tailscale

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves the official Headscale binary from GitHub releases and configures the official Tailscale package repository. These are trusted sources for the deployment of this infrastructure.
  • [COMMAND_EXECUTION]: Executable scripts manage network routing, WireGuard peers, and system services using standard CLI tools like tailscale, headscale, and docker.
  • [PRIVILEGE_ESCALATION]: The skill uses sudo to perform necessary administrative actions, including package installation, service management, and writing configuration files to protected system directories.
  • [DATA_EXFILTRATION]: Scripts for backup, restoration, and migration access sensitive VPN encryption keys and state databases. This access is required for the skill's functionality and is restricted to the user-specified backup locations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the tailnet and policy files. It utilizes structured parsing with jq and Python to prevent malicious configurations or metadata from affecting the agent's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:57 PM
Security Audit — agent-trust-hub — tailscale