Encodes read-first, no-destroy-by-default safety constraints for all homelab automation.
57
72%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./skills/homelab-safe-ops/SKILL.mdThis skill is the standing safety contract for all homelab operations. It must be active in any session that touches infrastructure, VMs, containers, networking, storage, or services.
It is always-on — load it at the start of every homelab session.
OpenCode / Codex: Invoke homelab-safe-ops
Freebuff: /skill homelab-safe-ops
homelab-logbook skill) and Obsidian (obsidian-homelab-logbook skill).Stop and ask the user if:
homelab-change-planner — plan before actinghomelab-logbook — log after actinghomelab-topology-mapper — know the environment firstreverse-proxy-and-tunnel — safe exposure patterns192.168.2.9 (tailnet 100.65.21.28, MagicDNS proxmox.tail0ea6ba.ts.net), PVE 9.2.11. Hardware: 2-core i5-7200U laptop, 8 GB RAM, 5400 RPM HDD = the bottleneck. Load 8–12 = thrashing (SSH handshakes die — looks like a network fault, isn't). One meaningful workload at a time.homelab-core 192.168.2.242 — the only guest; runs Navidrome (production, never restart without asking), slskd, beets 1.6.0.ssh root@192.168.2.9 (host) and ssh root@192.168.2.242 (CT) both work with the idols@MVNK key. SSH on the host required deleting TWO firewall DROP rules (cluster + node-level) — see proxmox-ve-operations skill before touching PVE firewall rules. ssh pve from WSL does not resolve (MagicDNS doesn't work inside WSL) — use IPs.192.168.2.1. Its ISP-side DNS filter NXDOMAINs test/reserved domains (example.com etc.) — if a benign domain mysteriously fails to resolve, this is why; don't debug the app first.ssh + pvesh beats browser automation for anything the PVE web UI could do; xterm.js consoles in the web UI can be typed into but not read (canvas rendering).pvnkmnk/homelab-proxmox-ansible → docs/findings/2026-09-18-homelab-music-library-cleanup.md (that repo is the canonical homelab authority).ff4471e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.