Skip to content

Commit 264c6e1

Browse files
committed
Add /tailssh skill — passwordless SSH to another Mac over Tailscale
One-directional device share + ssh alias + ssh-copy-id + verify, with a plain-English hand-off doc for the machine owner. Captured from the 2026-07-10 Kai's-laptop run.
1 parent da14e91 commit 264c6e1

3 files changed

Lines changed: 126 additions & 0 deletions

File tree

‎CHEATSHEET.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -132,6 +132,7 @@ These are custom skills installed by the setup scripts. Type them inside a Claud
132132
| `/recon` | Step 7 | Pre-build prior-art recon. Before you build a tool/app/CLI/MCP/library, sweeps GitHub (via `gh`) + the web for what already exists, ranks the top ~10 free and paid competitors in a comparison table, finds where an edge exists (or honestly calls it a red ocean), and ends with a GREEN/YELLOW/RED verdict. Output is a discussion — building starts only after. Auto-offers itself when you say "build / make / start a new X" or "does X exist?"; run it directly with `/recon <thing>` to skip the offer |
133133
| `/osmani-build` | Step 7 | Phase-gated product-build lifecycle over the [addyosmani/agent-skills](https://github.com/addyosmani/agent-skills) Claude Code plugin (24 skills: define → plan → build → verify → review → ship). Auto-offers itself (alongside `/recon`) when you start building a real tool/app/webapp/CLI/MCP/API — not creative ideation. Greenfield builds enter at Define (requirements interview → idea refine → spec); builds already in motion never get retroactive planning — they enter at Verify → Review → Ship. Run `/osmani-build <phase>` to jump straight to a phase |
134134
| `/safetycheck` | Step 8 | Security audit — scans any project for exposed keys, missing rate limiting, input sanitization gaps, dependency vulnerabilities, and insecure configurations. Also responds to "run a safety check" in plain English. Auto-activates 12 MCP-specific checks on MCP projects |
135+
| `/tailssh` | manual (`tailssh-skill/`) | Permanent passwordless `ssh <name>` into someone else's Mac over Tailscale. One-directional device share (they can't see your machines), `~/.ssh/config` alias, `ssh-copy-id` public-key install, end-to-end verify — plus generates a plain-English instructions doc the machine owner can follow solo. Also responds to "set up ssh to <person>'s laptop" / "onboard <person>'s machine" |
135136

136137
### 2ndBrain-mogging skills *(requires [2ndBrain-mogging](https://github.com/fidgetcoding/2ndBrain-mogging) installed)*
137138

