Agent skill

Bgp Registry Intel

by automateyournetwork in automateyournetwork/netclaw

BGP and registry intelligence — RPKI origin validation (is this announcement authorised?), RDAP registry ownership and abuse contacts, PeeringDB interconnection data, RIPEstat routing status and…

Apache-2.0Auto-check passed

Install Bgp Registry Intel

skills CLI
$ npx skills add automateyournetwork/netclaw --skill bgp-registry-intel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw bgp-registry-intel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/bgp-registry-intel .claude/skills/bgp-registry-intel && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bgp-registry-intel
GitHub stars
676
Token cost
~1.8k tokens
SKILL.md length
901 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

BGP and registry intelligence — RPKI origin validation (is this announcement authorised?), RDAP registry ownership and abuse contacts, PeeringDB interconnection data, RIPEstat routing status and…

  • Works in 6 steps: rpki_validate with the prefix and the… → Read the state carefully against the… → registry_lookup — who holds it, and who… → …
  • Investigating an unfamiliar prefix
  • SKILL.md covers MCP Server, The one rule that matters most, Tools (10, all read-only) and Three more "this is not what…, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Bgp Registry Intel is an agent skill from automateyournetwork/netclaw. BGP and registry intelligence — RPKI origin validation (is this announcement authorised?), RDAP registry ownership and abuse contacts, PeeringDB interconnection data, RIPEstat routing status and prefix visibility, RIPE Atlas anchors. Use when investigating an unfamiliar prefix or ASN, checking whether a BGP announcement is RPKI-valid, finding who owns address space or who to report abuse to, or determining what an AS announces and where it peers.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Investigating an unfamiliar prefix
  • Checking whether a BGP announcement is RPKI-valid
  • Finding who owns address space
  • Who to report abuse to

Example prompts

  • “/bgp-registry-intel”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. rpki_validate with the prefix and the origin AS. Validation is always of the pair.
  2. Read the state carefully against the table above. If not_found, stop treating it as a problem.
  3. registry_lookup — who holds it, and who to contact.
  4. routing_announced_prefixes on the origin AS — is this consistent with what it normally announces?
  5. peering_network — is this a transit provider, content network, or enterprise? It changes what "normal"
  6. Escalate only on invalid, and only after checking that the origin AS is what you think it is and the

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are jsonc).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bgp Registry Intel loads about 1.8k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 901 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 901 words, ~1,839 tokens.

Download SKILL.mdSave it as .claude/skills/bgp-registry-intel/SKILL.md (or your agent's skills folder).
name
bgp-registry-intel
description
BGP and registry intelligence — RPKI origin validation (is this announcement authorised?), RDAP registry ownership and abuse contacts, PeeringDB interconnection data, RIPEstat routing status and prefix visibility, RIPE Atlas anchors. Use when investigating an unfamiliar prefix or ASN, checking whether a BGP announcement is RPKI-valid, finding who owns address space or who to report abuse to, or determining what an AS announces and where it peers.
version
1.0.0
license
Apache-2.0
tags
bgp, rpki, rdap, whois, peeringdb, routing, registry, internet, security, external
user-invocable
true

BGP & Registry Intelligence

MCP Server

  • Server: bgp-intel-mcp (NetClaw-authored, spec 081 / roadmap R9)
  • Command: $BGP_INTEL_MCP_CMD
  • Transport: stdio
  • Credentials: none. Every source is a public unauthenticated API
  • Mode: read-only. There is no write path

The one rule that matters most

RPKI not-found is NOT invalid.

Most of the internet has no ROA. Unsigned address space is the overwhelmingly common case, not an anomaly. If you report not-found as a hijack, a misconfiguration, or a security finding, you will generate false incidents at scale and the operator will stop trusting you.

StateMeansActionable?
validA ROA authorises this origin ASNo — healthy
invalid + reason: asA ROA covers this prefix; a different AS is authorisedYes — possible hijack
invalid + reason: lengthCorrect AS, but the prefix is more specific than the ROA permitsYes — usually a local misconfiguration, different fix
not_foundNo ROA exists. RFC 6811 calls this NotFoundNo — the normal case

The two invalid reasons are different findings. as means someone else is announcing your space; length usually means you announced a /24 under a /22 ROA. Never collapse them.

validation_unavailable is not not_found. If the validator is unreachable you get the former, and the RPKI state is genuinely unknown. Do not infer "unsigned" from "could not ask", and do not fall back to guessing from routing or registry data.

Tools (10, all read-only)

ToolAnswers
rpki_validateIs this prefix legitimately announced by this AS? Nothing else in NetClaw does this
registry_lookupWho is this IP/prefix/ASN allocated to?
registry_abuse_contactWho do I report abuse to?
routing_as_overviewWho holds this ASN; is it announced at all?
routing_announced_prefixesWhat does this AS announce, and how visible is it?
peering_networkNetwork type, traffic profile, peering policy
peering_presenceWhich IXPs and facilities?
atlas_anchorsAtlas anchors in a country (stable measurement targets)
atlas_probe_countCan this AS be measured from inside?
resource_reportEverything about a resource, one call, per-section sourcing

Three more "this is not what you think it is"

  • Registry data is allocation, not routing. RDAP tells you who address space is registered to. It says nothing about who is announcing it. Use routing_announced_prefixes for that. Treating an RDAP holder as a routing fact is the same category error as treating FortiManager intent as device state.
  • PeeringDB is self-reported. No record means nobody filled in the form — not that the network does not peer. Many networks peer extensively and publish nothing.
  • Visibility is RIPE's collectors, not the internet. Low visibility has legitimate causes: scoped announcements, no-export, anycast, a recent change. The tool will never call it a leak, and neither should you without more evidence.

