skills/mukul975/anthropic-cybersecurity-skills/deploying-tailscale-for-zero-trust-vpn/Gen Agent Trust Hub
deploying-tailscale-for-zero-trust-vpn
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches the official installation script from Tailscale's domain (
tailscale.com) and provides instructions to download the Headscale binary from its GitHub repository. These are recognized sources for the software being implemented. - [COMMAND_EXECUTION]: The monitoring script in
scripts/process.pyexecutes thetailscaleCLI to retrieve status information in JSON format for health monitoring. - [PRIVILEGE_ESCALATION]: Instructions include the use of
sudofor repository configuration, service initialization, and modifying system networking parameters like IP forwarding, which are standard administrative requirements for VPN deployment. - [INDIRECT_PROMPT_INJECTION]: The audit scripts ingest data from external sources that could potentially contain malicious instructions.
- Ingestion points:
scripts/agent.pyreads data from the Tailscale API, andscripts/process.pyreads output from thetailscaleCLI. - Boundary markers: The scripts rely on structured JSON parsing without explicit boundary delimiters for natural language content.
- Capability inventory: The skill scripts possess capabilities for network requests (
requests.get) and local command execution (subprocess.run). - Sanitization: No specific content sanitization or validation is applied to the data retrieved from the API or CLI beyond standard JSON parsing.
Audit Metadata