tailscale-wif
JRichlen/agent-pluginsSet up and troubleshoot SECRETLESS GitHub Actions -> Tailscale authentication using Workload Identity Federation (WIF): each run mints a GitHub OIDC token…
Scores out of 100 · grade B+
2026-08-22Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score4/100
- 1 stars on the source repo.
Documented
15% of the score100/100
- 1,415 words with worked examples.
- Ships 7 bundled files.
Install
npx skills add JRichlen/agent-plugins/tailscale-wifWhat it says it does
Set up and troubleshoot SECRETLESS GitHub Actions -> Tailscale authentication using Workload Identity Federation (WIF): each run mints a GitHub OIDC token that a Tailscale "Trust Credential" exchanges for a short-lived API token or ephemeral auth key, so no Tailscale API key or OAuth client secret is ever stored. Use this WHENEVER a GitHub Actions workflow needs to talk to Tailscale — pushing an ACL/policy file with tailscale/gitops-acl-action, or joining a CI runner to the tailnet with tailscale/github-action — and you want to drop the stored credential, OR when such a workflow is failing with "token exchange failed with status 403: Unauthorized", "requested tags are invalid or not permitted", or "only one of API Key, OAuth secret, or OAuth client ID and audience". Reach for it on phrases like "Tailscale OIDC", "Tailscale WIF", "federated identity Tailscale", "secretless Tailscale in CI", "remove the Tailscale API key / OAuth secret from Actions", or "Tailscale Trust Credential".
Also in JRichlen/agent-plugins
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| dev-diaryJRichlen/agent-plugins | clean | Skill | 1 stars | today | |
| orchestrateJRichlen/agent-plugins | clean | Skill | 1 stars | today | |
| graveyardJRichlen/agent-plugins | clean | Skill | 1 stars | today | |
| plugin-factoryJRichlen/agent-plugins | clean | Skill | 1 stars | today | |
| grill-meJRichlen/agent-plugins | clean | Skill | 1 stars | today | |
| semver-gateJRichlen/agent-plugins | clean | Skill | 1 stars | today |
Other git & workflow skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| finishing-a-development-branchobra/superpowers | clean | Git & workflow | 167,156 installs | 2 days ago | |
| using-git-worktreesobra/superpowers | clean | Git & workflow | 170,252 installs | 2 days ago | |
| git-guardrails-claude-codemattpocock/skills | clean | Git & workflow | 252,653 installs | today | |
| github-issuesgithub/awesome-copilot | clean | Git & workflow | 14,854 installs | today | |
| setup-pre-commitmattpocock/skills | clean | Git & workflow | 245,932 installs | today | |
| commitmicrosoft/vscode | clean | Git & workflow | 189k stars | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=JRichlen%2Fagent-plugins)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