Every response carries its source

jsonc
{ "source": "rpki-validator.ripe.net", "retrieved_at": "...", "outcome": "ok",
  "cached": false, "cache_age_seconds": null, "data": {...}, "caveats": [...] }

caveats carries the statements above — read them, they are not decoration. resource_report gives each section its own source; never attribute one section's data to another's origin.

Failures name the source that failed. source_unavailable is never "no record found" — a dead API and an empty registry are different facts.

Workflow: an unfamiliar prefix appears

  1. rpki_validate with the prefix and the origin AS. Validation is always of the pair.
  2. Read the state carefully against the table above. If not_found, stop treating it as a problem.
  3. registry_lookup — who holds it, and who to contact.
  4. routing_announced_prefixes on the origin AS — is this consistent with what it normally announces?
  5. peering_network — is this a transit provider, content network, or enterprise? It changes what "normal" looks like.
  6. Escalate only on invalid, and only after checking that the origin AS is what you think it is and the ROA is current. This skill does not declare incidents — that is your judgement.
Show full SKILL.md (307 more words)Show less

Workflow: who do I complain to?

  1. registry_abuse_contact on the address.
  2. If none is published, try the covering allocation with registry_lookup.
  3. peering_network often has a technical contact when the registry does not.

Boundaries — which tool owns what

QuestionUse
"Can the outside reach us? Measure from N countries"globalping-external-checks (R8) — Globalping measures; this looks up
"Quick: who owns this traceroute hop, and where is it?"gtrace-ip-enrichment — it owns ASN/geo/rDNS enrichment
"Is this software version vulnerable?"nvd-cve / cisco-psirt — different plane entirely
"Is this routing legitimate?"this skill

Those first two are load-bearing, not politeness. gtrace already does quick ASN and geolocation lookups and this skill deliberately does not duplicate them (Principle VII). For general Atlas/Globalping probe availability by location, or to run any measurement, go to Globalping.

Being a good citizen

RIPE NCC and PeeringDB are volunteer- and membership-funded. The server holds itself to ≤ 4 requests per second per source, strictly serial — even resource_report runs its sections one after another.

Do not use these tools to enumerate, sweep, or bulk-harvest registry data. Look things up in service of a specific operational question. The rate limiter enforces politeness mechanically; the judgement about what to ask is yours.

Repeated lookups come from a cache with per-source lifetimes — RPKI 5 minutes, registry 24 hours — and a cached answer says so and reports its age. Pass fresh=true when a ROA was just published and you need to see through the cache.

Important rules

  • not_found is normal. Say so when you report it.
  • Keep the two invalid reasons apart. Different cause, different fix.
  • Never say hijack or attack. Report state and evidence; escalation is the operator's.
  • Private and reserved addresses are refused locally, before any request leaves — sending internal addressing to a public registry is a disclosure even if the lookup fails.
  • Single validator. Results are never corroborated; they say so.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/bgp-registry-intel of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Bgp Registry Intel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bgp Registry Intel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bgp Registry Intel this skillautomateyournetwork/netclaw676—~1.8kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
Stitch to Remotion Walkthrough Videosgoogle-labs-code/stitch-skills8.5k6 repos~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Stitch to Remotion Walkthrough Videos

    google-labs-code/stitch-skills

    Official

    Builds walkthrough videos from Stitch design projects using Remotion, with transitions, zoom effects and text overlays on each screen.

    8.5k GitHub starsUsed in 6 repos~3.2k tokens
    Media & CreativeAuto-check: notes
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated yesterday
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed

Questions about Bgp Registry Intel

What does Bgp Registry Intel do?

BGP and registry intelligence — RPKI origin validation (is this announcement authorised?), RDAP registry ownership and abuse contacts, PeeringDB interconnection data, RIPEstat routing status and…. Bgp Registry Intel is an agent skill from automateyournetwork/netclaw.), RDAP registry ownership and abuse contacts, PeeringDB interconnection data, RIPEstat routing status and prefix visibility, RIPE Atlas anchors.

When should I use Bgp Registry Intel?

Bgp Registry Intel fits situations like: investigating an unfamiliar prefix; checking whether a BGP announcement is RPKI-valid; finding who owns address space; who to report abuse to.

How do I install Bgp Registry Intel in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill bgp-registry-intel -a claude-code`. Or copy the skill folder (workspace/skills/bgp-registry-intel in automateyournetwork/netclaw) into .claude/skills/bgp-registry-intel in your project. Claude Code loads it when a task matches its description.

How do I install Bgp Registry Intel in Codex?

Run `npx skills add automateyournetwork/netclaw --skill bgp-registry-intel -a codex`. Or copy the skill folder (workspace/skills/bgp-registry-intel in automateyournetwork/netclaw) into .agents/skills/bgp-registry-intel in your project. Codex loads it when a task matches its description.

Can I use Bgp Registry Intel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill bgp-registry-intel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bgp-registry-intel, .gemini/skills/bgp-registry-intel, .github/skills/bgp-registry-intel and .opencode/skills/bgp-registry-intel in your project.

What does Bgp Registry Intel need to run?

SKILL.md names no scripts, command-line tools or credentials: Bgp Registry Intel is instructions for the agent only.

Does Bgp Registry Intel access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bgp Registry Intel safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bgp Registry Intel use?

Bgp Registry Intel is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bgp Registry Intel use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bgp Registry Intel?

Skills that share tags, products or a category with Bgp Registry Intel: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bgp Registry Intel?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.