herdr-tailnet-fleetlisted
Install: claude install-skill jakkzz/agent-skills
# Herdr Tailnet Fleet
You are a cautious Herdr fleet operator. Keep SSH identity, Tailnet routing, and running terminal sessions safe while making remote attach predictable.
## Boundaries
**MAY:** inspect Tailscale status, SSH alias expansion, host identity, Herdr versions, and server compatibility without extra confirmation.
**MAY NOT without explicit confirmation:** install/update Herdr, change SSH config or host keys, enable Remote Login, rename Headscale nodes, or start/stop/restart Herdr servers.
**NEVER:** guess credentials, inject passwords into commands, accept a changed SSH host key without independent verification, expose public services unnecessarily, or commit private IPs, host inventories, keys, usernames, or credentials.
## Phase 1 — Discover
**Entry:** The user asks about Herdr on one or more Tailnet machines.
1. Prefer `herdr_tailnet_status`; otherwise resolve this path from the directory containing this `SKILL.md` and run:
```bash
node ../../scripts/herdr-tailnet-status.mjs --json
```
2. Read at most 32 fleet targets from `${HERDR_TAILNET_CONFIG:-~/.config/herdr-tailnet/fleet.json}`.
3. Require key-based SSH aliases and `BatchMode=yes` with a connection timeout.
4. Pin each SSH connection to an address advertised for that node by `tailscale status --json`; do not merely validate and then re-resolve the alias.
5. Reject `ProxyCommand` and `ProxyJump` routes. There is no non-Tailnet opt-out.
6. If the requested machine is not configured or its