Kubernetes Network Root Cause Analysis
kubeshark/kubeshark
Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
$ npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw aci-fabric-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/aci-fabric-audit .claude/skills/aci-fabric-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "aci-fabric-audit" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/aci-fabric-audit into .claude/skills/aci-fabric-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aci-fabric-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/aci-fabric-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw aci-fabric-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/aci-fabric-audit .agents/skills/aci-fabric-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "aci-fabric-audit" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/aci-fabric-audit into .agents/skills/aci-fabric-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aci-fabric-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw aci-fabric-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/aci-fabric-audit .cursor/skills/aci-fabric-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "aci-fabric-audit" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/aci-fabric-audit into .cursor/skills/aci-fabric-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aci-fabric-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/aci-fabric-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw aci-fabric-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/aci-fabric-audit .gemini/skills/aci-fabric-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "aci-fabric-audit" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/aci-fabric-audit into .gemini/skills/aci-fabric-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aci-fabric-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw aci-fabric-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/aci-fabric-audit .github/skills/aci-fabric-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "aci-fabric-audit" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/aci-fabric-audit into .github/skills/aci-fabric-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aci-fabric-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw aci-fabric-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/aci-fabric-audit .opencode/skills/aci-fabric-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "aci-fabric-audit" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/aci-fabric-audit into .opencode/skills/aci-fabric-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "aci-fabric-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
aci-fabric-auditRuns a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
This skill walks an agent through a fixed-order health audit of a Cisco ACI fabric by calling ACI MCP tools through an `mcp-call` wrapper, with the APIC address and login passed as environment variables. It covers node status, tenant, VRF, bridge domain and EPG policy review, contract analysis, fault triage and endpoint learning checks. It suits scheduled daily or weekly checks, baselines before and after a change, incident response, tenant policy compliance reviews and leaf and spine capacity planning.
The audit runs in strict phases, each building on the last. Phase 1 lists fabric nodes with ID, name, role, serial number, admin and operational state, firmware and model, then checks pods and fabric links. A node that is not available is flagged critical, as is a link that is not up, while mixed firmware within a role, inactive nodes and single-homed spines are warnings. Phase 2 walks the policy tree from tenants down, flagging tenants missing from an approved registry, then examines VRF contexts. The text available here ends partway through phase 2.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f943637. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ACI_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cisco ACI Fabric Health Audit loads about 2.9k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 837 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit f943637, republished under its Apache-2.0 licence (© automateyournetwork). 837 words, ~2,870 tokens.
.claude/skills/aci-fabric-audit/SKILL.md (or your agent's skills folder).All ACI tool calls use mcp-call with environment variables set as a prefix:
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" TOOL_NAME '{"param":"value"}'Always run the audit in this exact order. Each phase builds on the previous one.
Verify all leaf and spine switches are registered, healthy, and running expected firmware.
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" fabric_nodes '{}'Extract and report:
Flags:
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" fabric_pods '{}'Verify all pods are healthy and reachable.
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" fabric_links '{}'Flags:
Systematically walk the ACI policy tree from tenant down to EPG.
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" tenants_get '{}'Record the full tenant list. Flag any unexpected tenants (not in the approved tenant registry).
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" fvCtx_get '{}'Flags:
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" fvBD_get '{}'Flags:
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" fvAp_get '{}'Enumerate application profiles to understand the logical grouping of EPGs.
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" fvAEPg_get '{}'Flags:
Audit contracts for security hygiene -- look for overly permissive rules and unused contracts.
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" contracts_get '{}'Flags:
For each contract returned, inspect the subjects and filters. Look for:
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" faults '{}'Categorize and count by severity:
| Severity | Action |
|---|---|
| critical | Immediate triage required |
| major | Schedule remediation within 24 hours |
| minor | Review in next maintenance window |
| warning | Informational, track trending |
Flags:
APIC_URL=$APIC_URL USERNAME=$ACI_USERNAME PASSWORD=$ACI_PASSWORD python3 $MCP_CALL "python3 -u $ACI_MCP_SCRIPT" health '{}'Thresholds:
Verify that endpoints are being learned correctly across the fabric.
Look for:
Always produce a consolidated summary:
ACI Fabric Audit Report
========================
APIC: $APIC_URL
Timestamp: YYYY-MM-DD HH:MM UTC
Fabric Summary
--------------
Pods: 1 | Nodes: 6 (2 spine, 4 leaf) | All nodes available: YES
Firmware: 6.0(3e) uniform across all nodes
Policy Summary
--------------
Tenants: 5 | VRFs: 8 | BDs: 23 | App Profiles: 12 | EPGs: 47
+--------------------+----------+----------------------------------+
| Check | Status | Details |
+--------------------+----------+----------------------------------+
| Fabric Nodes | HEALTHY | 6/6 nodes available |
| Fabric Links | HEALTHY | All inter-switch links up |
| Tenant Policy | WARNING | 2 EPGs with no contracts |
| VRF Enforcement | HEALTHY | All VRFs enforced |
| Bridge Domains | WARNING | 1 BD with no subnet |
| Contracts | CRITICAL | 1 any-to-any contract found |
| Faults (Critical) | HEALTHY | 0 critical faults |
| Faults (Major) | WARNING | 3 major faults (unacknowledged) |
| Health Score | HEALTHY | 97/100 |
| Endpoint Learning | HEALTHY | No duplicate MACs detected |
+--------------------+----------+----------------------------------+
Overall: WARNING -- 4 items need attention, 1 CRITICAL contract issue
Critical Findings
-----------------
1. [CRITICAL] Contract "default" in tenant "prod" permits all traffic
- Scope: global | Subject filter: implicit-allow
- Recommendation: Replace with explicit per-port filters
2. [WARNING] EPG "web-servers" in tenant "prod" has no provider contracts
- No inbound communication path defined
- Recommendation: Attach appropriate provider contract
3. [WARNING] BD "legacy-bd" has no subnet configured
- L2-only mode, verify this is intentional
...Severity order: CRITICAL > HIGH > WARNING > HEALTHY. Overall status = worst individual status.
