Repository navigation
Add Tailscale plugin for Grok Bot - #533
Draft
minupalaniappan wants to merge 1 commit into
Draft
minupalaniappan wants to merge 1 commit into
minupalaniappan wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a Grok Bot-only
tailscaleplugin (PGT-4708). It is where a user connects Grok Bot to their private Tailscale tailnet so Grok Bot can reach MCP servers on it. Grok Bot joins as one device taggedtag:grokbotand reaches only the hosts the tailnet policy grants to that tag.The plugin has no
mcpServers. It pairs with the built-in Tailscale MCP row the Grok Bot backend serves (everysphere, in progress). That row attaches to the installed plugin the same way Merge connectors attach toquickbooks-online, and Authenticate opens Tailscale sign-in. The backend row is gated by Statsiggrok_bot_tailnet, so keep this PR in draft until the tailnet rollout. Merging it lists the plugin publicly.Files
third_party/tailscale/:.cursor-plugin/plugin.json(1.0.0,cursor: never,grokbot/sand0.49.0, same asfinanceandshopify-store),README.md,CHANGELOG.md,LICENSE,assets/logo.svg(Tailscale's official mark from their press kit, 192×192 on white),skills/tailscale-setup/SKILL.md(covers thetag:grokbottag owner and grant snippet, Authenticate and device approval, Tailnet Lock, adding*.ts.netMCP servers, who can use the tailnet, and Remove).cursor-plugin/marketplace.jsonentry, appended last. Its description matches plugin.json exactly.Validation
npm install --no-save ajv ajv-formats && node scripts/validate-plugins.mjs: All plugins validated successfully.Note
Medium Risk
The change publicly lists an opt-in that exposes private tailnet MCP access; risk is mostly rollout timing (backend gated) and users misconfiguring grants, not runtime code in this repo.
Overview
Adds a new Grok Bot-only
tailscaleintegration to the marketplace so users can opt in to joining Grok Bot to their tailnet (devicetag:grokbot) and reach private MCP servers you allow in policy.The plugin is docs and manifest only—no
mcp.json; it pairs with the backend Tailscale connector and Authenticate flow.cursor: "never"andgrokbot/sand≥ 0.49.0 match other Grok-only plugins likefinanceandshopify-store. Listing updates:marketplace.jsonand root README table.Ships
tailscale-setupskill (policytagOwners/grants snippet, sign-in, device approval, Tailnet Lock, adding*.ts.netMCP URLs, disconnect/troubleshooting), plus README, CHANGELOG, LICENSE, and logo.Reviewed by Cursor Bugbot for commit 74b2ca1. Bugbot is set up for automated code reviews on this repo. Configure here.