fields such as
allowed-toolsandmetadata.dangerous— anything that willDELETE /api/v2/deviceorPUT /api/v2/tailnet/{tailnet}/aclneeds a close look. - Anything that touches the policy or keys goes into a test tailnet first: Tailscale lets you run more than one tailnet, so make the first run in a test tailnet and switch to the real one once you are confident.
- Give the API token least privilege: a Tailscale OAuth client can be limited by scope (
devices:read,acl,keysand so on) — grant only what the skill needs, never a wide-open admin token. - Pin a version in production: pin it with a git
@tagor@commitso an upstream change does not upgrade you without your noticing. - Put policy changes through a PR: for a real production tailnet policy, use
tailscale aclwith a GitHub Actions PR flow — the agent only produces the diff, it never PUTs directly. A skill earns its place by generating the right diff, not by pressing apply. - Stars mean popularity, not safety: even the popular collections have had cases of quietly exporting environment variables.
SKILL.md spec quick reference · with a homemade tailscale-cli example
The minimum skeleton of a skill:
tailscale-cli/
└── SKILL.md ← the only required file
# SKILL.md contents
---
name: tailscale-cli
description: Triggers when the user mentions tailnet, tailscale status,
subnet router, DERP, magic DNS, tailscale serve, tailscale ssh, tailscale ping
or tailscale netcheck. Uses the local tailscale CLI for queries and settings;
for changes to the tailnet policy or keys, use the tailscale-api skill instead.
allowed-tools: ["Bash"]
---
# tailscale CLI handbook
## Common commands
- `tailscale status --json` — list current tailnet nodes and connection state
- `tailscale ping <host>` — test the P2P connection (direct vs DERP)
- `tailscale up --advertise-routes=192.168.1.0/24 --reset` — advertise a subnet router
- `tailscale serve https://ha-home / http://localhost:8123` — HTTPS reverse proxy for HA
## Safety rules
- `tailscale up --reset` overwrites the existing flags; run `tailscale up --json` first to save the current settings
- Do not run `tailscale logout` without confirming first (it removes the device from the tailnet)
Put it at ~/.claude/skills/tailscale-cli/SKILL.md and it loads the next time you open a session. This kind of homemade skill is the most useful sort for Tailscale users: write in your own tailnet naming convention, the subnet CIDRs you use most and your DERP preference, and the agent stops having to ask.
| Field | Required | Description |
|---|---|---|
name | Yes | Lowercase letters, digits and hyphens; 1–64 characters. |
description | Yes | What it does and when to use it. The AI decides whether to load the skill from this line, so put in the words a user would actually say (tailnet, tailscale up, subnet router). |
allowed-tools | No | The tool allowlist. For example: ["Bash", "WebFetch"]. Network skills almost all need Bash. |
license / compatibility | No | License and compatibility annotations. |
Convention: keep SKILL.md short (< 5000 characters), put attachments in references/, scripts/ and assets/, and read them only when they are needed, so the context does not blow up.
FAQ
Installed it, but nothing happens at all?
Will Tailscale publish an official skill?
tailscale-mcp) and the tailscale CLI supports JSON output; wrapping those two as a skill is close to a 5-minute job. Cloudflare's official skill in the VoltAgent index is a good model for the same approach.What happens if I install too many skills?
What should Headscale users pick?
tailscale CLI is compatible (the client is the same one). For Headscale's own management interface (the headscale CLI and gRPC) there is no ready-made skill yet; the fastest route is to adapt the tailscale-cli example above into a headscale-cli of your own.Can I install just one skill out of a monorepo?
Take this handbook with you
The whole handbook is a self-contained single HTML file, and it opens offline once downloaded. Collection details go stale, so before an important decision go back to the Resource Hub and read the online version.