‎tailssh-skill/SKILL.md‎

Lines changed: 93 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,93 @@
1+
---
2+
name: tailssh
3+
description: >
4+
Set up permanent passwordless SSH into someone else's Mac over Tailscale — the exact playbook
5+
from the Kai's-laptop run (2026-07-10). Fires on "/tailssh", "set up ssh to <person>'s
6+
laptop/computer", "onboard <person>'s machine", "add <person> to tailscale", "make ssh <alias>
7+
work for <person>'s machine", or when the user is at (or coordinating with) a friend's/client's
8+
Mac and wants permanent remote access from their own Mac. Covers: Tailscale device share
9+
(one-directional), ~/.ssh/config alias, ssh-copy-id key install, end-to-end verification — and
10+
generates a plain-English instructions doc the machine owner can follow solo.
11+
user_invocable: true
12+
allowed-tools: Bash, Read, Edit, Write
13+
---
14+
15+
# tailssh — passwordless `ssh <name>` into someone's Mac over Tailscale
16+
17+
End state: `ssh <alias>` from the user's Mac lands on the other person's Mac with no password,
18+
over Tailscale, with zero access granted in the reverse direction.
19+
20+
## Security model (lead with this if the user hesitates)
21+
22+
- **The share is one-directional.** Their device gets shared TO the user's tailnet. The user can
23+
reach that one machine; the machine's owner cannot see or reach any of the user's machines.
24+
- **Only the PUBLIC key lands on their Mac** (`~/.ssh/authorized_keys`). It's a lock, not a key —
25+
it lets the user in, it grants nothing back. The private key never leaves the user's machine.
26+
- **Their password auth stays on.** This setup stops the *user* from needing the password; it does
27+
not weaken or change how the owner logs in.
28+
- Direction check: putting THEIR key on the user's machine would be the reverse grant. Never do it.
29+
30+
## Intake — ONE combined ask
31+
32+
1. Alias for `ssh <alias>` (default: their first name, lowercase).
33+
2. Their macOS username (`whoami` on their machine — NOT their display name).
34+
3. Are you sitting at their machine now, or handing them instructions? (hand-off → generate the doc)
35+
36+
Share-invite email defaults to `nate@lorecraft.io` — confirm silently unless it's clearly not Nate.
37+
38+
## Phase 1 — on THEIR machine
39+
40+
If handing off: fill `references/instructions-template.md` placeholders (`<OWNER>`, `<REQUESTER>`,
41+
`<EMAIL>`, `<ALIAS>`) and save to `~/Desktop/ssh-setup-<alias>.md` for AirDrop. If present in
42+
person, walk through live:
43+
44+
1. **Remote Login ON** — System Settings → General → Sharing → Remote Login. Off by default on
45+
most Macs; skipping this is the #1 cause of "Connection refused" later.
46+
2. **Install Tailscale** — https://tailscale.com/download (or Mac App Store).
47+
3. **Sign in with THEIR OWN account** (Google/Apple/email — anything). They do not join the
48+
user's account or tailnet.
49+
4. **Share the device** — login.tailscale.com → Machines → this machine → **⋯ → Share** → enter
50+
the user's email → send invite.
51+
5. **Capture their username** — `whoami` in Terminal on their machine.
52+
53+
## Phase 2 — on the USER'S machine
54+
55+
1. **Accept the share invite** from the email link. The device appears as a shared node.
56+
2. **Get its Tailscale IP** (100.x.y.z) — `tailscale status` or the accept page / admin console.
57+
3. **Add the alias** — Read `~/.ssh/config` first, preserve everything, append:
58+
```
59+
Host <alias>
60+
HostName <100.x.y.z>
61+
User <their-username>
62+
```
63+
4. **Install the key** — interactive password prompt, so it must run in the user's own terminal,
64+
never through the agent's Bash tool. In Claude Code, tell them to run:
65+
```
66+
! ssh-copy-id <alias>
67+
```
68+
They type the owner's password once. No keypair yet? `ssh-keygen -t ed25519` first.
69+
5. **Verify** (agent runs these):
70+
```bash
71+
ssh -G <alias> | grep -E '^(hostname|user) '
72+
ssh -o PasswordAuthentication=no -o BatchMode=yes <alias> true && echo PASS
73+
```
74+
PASS = done. Report both results.
75+
76+
## Troubleshooting
77+
78+
| Symptom | Fix |
79+
|---|---|
80+
| Connection refused | Remote Login off on their Mac (Phase 1 step 1) |
81+
| Timeout / no route | Tailscale not running on one side (`tailscale status`), or invite not accepted |
82+
| Still asks for password | ssh-copy-id didn't land — rerun; on their Mac check `chmod 700 ~/.ssh`, `chmod 600 ~/.ssh/authorized_keys` |
83+
| Permission denied | Wrong `User` — must be `whoami` output on their machine |
84+
85+
Tailscale 100.x IPs are stable for the life of the node; if MagicDNS is on you can use
86+
`<machine>.<tailnet>.ts.net` as `HostName` instead — optional, not required.
87+
88+
## Rules
89+
90+
- Never place the other person's key on the user's machine.
91+
- Never change sshd config / disable password auth on their machine — not ours to harden.
92+
- All password entry happens in the user's own terminal (`!` prefix), never via agent Bash.
93+
- Read `~/.ssh/config` before editing; append, don't rewrite.
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
# Letting <REQUESTER> connect to this Mac (~5 minutes)
2+
3+
Hi <OWNER> — these steps let <REQUESTER> log into this Mac remotely to help with stuff.
4+
Two things worth knowing up front:
5+
6+
- Nothing here shares your password. You keep it; nobody else learns it.
7+
- This is one-way. <REQUESTER> can reach **this Mac only** — this Mac gets no access to
8+
<REQUESTER>'s computers, files, or network.
9+
10+
## 1. Turn on Remote Login
11+
12+
System Settings → General → Sharing → turn **Remote Login** ON.
13+
14+
## 2. Install Tailscale
15+
16+
Download from https://tailscale.com/download (or the Mac App Store), open it, and sign in
17+
with **your own** Google/Apple/email account. Free for personal use.
18+
19+
## 3. Share this machine with <REQUESTER>
20+
21+
1. Go to https://login.tailscale.com and log in with the same account.
22+
2. Click **Machines**, find this Mac in the list.
23+
3. Click the **⋯** menu on its row → **Share** → enter `<EMAIL>` → send.
24+
25+
## 4. Done
26+
27+
<REQUESTER> accepts the invite on their side and finishes the rest remotely. The very first
28+
connection will ask for this Mac's login password once (you can type it yourself) — after
29+
that, never again.
30+
31+
To undo any of this later: Tailscale admin console → Machines → this Mac → ⋯ → remove the
32+
share, and/or turn Remote Login back off.

0 commit comments

Comments
 (0)