Control consequential homelab changes with explicit scope, observed-state evidence, approval, rollback, and non-secret records. Use before changing guests, services, storage, networking, access, backups, monitoring, or secrets.
69
85%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Use this skill as the cross-boundary gate for consequential homelab work. It complements homelab-safe-ops and homelab-change-planner: this skill decides whether a proposed action is ready to enter a change plan at all.
Prevent undocumented state changes from turning experiments into hidden dependencies. Require clear ownership, observed facts, exact approval, recovery evidence, and a record that excludes secrets and unnecessary environment details.
Before a write, establish all of the following:
Request an exact owner approval for any state change. The approval must state the target, parameters, data placement, network/access effect, excluded workloads, rollback boundary, and whether the resource should start or autostart. Do not convert a broad goal into an unbounded change.
Require a separate approval for each of these categories: guest creation or destruction; service deployment; live secret or machine-identity activation; storage allocation or data placement; backup or restore; Tailscale, DNS, firewall, route, or public-access change; and modification of a protected legacy service.
Request: “Add remote access to a new service guest.”
Route: Confirm a supported service, recovery boundary, intended access path, and private-only requirement. Inspect existing tailnet and network posture read-only. Prepare a port-specific, reversible approval packet. Do not enroll a device, create a key, change policy, or expose a service until that exact packet is approved.
proxmox-service-guest-gate for fresh Proxmox guest creation and validation.homelab-change-planner once this gate establishes that a change is ready to plan.homelab-safe-ops during every infrastructure session.homelab-logbook after an approved change.music-library-safety or local-knowledge-integration when a homelab change crosses media or private-knowledge boundaries.0f62e6b
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.