Atlas / MCP servers / hexsleeves / Tailscale

TailscaleCAUTION

mcp/hexsleeves/tailscale-2

server that provides seamless integration with Tailscale's CLI commands and REST API, enabling automated network management and monitoring through a standardized interface

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
19 19r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
140
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for operating Tailscale from any MCP client. Supports local stdio for desktop clients and an authenticated HTTP transport for private tailnet deployments. Defaults to read-only access, localhost binding, and short-lived OAuth credentials where available.

Table of Contents

  • Features
  • Requirements
  • Quick Start
  • Claude Desktop
  • Claude Code (CLI)
  • Cursor
  • Tool Reference
  • Resources and Prompts
  • Configuration
  • HTTP Transport
  • Docker
  • Example Prompts
  • Development
  • Contributing

Features

  • Device management — list, authorize, deauthorize, delete, expire keys, manage routes.
  • Network operations — connect/disc
Read from source at commit 1efe97ac13a9OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add tailscale-mcp-server --env TAILSCALE_API_KEY=${TAILSCALE_API_KEY} -- npx -y @hexsleeves/[email protected]
claude-desktop
{
  "mcpServers": {
    "tailscale-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@hexsleeves/[email protected]"
      ],
      "env": {
        "TAILSCALE_API_KEY": "${TAILSCALE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (19)

19 read · 0 write · 0 destructive.

ToolRiskDescription
connect_networkread
device_actionread
disconnect_networkread
get_network_statusread
get_tailnet_inforead
get_versionread
get_version_inforead
list_devicesread
manage_aclread
manage_device_tagsread
manage_dnsread
manage_exit_nodesread
manage_file_sharingread
manage_keysread
manage_network_lockread
manage_policy_fileread
manage_routesread
manage_webhooksread
ping_peerread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (12)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:24
CMD bun -e "fetch('http://127.0.0.1:3000/health').then(r => process.exit(r.ok ? 0 : 1)).catch(() => process.exit(1))"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/tailscale/render-serve-config.sh:39
"Proxy": "http://127.0.0.1:$port"
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/__test__/utils/validation.test.ts:235
expect(() => validateTarget("~/.ssh/id_rsa")).toThrow();
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__test__/config/env.test.ts:2
import { loadConfig } from "../../config/env.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__test__/mcp/acl-tools.test.ts:11
import { registerAclTools } from "../../mcp/tools/acl.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__test__/mcp/admin-tools.test.ts:11
import { registerAdminTools } from "../../mcp/tools/admin.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__test__/mcp/device-tools.test.ts:12
import { DevicesOutputSchema } from "../../mcp/schemas/tool-results.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__test__/mcp/device-tools.test.ts:13
import { registerDeviceTools } from "../../mcp/tools/devices.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/README.md:36
to `http://127.0.0.1:${MCP_HTTP_PORT}`.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
deploy/README.md:49
tailscale serve --bg --https=443 http://127.0.0.1:3000
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__test__/config/env.test.ts:45
"http://127.0.0.1:8080",
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
src/__test__/README.md:97
curl -fsSL https://tailscale.com/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 1efe97ac13a9full audit observations/trust-audit/mcp-server/hexsleeves__tailscale-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-071efe97ac13a9CAUTIONB89first audit
06

Questions

What is the Tailscale MCP server?

server that provides seamless integration with Tailscale's CLI commands and REST API, enabling automated network management and monitoring through a standardized interface

What tools does Tailscale expose?

19 in total: 19 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Tailscale safe to connect to an agent?

With care. The audit graded it B (89/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Tailscale need?

It reads TAILSCALE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Tailscale run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @hexsleeves/tailscale-mcp-server at 1.3.4.

How current is this page?

The grade is for one exact copy of the source (1efe97ac13a9), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement