Agent skill

Anta Validation

by automateyournetwork in automateyournetwork/netclaw

Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

Apache-2.0Auto-check passed

Install Anta Validation

skills CLI
$ npx skills add automateyournetwork/netclaw --skill anta-validation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw anta-validation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/anta-validation .claude/skills/anta-validation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
anta-validation
GitHub stars
676
Token cost
~1.2k tokens
SKILL.md length
570 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

  • Is this switch healthy
  • SKILL.md covers Which plane answers — read…, The verdicts — five, and they…, Workflow and Reading a result honestly, plus 2 more sections
  • Needs ANTA_PASSWORD
  • Did my change break anything

What it does

Anta Validation is an agent skill from automateyournetwork/netclaw. Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts. Use for "is this switch healthy", "did my change break anything", "verify BGP/interfaces/hardware are correct", "run a health check on this device". Read-only. A test for a feature the device does not run reports notapplicable — never a failure — and no health percentage is ever emitted. For non-Arista devices, or an assertion ANTA's catalogue doesn't cover, use pyats-dynamic-test to author a custom…

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Is this switch healthy
  • Did my change break anything
  • Verify BGP/interfaces/hardware are correct
  • Run a health check on this device

Example prompts

  • “is this switch healthy”
  • “did my change break anything”
  • “verify BGP/interfaces/hardware are correct”
  • “/anta-validation”

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTA_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Anta Validation loads about 1.2k tokens when it runs. Until then it costs about 140 tokens; SKILL.md has 570 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~140
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 570 words, ~1,244 tokens.

Download SKILL.mdSave it as .claude/skills/anta-validation/SKILL.md (or your agent's skills folder).
name
anta-validation
description
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts. Use for "is this switch healthy", "did my change break anything", "verify BGP/interfaces/hardware are correct", "run a health check on this device". Read-only. A test for a feature the device does not run reports not_applicable — never a failure — and no health percentage is ever emitted. For non-Arista devices, or an assertion ANTA's catalogue doesn't cover, use `pyats-dynamic-test` to author a custom aetest script instead.

ANTA validation — the assertion layer

Every other NetClaw source reads state. This one asserts on it and returns a verdict you can act on.

Server: anta-mcp (NetClaw-authored over ANTA 1.9.0, Apache-2.0, own virtualenv) · 4 tools · 1,272 tokens · 208 tests in the catalogue

Which plane answers — read this before reaching for another server

Three servers touch Arista. They answer different questions, and picking the wrong one gives a confidently wrong answer.

PlaneServerAnswers
Validationthis skilldoes the state match what it should be — pass/fail
Managementarista-cvp-mcpwhat does CloudVision say — inventory, tags, compliance as CVP sees it
Device CLIpyats-*, multivendor-cliwhat is the raw state — show-command output

Use this skill to assert, not to fetch. If the question is "what is the interface MTU", that is the CLI plane. If the question is "is the MTU what it should be", that is this one.

The verdicts — five, and they never merge

VerdictMeansNever counts as
passtested, expectation held—
failtested, expectation did not hold—
not_applicablethe feature is not configured — nothing was testedfail
skippedANTA declined to run itpass
errordevice unreachable or the run brokefail
not_applicable is the one that matters

ANTA natively reports a test for an unconfigured feature as a failure. Measured on a lab switch:

VerifyBGPPeerCount → failure
  "'show bgp summary vrf all' failed on veos1: BGP inactive"

That device has no BGP at all. Reporting it as a failure claims a BGP fault where there is no BGP. The server reclassifies it to not_applicable and keeps the original message.

When you report results: say "BGP: not applicable — this device does not run BGP", never "BGP test failed".

There is no health percentage, and you should not compute one

passed / total is meaningless when not_applicable and skipped sit in the denominator. Forty tests of which thirty are not applicable is not "25% healthy" — it is ten real answers and thirty non-answers. The server refuses to emit a percentage. Report the five counts.

Show full SKILL.md (250 more words)Show less

Workflow

1. Find the tests (contacts no device):

anta_list_tests: category="routing.bgp"        # or keyword="ntp", or both

2. Learn what a test needs (contacts no device):

anta_describe_test: test="VerifyEOSVersion"    # returns its input schema

Do this whenever a test takes inputs. A test run without required inputs is reported as skipped with the requirements listed — it does not guess a default and silently test the wrong thing.

3. Run them:

anta_run_tests:
  host: "172.20.20.4"
  tests: ["VerifyEOSVersion", "VerifyUptime", "VerifyNTP"]
  inputs: {"VerifyEOSVersion": {"versions": ["4.36.1F"]}, "VerifyUptime": {"minimum": 3600}}

Or by category: category: "hardware".

