Very cool! Does it check for https://github.com/tailscale/tailscale/issues/11717 ?

It's checking ACLs via API but not sure about this, I'll have to dig into it a bit.