Skip to content

Add Tailscale plugin for Grok Bot - #533

Draft
minupalaniappan wants to merge 1 commit into
mainfrom
minu/tailscale-plugin
Draft

minupalaniappan wants to merge 1 commit into
mainfrom
minu/tailscale-plugin

Conversation

@minupalaniappan

@minupalaniappan minupalaniappan commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Adds a Grok Bot-only tailscale plugin (PGT-4708). It is where a user connects Grok Bot to their private Tailscale tailnet so Grok Bot can reach MCP servers on it. Grok Bot joins as one device tagged tag:grokbot and reaches only the hosts the tailnet policy grants to that tag.

The plugin has no mcpServers. It pairs with the built-in Tailscale MCP row the Grok Bot backend serves (everysphere, in progress). That row attaches to the installed plugin the same way Merge connectors attach to quickbooks-online, and Authenticate opens Tailscale sign-in. The backend row is gated by Statsig grok_bot_tailnet, so keep this PR in draft until the tailnet rollout. Merging it lists the plugin publicly.

Files

  • third_party/tailscale/: .cursor-plugin/plugin.json (1.0.0, cursor: never, grokbot/sand 0.49.0, same as finance and shopify-store), README.md, CHANGELOG.md, LICENSE, assets/logo.svg (Tailscale's official mark from their press kit, 192×192 on white), skills/tailscale-setup/SKILL.md (covers the tag:grokbot tag owner and grant snippet, Authenticate and device approval, Tailnet Lock, adding *.ts.net MCP servers, who can use the tailnet, and Remove)
  • .cursor-plugin/marketplace.json entry, appended last. Its description matches plugin.json exactly.
  • Root README table row

Validation
npm install --no-save ajv ajv-formats && node scripts/validate-plugins.mjs: All plugins validated successfully.


Note

Medium Risk
The change publicly lists an opt-in that exposes private tailnet MCP access; risk is mostly rollout timing (backend gated) and users misconfiguring grants, not runtime code in this repo.

Overview
Adds a new Grok Bot-only tailscale integration to the marketplace so users can opt in to joining Grok Bot to their tailnet (device tag:grokbot) and reach private MCP servers you allow in policy.

The plugin is docs and manifest only—no mcp.json; it pairs with the backend Tailscale connector and Authenticate flow. cursor: "never" and grokbot/sand ≥ 0.49.0 match other Grok-only plugins like finance and shopify-store. Listing updates: marketplace.json and root README table.

Ships tailscale-setup skill (policy tagOwners/grants snippet, sign-in, device approval, Tailnet Lock, adding *.ts.net MCP URLs, disconnect/troubleshooting), plus README, CHANGELOG, LICENSE, and logo.

Reviewed by Cursor Bugbot for commit 74b2ca1. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant