Agent skill

Batfish Config Analysis

by automateyournetwork in automateyournetwork/netclaw

Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking.

Apache-2.0Auto-check passedDevOps & Cloud

Install Batfish Config Analysis

skills CLI
$ npx skills add automateyournetwork/netclaw --skill batfish-config-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw batfish-config-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/batfish-config-analysis .claude/skills/batfish-config-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
batfish-config-analysis
GitHub stars
676
Token cost
~1.4k tokens
SKILL.md length
452 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking.

  • Works in 6 steps: Upload configs: batfish_upload_snapshot… → Validate: batfish_validate_config to… → Test reachability:… → …
  • Validating configs before deployment
  • SKILL.md covers MCP Server, Available Tools (8), Workflow: Pre-Change Validation and Workflow: Change Impact Analysis, plus 5 more sections
  • Calls python3 and docker

What it does

Batfish Config Analysis is an agent skill from automateyournetwork/netclaw. Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking. Use when validating configs before deployment, testing traffic paths, tracing ACL rules, comparing config versions, or auditing compliance policies. Strictly read-only.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Regulatory compliance and Deployment. It works with Model Context Protocol and Python. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Validating configs before deployment
  • Testing traffic paths
  • Tracing ACL rules
  • Comparing config versions

Example prompts

  • “/batfish-config-analysis”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Upload configs: batfish_upload_snapshot with inline configs dict or path to config directory
  2. Validate: batfish_validate_config to check parse status, vendor detection, warnings/errors
  3. Test reachability: batfish_test_reachability for critical traffic paths
  4. Check compliance: batfish_check_compliance against organizational policies
  5. Report: Structured pass/fail results with specific findings
  6. GAIT: All operations automatically logged

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Batfish Config Analysis loads about 1.4k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 452 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 452 words, ~1,383 tokens.

Download SKILL.mdSave it as .claude/skills/batfish-config-analysis/SKILL.md (or your agent's skills folder).
name
batfish-config-analysis
description
Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking. Use when validating configs before deployment, testing traffic paths, tracing ACL rules, comparing config versions, or auditing compliance policies. Strictly read-only.
license
Apache-2.0
user-invocable
true

Batfish Configuration Analysis

MCP Server

  • Source: Built-in (mcp-servers/batfish-mcp/)
  • Command: python3 -u mcp-servers/batfish-mcp/batfish_mcp_server.py (stdio transport)
  • Requires: Batfish Docker container running, BATFISH_HOST and BATFISH_PORT environment variables
  • Python: 3.10+
  • Dependencies: pybatfish, mcp[cli], python-dotenv

Available Tools (8)

ToolParametersWhat It Does
batfish_upload_snapshotsnapshot_name, configs/config_path, networkUpload device configs to Batfish and create a named snapshot
batfish_validate_configsnapshot_name, networkValidate configs with per-device pass/fail status, vendor detection, warnings
batfish_test_reachabilitysnapshot_name, src_ip, dst_ip, protocol, dst_portTest if traffic can flow between two endpoints with full path trace
batfish_trace_aclsnapshot_name, device, filter_name, src_ip, dst_ip, protocol, dst_portTrace a packet through ACL rules to find matching permit/deny rule
batfish_diff_configsreference_snapshot, candidate_snapshot, include_routes, include_reachabilityCompare two snapshots for route and reachability differences
batfish_check_compliancesnapshot_name, policy_typeCheck configs against compliance policies (6 built-in policy types)
batfish_list_snapshotsnetworkList all available snapshots
batfish_delete_snapshotsnapshot_name, networkDelete a snapshot

Workflow: Pre-Change Validation

When a user wants to validate configurations before deployment:

  1. Upload configs: batfish_upload_snapshot with inline configs dict or path to config directory
  2. Validate: batfish_validate_config to check parse status, vendor detection, warnings/errors
  3. Test reachability: batfish_test_reachability for critical traffic paths
  4. Check compliance: batfish_check_compliance against organizational policies
  5. Report: Structured pass/fail results with specific findings
  6. GAIT: All operations automatically logged
Example: Validate Before Deploy
bash
# Upload proposed configs
batfish_upload_snapshot snapshot_name="pre-change-site-a" config_path="/path/to/configs/"

# Validate parse status
batfish_validate_config snapshot_name="pre-change-site-a"

# Test critical path
batfish_test_reachability snapshot_name="pre-change-site-a" src_ip="10.1.1.1" dst_ip="10.2.2.1" protocol="TCP" dst_port=443

# Check compliance
batfish_check_compliance snapshot_name="pre-change-site-a" policy_type="interface_descriptions"

Workflow: Change Impact Analysis

When comparing before/after configurations:

  1. Upload "before" snapshot: batfish_upload_snapshot with current configs
  2. Upload "after" snapshot: batfish_upload_snapshot with proposed configs
  3. Diff: batfish_diff_configs to find route and reachability differences
  4. Investigate: Use batfish_trace_acl on any newly denied traffic
  5. Report: Structured diff showing added/removed/changed routes and flows
Show full SKILL.md (195 more words)Show less

Workflow: ACL Troubleshooting

When investigating access control issues:

  1. Upload configs: batfish_upload_snapshot with device configs
  2. Trace packet: batfish_trace_acl with device, ACL name, and packet headers
  3. Review: Identify matching rule, line number, permit/deny action
  4. Test alternatives: Modify config, re-upload, trace again

Integration with Other Skills

SkillIntegration
pyats-config-mgmtValidate configs with Batfish before pushing via pyATS
gait-session-trackingAll Batfish operations automatically logged
servicenow-change-workflowReference Batfish validation in change request evidence
fwrule-analyzerComplement ACL trace with cross-vendor overlap analysis
cml-lab-lifecycleValidate CML lab configs with Batfish analysis

Important Rules

  • All operations are strictly read-only -- Batfish analyzes uploaded configs, never modifies network devices
  • GAIT audit mandatory -- All operations logged automatically
  • Snapshots are ephemeral -- Batfish manages snapshot lifecycle; use GAIT for persistent records
  • Multi-vendor -- Supports Cisco IOS/IOS-XE/NX-OS, JunOS, Arista EOS, Palo Alto, F5

Error Handling

  • BATFISH_UNREACHABLE: Verify Docker container is running (docker ps | grep batfish)
  • SNAPSHOT_NOT_FOUND: Use batfish_list_snapshots to see available snapshots
  • INVALID_INPUT: Check configs dict is non-empty or config_path exists
  • DEVICE_NOT_FOUND: Use batfish_validate_config to list devices in snapshot
  • FILTER_NOT_FOUND: Verify ACL/filter name exists on the specified device

Environment Variables

  • BATFISH_HOST -- Batfish hostname (default: localhost)
  • BATFISH_PORT -- Batfish port (default: 9997)
  • BATFISH_NETWORK -- Default network name (default: netclaw)

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/batfish-config-analysis of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Batfish Config Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Batfish Config Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Batfish Config Analysis this skillautomateyournetwork/netclaw676—~1.4kAutomated safety check: PassApache-2.0
AWS Cloudformationaws/agent-toolkit-for-aws2.8k—~3.6kAutomated safety check: PassApache-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Dv Solutionmicrosoft/Dataverse-skills243—~3kAutomated safety check: PassMIT
Validator Expertjeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: PassMIT
Upgrading Mwaa Environmentsaws/agent-toolkit-for-aws2.8k—~7.3kAutomated safety check: PassApache-2.0

Similar skills

  • AWS Cloudformation

    aws/agent-toolkit-for-aws

    Official

    Authors, validates, and troubleshoots AWS CloudFormation templates.

    2.8k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Dv Solution

    microsoft/Dataverse-skills

    Official

    Dataverse solution lifecycle — create, export, import, promote across environments, and validate deployments.

    243 GitHub stars~3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Validator Expert

    jeremylongshore/tons-of-skills-marketplace

    Validate production readiness of Vertex AI Agent Engine deployments across security, monitoring, performance, compliance, and best practices.

    2.8k GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Upgrading Mwaa Environments

    aws/agent-toolkit-for-aws

    Official

    Upgrades an MWAA environment to a newer Airflow version — within 2.x, within 3.x, or across the 2.x-to-3.x boundary.

    2.8k GitHub stars~7.3k tokensUpdated yesterday
    Data & AnalyticsAuto-check passed
  • Fastmcp

    Tommy-yw/RunbookHermes

    Build, test, inspect, install, and deploy MCP servers with FastMCP in Python.

    546 GitHub starsUsed in 3 repos~2.1k tokens
    Agent WorkflowsAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Questions about Batfish Config Analysis

What does Batfish Config Analysis do?

Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking. Batfish Config Analysis is an agent skill from automateyournetwork/netclaw. Batfish network configuration analysis -- pre-deployment validation, reachability testing, ACL/firewall tracing, differential analysis, compliance checking.

When should I use Batfish Config Analysis?

Batfish Config Analysis fits situations like: validating configs before deployment; testing traffic paths; tracing ACL rules; comparing config versions.

How do I install Batfish Config Analysis in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill batfish-config-analysis -a claude-code`. Or copy the skill folder (workspace/skills/batfish-config-analysis in automateyournetwork/netclaw) into .claude/skills/batfish-config-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Batfish Config Analysis in Codex?

Run `npx skills add automateyournetwork/netclaw --skill batfish-config-analysis -a codex`. Or copy the skill folder (workspace/skills/batfish-config-analysis in automateyournetwork/netclaw) into .agents/skills/batfish-config-analysis in your project. Codex loads it when a task matches its description.

Can I use Batfish Config Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill batfish-config-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/batfish-config-analysis, .gemini/skills/batfish-config-analysis, .github/skills/batfish-config-analysis and .opencode/skills/batfish-config-analysis in your project.

What does Batfish Config Analysis need to run?

Going by SKILL.md and its folder, Batfish Config Analysis needs the command-line tools its instructions call (python3 and docker). Our summary lists: Python 3; Docker.

Does Batfish Config Analysis access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Batfish Config Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Batfish Config Analysis use?

Batfish Config Analysis is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Batfish Config Analysis use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Batfish Config Analysis?

Skills that share tags, products or a category with Batfish Config Analysis: AWS Cloudformation (aws/agent-toolkit-for-aws, 2.8k stars), AWS Cdk Development (zxkane/aws-skills, 367 stars), Dv Solution (microsoft/Dataverse-skills, 243 stars) and Validator Expert (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Batfish Config Analysis?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.