Twingate ZTNA implementation assistant — architecture, deployment, IaC, troubleshooting. Use this plugin whenever working with Twingate, zero trust network access, or any of: connectors, remote networks, resources, security policies, identity providers, device trust, DNS filtering, exit networks, the Twingate API, Twingate Terraform provider, Twingate Pulumi provider, Twingate Kubernetes operator, Twingate gateway, or SSH PAM.
AWS-specific Twingate deployment specialist. Use this agent when the user is deploying Twingate connectors on AWS — EC2, ECS, EKS, or Fargate. Also use when generating Terraform for an AWS + Twingate deployment, configuring VPC networking for connectors, or troubleshooting connectivity in an AWS environment. For multi-cloud or general architecture questions, use twingate-se instead.
Azure-specific Twingate deployment specialist. Use this agent when the user is deploying Twingate connectors on Azure — ACI, VMs, AKS, or Azure Container Apps. Also use when generating Terraform for an Azure + Twingate deployment, configuring VNet networking for connectors, or troubleshooting connectivity in Azure. For multi-cloud or general architecture questions, use twingate-se instead.
GCP-specific Twingate deployment specialist. Use this agent when the user is deploying Twingate connectors on GCP — GCE, GKE, Cloud Run, or managed instance groups. Also use when generating Terraform for a GCP + Twingate deployment, configuring VPC firewall rules for connectors, or troubleshooting connectivity in GCP. For multi-cloud or general architecture questions, use twingate-se instead.
Twingate Identity Firewall deployment specialist. Use this agent when the user needs to deploy the Twingate Gateway for privileged access, configure Certificate Authorities (X.509 or SSH CA, local or HashiCorp Vault), implement session recording, enable identity-aware kubectl access, automate IDFW setup with Terraform or Ansible, or grant contractors time-bounded SSH access. Also trigger on 'IDFW', 'gateway', 'SSH certificates', 'short-lived certs', or 'privileged access management'.
Twingate network topology and resource design specialist. Use this agent when the user needs to plan their Twingate network structure — how many Remote Networks to create, where to place connectors, how to define resources (FQDN vs CIDR vs IP), how to structure groups and security policies, or how to map their existing network topology to Twingate's model. This agent designs plans; it does not generate deployment code (use aws-deployer, azure-deployer, gcp-deployer, or twingate-terraform skill for that).
Twingate GraphQL API, CLI tools, and automation. Load when the user wants to automate Twingate via the API, write scripts against the GraphQL endpoint, generate or manage API tokens, use the Twingate CLI tools, or build automation pipelines. Also trigger on 'GraphQL', 'X-API-KEY', 'Twingate API', 'api/graphql', 'service account key', 'connector token provisioning', 'rate limiting', or any Twingate admin API mention.
Use when the user asks how Twingate works, wants to design or evaluate a Twingate deployment, needs to understand components (Controller, Client, Connector, Relay), or is planning a ZTNA rollout. Activate for: zero trust, ZTNA, remote access architecture, network design with Twingate, VPN replacement, microsegmentation, split DNS, NAT traversal, P2P vs Relay, Remote Network topology, Resource definition strategy, or deployment sequencing.
Use when the user needs to deploy, configure, upgrade, or troubleshoot Twingate Connectors on any platform. Activate for: Docker connector, Linux connector, systemd connector, ECS connector, Azure Container Instances, GCE, Helm chart connector, connector tokens, connector HA, connector health, connector metrics, connector logging, connector upgrades, DEAD_NO_RELAYS, DEAD_NO_HEARTBEAT, or connector placement questions.
Twingate Internet Security — DNS filtering, exit networks, browser security, and DNS-over-HTTPS. Load when the user mentions DNS filtering, content filtering, internet security, exit networks, egress routing, browser security, NextDNS, DoH, DNS categories, or profile priority. Also trigger on 'Internet Security', 'DNS Security Profile', 'fixed egress IP', or 'SaaS allowlisting' in a Twingate context.
Use when the user asks about IdP integration, SCIM provisioning, security policies, device trust, groups, users, or access control in Twingate. Activate for: SAML, SCIM, Okta, Entra ID, Google Workspace, JumpCloud, OneLogin, Keycloak, device trust, device posture, MFA enforcement, groups, JIT access, ephemeral access, auto-lock, offboarding, deprovisioning, multi-IdP deployments, or security policy configuration.
