ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      jmagar

      Safety Report

      Tailscale

      @jmagar

      Manage Tailscale tailnet via CLI and API. Use when the user asks to "check tailscale status", "list tailscale devices", "ping a device", "send file via tailscale", "tailscale funnel", "create auth key", "check who's online", or mentions Tailscale network management.

      3,484Downloads
      33Installs
      4Stars
      1Versions
      API Integration13,230File Management6,712CLI & Shell Tools4,287Networking & DNS2,429

      Security Analysis

      medium confidence
      Suspicious0.04 risk

      The skill appears to implement the advertised Tailscale CLI/API functionality, but its metadata omits required credential and config declarations (it reads a Tailscale API key and a credentials file), which is an internal inconsistency you should resolve before trusting it.

      Feb 11, 20263 files2 concerns
      Purpose & Capabilityok

      Name/description (manage a Tailscale tailnet) align with the provided scripts and SKILL.md: local CLI commands and API operations (devices, keys, DNS, ACLs) are coherent with the stated purpose.

      Instruction Scopenote

      SKILL.md instructs the agent to run local tailscale CLI commands and the included ts-api.sh script for tailnet-wide tasks. That scope is appropriate, but the instructions reference a specific credential file (~/.clawdbot/credentials/tailscale/config.json) and environment variables (TS_API_KEY, TS_TAILNET) which are not declared in the registry metadata — an inconsistency that should be fixed. The skill does not instruct exfiltration to unknown endpoints; API calls target api.tailscale.com.

      Install Mechanismok

      This is an instruction-only skill with one helper script; there is no install spec or remote download. No high-risk install behavior observed.

      Credentialsconcern

      The runtime script expects a Tailscale API key (TS_API_KEY) and optionally TS_TAILNET or a config file, but the registry metadata lists no required env vars or primary credential. Requesting an API key is proportionate to the skill's purpose, however the metadata omission is misleading and could lead to surprise when the agent attempts to read/store credentials.

      Persistence & Privilegeok

      always is false and the skill does not request permanent agent-wide presence or modify other skills. It runs normal network and CLI operations appropriate to its role.

      Guidance

      This skill appears to do what it claims (control Tailscale locally and via the API), but the package metadata does not declare that it needs your Tailscale API key or a credentials file. Before installing or enabling the skill: - Verify the skill source/author (homepage unknown) and inspect the included scripts yourself (ts-api.sh is present and readable). - Only provide a Tailscale API key with the minimum required privileges; prefer creating an ephemeral or limited-scope key in the Tailscale Admin Console. - Store the key in the expected config file (~/.clawdbot/credentials/tailscale/config.json) or via TS_API_KEY, and avoid putting broader credentials in that location. - Ask the publisher to update registry metadata to declare TS_API_KEY (primary credential) and the config path so the requirements are explicit. If you cannot verify the publisher or are uncomfortable providing an API key, do not enable the tailnet-wide features; you can still use local CLI operations if the tailscale binary is present on the machine.

      Latest Release

      v1.0.0

      - Initial release of the Tailscale skill. - Enables management of your Tailscale tailnet via CLI (local) and API (tailnet-wide) commands. - Provides examples for checking status, listing devices, file transfer, device tagging, exposing services, SSH, funneling ports, and managing auth keys. - Supports both everyday user queries (e.g., “who’s online?”, “send file”) and advanced network management tasks. - Offers setup instructions for both CLI use and API authentication.

      More by @jmagar

      Unifi

      2 stars

      Sabnzbd

      0 stars

      Unraid

      0 stars

      Linkding

      0 stars

      Qbittorrent

      0 stars

      Prowlarr

      0 stars

      Published by @jmagar on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]