After completing the audit, record the session in GAIT:
python3 $MCP_CALL "python3 -u $GAIT_MCP_SCRIPT" gait_record_turn '{"user_text":"Example only: replace with the actual authorized request.","assistant_text":"ACI fabric audit completed on APIC $APIC_URL: Nodes HEALTHY (6/6), Policy WARNING (2 EPGs no contracts), Contracts CRITICAL (1 any-to-any), Faults WARNING (3 major), Health 97/100. Overall: WARNING.","artifacts":[]}'Generate an interactive mind map of the tenant hierarchy:
python3 $MCP_CALL "node $MARKMAP_MCP_SCRIPT" markmap_generate '{"markdown_content":"# ACI Fabric\n## Tenant: prod\n### VRF: prod-vrf\n#### BD: web-bd\n##### EPG: web-servers\n##### EPG: app-servers\n#### BD: db-bd\n##### EPG: db-servers\n## Tenant: shared\n### VRF: shared-l3out\n#### BD: external-bd"}'Generate a visual fabric topology diagram:
python3 $MCP_CALL "npx -y @drawio/mcp" open_drawio_mermaid '{"content":"graph TD\n subgraph \"Pod 1\"\n APIC1[\"APIC-1\"]\n S1[\"Spine-1\"]\n S2[\"Spine-2\"]\n L1[\"Leaf-1\"]\n L2[\"Leaf-2\"]\n L3[\"Leaf-3\"]\n L4[\"Leaf-4\"]\n S1 --- L1\n S1 --- L2\n S1 --- L3\n S1 --- L4\n S2 --- L1\n S2 --- L2\n S2 --- L3\n S2 --- L4\n end"}'The audit produces:
ACI_MCP_SCRIPT, ACI_PASSWORD, ACI_USERNAME, APIC_URL, GAIT_MCP_SCRIPT, MARKMAP_MCP_SCRIPT are set and valid before assuming a data or device problem.Audit examples are illustrative. Replace request, outcomes, identifiers and counts
with observed session evidence; do not record these example results as facts.
Inspect MCP isError, returned ok, and the recorded turn with gait_show when
validating a new client/schema. Follow gait-session-tracking for branch checkout.
© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/aci-fabric-audit of automateyournetwork/netclaw.
Open the folder on GitHubat commit f943637
Cisco ACI Fabric Health Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cisco ACI Fabric Health Audit this skillautomateyournetwork/netclaw | 677 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Root Cause Analysiskubeshark/kubeshark | 12k | — | ~5.3k | Automated safety check: Pass | Apache-2.0 | |
| Syncmetapawurb/hotpath-rs | 1.9k | — | ~1.2k | Automated safety check: Notes | MIT | |
| UModel Root Cause Analysisalibaba/UnifiedModel | 415 | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Greptimedb Perses DashboardGreptimeTeam/dashboard | 111 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Unifienuno/unifi-mcp-server | 284 | — | ~1k | Automated safety check: Pass | Apache-2.0 |
kubeshark/kubeshark
Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.
pawurb/hotpath-rs
Sync changes from the hotpath, hotpath-macros and hotpath-drain crates to their meta counterparts (hotpath-meta, hotpath-macros-meta and hotpath-drain-meta).
alibaba/UnifiedModel
Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.
GreptimeTeam/dashboard
Generate Perses dashboards or single panels for GreptimeDB. An agent skill from GreptimeTeam/dashboard.
enuno/unifi-mcp-server
Manage UniFi network infrastructure via the UniFi MCP Server.
grafana/skills
Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
automateyournetwork/netclaw
Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking.
Works with
Categories
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning. This skill walks an agent through a fixed-order health audit of a Cisco ACI fabric by calling ACI MCP tools through an `mcp-call` wrapper, with the APIC address and login passed as environment variables. It covers node status, tenant, VRF, bridge domain and EPG policy review, contract analysis, fault triage and endpoint learning checks.
Cisco ACI Fabric Health Audit fits situations like: running a daily or weekly Cisco ACI fabric health check; capturing a baseline before an ACI policy change and comparing afterward; triaging faults when an ACI-related alert fires; reviewing tenant, VRF and contract hygiene on an APIC.
Run `npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a claude-code`. Or copy the skill folder (workspace/skills/aci-fabric-audit in automateyournetwork/netclaw) into .claude/skills/aci-fabric-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a codex`. Or copy the skill folder (workspace/skills/aci-fabric-audit in automateyournetwork/netclaw) into .agents/skills/aci-fabric-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill aci-fabric-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aci-fabric-audit, .gemini/skills/aci-fabric-audit, .github/skills/aci-fabric-audit and .opencode/skills/aci-fabric-audit in your project.
Going by SKILL.md and its folder, Cisco ACI Fabric Health Audit needs the command-line tools its instructions call (python3) and credentials named ACI_PASSWORD. Our summary lists: An APIC reachable with its URL, username and password set as environment variables; The ACI MCP server script and the `mcp-call` helper; Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cisco ACI Fabric Health Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cisco ACI Fabric Health Audit: Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars), Syncmeta (pawurb/hotpath-rs, 1.9k stars), UModel Root Cause Analysis (alibaba/UnifiedModel, 415 stars) and Greptimedb Perses Dashboard (GreptimeTeam/dashboard, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 677 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 11, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.