Uses power tools
Uses Bash, Write, or Edit tools
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
A Claude Code plugin that gives Claude Code deep Twingate ZTNA expertise — architecture design, deployment playbooks, IaC generation, and troubleshooting. Once installed, every Claude Code session can act as a Twingate solutions engineer: it assesses your environment, designs Remote Networks, generates Terraform or Pulumi, and walks you through deployments on AWS, Azure, GCP, or Kubernetes.
In Claude Code, add the marketplace and install the plugin:
/plugin marketplace add Twingate-Solutions/twingate-assistant
/plugin install twingate-assistant@twingate-solutions
That's all. The plugin loads automatically in every future Claude Code session.
To update later, re-run the same /plugin install command — it pulls the latest version.
The plugin adds two things to Claude Code:
twingate-connectors activates).Use the twingate-se agent to help me deploy Twingate to my AWS environment.
The senior SE agent runs a structured environment assessment, produces a network design, and generates IaC.
If Twingate is already in place, create a context file once so future sessions skip re-asking:
Use the twingate-se agent to document my current Twingate deployment as twingate-context.md.
Commit the resulting file. Future sessions will pick it up automatically. Template: docs/twingate-context-template.md.
Use the twingate-troubleshoot skill. My users can't reach a resource that was working yesterday.
Use the aws-deployer agent to generate Terraform for two HA connectors in us-east-1.
Use the azure-deployer agent to deploy connectors as Azure Container Instances with Entra ID auth.
Skills load automatically when Twingate topics are detected, or you can invoke explicitly with /skill <name>.
| Skill | What it covers |
|---|---|
twingate-architect | Core ZTNA architecture, Remote Networks, Resources, design patterns |
twingate-connectors | Connector deployment, HA, upgrades, metrics, logging |
twingate-terraform | Terraform provider, resource definitions, secrets management |
twingate-pulumi | Pulumi provider — TypeScript, Python, Go, C# |
twingate-kubernetes | Helm chart, Kubernetes operator, CRDs, traffic routing |
twingate-idfw | Identity Firewall — SSH PAM, Kubernetes gateway, session recording |
twingate-identity | IdP integration, SCIM, security policies, device trust, JIT |
twingate-api | GraphQL API, CLI tools, automation scripts |
twingate-dns-security | DNS filtering, exit networks, DNS-over-HTTPS |
twingate-troubleshoot | Diagnostics — connector failures, access failures, policy issues |
Agents orchestrate multiple skills for end-to-end workflows. Invoke them by name.
| Agent | When to use |
|---|---|
twingate-se | Starting any Twingate deployment or major change — environment assessment, network design, end-to-end deployment |
aws-deployer | Deploying connectors on AWS (ECS, EC2, IAM, Secrets Manager) |
azure-deployer | Deploying connectors on Azure (ACI, VMs, Key Vault, Entra ID) |
gcp-deployer | Deploying connectors on GCP (Cloud Run, GCE, Secret Manager, Google Workspace) |
network-designer | Planning a new Twingate network before writing IaC — resource strategy, security tiers, output tables |
idfw-deployer | Implementing certificate-based SSH PAM or kubectl proxy access |
Example invocations:
Use the aws-deployer agent to help me set up HA connectors in us-west-2.
Use the network-designer agent to plan our resource structure for three environments.
Each skill has a references/ directory of summarized Twingate documentation. A weekly GitHub Action refreshes those summaries from the live docs site, so the plugin always reflects current Twingate behavior. No action needed on your end — just re-run /plugin install occasionally to pull updates.
Want to fork this plugin and customize it for your own organization, run the pipeline against your own docs, or extend it for a Twingate-adjacent product? See docs/MAINTAINING.md.
Want to contribute back upstream? See CONTRIBUTING.md.
Apache 2.0 — see LICENSE.
npx claudepluginhub twingate-solutions/twingate-assistant --plugin twingate-assistantComprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
Develop, test, build, and deploy Godot 4.x games with Claude Code. Includes GdUnit4 testing, web/desktop exports, CI/CD pipelines, and deployment to Vercel/GitHub Pages/itch.io.
Comprehensive feature development workflow with specialized agents for codebase exploration, architecture design, and quality review
Harness-native ECC operator layer - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, selective install profiles, and production-ready workflows for Claude Code, Codex, OpenCode, Cursor, and related agent harnesses
Access thousands of AI prompts and skills directly in your AI coding assistant. Search prompts, discover skills, save your own, and improve prompts with AI.
Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security