Reading a result honestly

  • An unreachable device returns error with zero results. It is not a broken device — nothing was tested. Say "could not reach the device", never "the device failed its tests".
  • An empty selection returns no_tests_selected. No test matched. That is not a healthy device.
  • A fail names observed and expected. Quote both — "NTP expected synchronised, actual unsynchronised" is actionable; "NTP test failed" is not.

Credentials and scope

ANTA_USERNAME / ANTA_PASSWORD come from the environment and are never tool arguments and never appear in output. ANTA_VERIFY_TLS defaults to true and verifies both certificate trust and hostname. For private PKI set ANTA_CA_BUNDLE to a trusted PEM bundle. An explicit false lab override is disclosed as tls_verified=false; it does not disable SSH host-key checks. See docs/INTEGRATION-TLS-MIGRATION.md for migration.

Boundaries

  • EOS only. ANTA is Arista's framework. This is not multivendor validation, and it must not be described as such.
  • Read-only. ANTA tests; it does not configure. There is no remediation path here — if a test fails, fixing it goes through the normal change process with its CR gating.
  • On demand. This is not continuous monitoring. For "what was it doing over time", use zabbix-metrics-history.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/anta-validation of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Anta Validation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Anta Validation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Anta Validation this skillautomateyournetwork/netclaw676—~1.2kAutomated safety check: PassApache-2.0
Arista Device HealthLeoYeAI/openclaw-master-skills2.2k—~4.5kAutomated safety check: PassApache-2.0
Traction Eoswondelai/skills2.4k—~3.5kAutomated safety check: PassMIT
Eos Compositionneurofoo/agent-skills119—~1.3kAutomated safety check: PassMIT
Eos Styleneurofoo/agent-skills119—~1.3kAutomated safety check: PassMIT
Eos Usageneurofoo/agent-skills119—~1.2kAutomated safety check: PassMIT

Similar skills

  • Arista Device Health

    LeoYeAI/openclaw-master-skills

    Arista EOS device health check and triage procedure. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Traction Eos

    wondelai/skills

    Implement the Entrepreneurial Operating System (EOS) to align vision and execution across a company.

    2.4k GitHub stars~3.5k tokensUpdated 28 days ago
    Marketing & SEOAuto-check passed
  • Eos Composition

    neurofoo/agent-skills

    Strunk & White composition review using the 11 principles from "Elements of Style" Chapter II.

    119 GitHub stars~1.3k tokensUpdated 8 mo ago
    Auto-check passed
  • Eos Style

    neurofoo/agent-skills

    Strunk & White style review using the 21 reminders from "Elements of Style" Chapter V.

    119 GitHub stars~1.3k tokensUpdated 8 mo ago
    Auto-check passed
  • Eos Usage

    neurofoo/agent-skills

    Strunk & White grammar review using the 11 elementary rules from "Elements of Style" Chapter I.

    119 GitHub stars~1.2k tokensUpdated 8 mo ago
    Auto-check passed
  • Change Verification

    LeoYeAI/openclaw-master-skills

    Pre/post change verification with baseline capture, diff analysis, and rollback decision guidance across Cisco IOS-XE/NX-OS, Juniper JunOS, and Arista EOS.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated 4 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated 4 days ago
    Auto-check passed
  • Batfish Config Analysis

    automateyournetwork/netclaw

    Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking.

    676 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed

Questions about Anta Validation

What does Anta Validation do?

Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts. Anta Validation is an agent skill from automateyournetwork/netclaw. Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

When should I use Anta Validation?

Anta Validation fits situations like: is this switch healthy; did my change break anything; verify BGP/interfaces/hardware are correct; run a health check on this device.

How do I install Anta Validation in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill anta-validation -a claude-code`. Or copy the skill folder (workspace/skills/anta-validation in automateyournetwork/netclaw) into .claude/skills/anta-validation in your project. Claude Code loads it when a task matches its description.

How do I install Anta Validation in Codex?

Run `npx skills add automateyournetwork/netclaw --skill anta-validation -a codex`. Or copy the skill folder (workspace/skills/anta-validation in automateyournetwork/netclaw) into .agents/skills/anta-validation in your project. Codex loads it when a task matches its description.

Can I use Anta Validation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill anta-validation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/anta-validation, .gemini/skills/anta-validation, .github/skills/anta-validation and .opencode/skills/anta-validation in your project.

What does Anta Validation need to run?

Going by SKILL.md and its folder, Anta Validation needs credentials named ANTA_PASSWORD.

Does Anta Validation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Anta Validation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Anta Validation use?

Anta Validation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Anta Validation use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Anta Validation?

Skills that share tags, products or a category with Anta Validation: Arista Device Health (LeoYeAI/openclaw-master-skills, 2.2k stars), Traction Eos (wondelai/skills, 2.4k stars), Eos Composition (neurofoo/agent-skills, 119 stars) and Eos Style (neurofoo/agent-skills, 119 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Anta Validation?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.