Agent skill

Cml Packet Capture

by automateyournetwork in automateyournetwork/netclaw

CML packet capture — start, stop, download pcaps from CML lab links, integrate with Packet Buddy for analysis.

Apache-2.0Auto-check passedSecurity

Install Cml Packet Capture

skills CLI
$ npx skills add automateyournetwork/netclaw --skill cml-packet-capture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw cml-packet-capture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/cml-packet-capture .claude/skills/cml-packet-capture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cml-packet-capture
GitHub stars
676
Token cost
~1.6k tokens
SKILL.md length
585 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

CML packet capture — start, stop, download pcaps from CML lab links, integrate with Packet Buddy for analysis.

  • Works in 7 steps: Find the link: Use get_links (from… → Start capture: start_capture with… → Generate traffic: Tell the user to… → …
  • Capturing packets in a CML lab
  • SKILL.md covers MCP Server, Available Tools, Workflow: Capture and Analyze… and Workflow: Targeted Protocol…, plus 5 more sections
  • Needs CML_PASSWORD

What it does

Cml Packet Capture is an agent skill from automateyournetwork/netclaw. CML packet capture — start, stop, download pcaps from CML lab links, integrate with Packet Buddy for analysis. Use when capturing packets in a CML lab, troubleshooting BGP or OSPF with packet analysis, or downloading pcap files for Wireshark review.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Network security. It works with Wireshark. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Capturing packets in a CML lab
  • Troubleshooting BGP
  • OSPF with packet analysis
  • Downloading pcap files for Wireshark review

Example prompts

  • “/cml-packet-capture”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Find the link: Use get_links (from cml-topology-builder) to find the link ID between R1 and R2
  2. Start capture: start_capture with optional filter (e.g., "icmp", "tcp port 179")
  3. Generate traffic: Tell the user to generate traffic (or use execute_command to ping)
  4. Stop capture: stop_capture after sufficient traffic is collected
  5. Download pcap: download_capture to save the pcap file locally
  6. Analyze with Packet Buddy: Hand off to the packet-analysis skill
  7. Report findings: Summarize the analysis in plain English

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CML_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cml Packet Capture loads about 1.6k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 585 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 585 words, ~1,551 tokens.

Download SKILL.mdSave it as .claude/skills/cml-packet-capture/SKILL.md (or your agent's skills folder).
name
cml-packet-capture
description
CML packet capture — start, stop, download pcaps from CML lab links, integrate with Packet Buddy for analysis. Use when capturing packets in a CML lab, troubleshooting BGP or OSPF with packet analysis, or downloading pcap files for Wireshark review.
version
1.0.0
license
Apache-2.0
tags
cml, pcap, capture, troubleshooting, wireshark

CML Packet Capture

MCP Server

  • Command: cml-mcp (pip-installed, stdio transport)
  • Requires: CML_URL, CML_USERNAME, CML_PASSWORD environment variables

Available Tools

Packet Capture Operations
ToolParametersWhat It Does
start_capturelab_id/lab_title, link_id, max_packets?, pcap_filter?Start capturing packets on a link
stop_capturelab_id/lab_title, link_idStop an active capture
get_capture_statuslab_id/lab_title, link_idCheck capture status (running, packet count)
download_capturelab_id/lab_title, link_id, file_path?Download the captured pcap file
list_captureslab_id/lab_titleList all active and completed captures in a lab

Workflow: Capture and Analyze (Full Pipeline)

When a user says "capture traffic between R1 and R2 and analyze it":

  1. Find the link: Use get_links (from cml-topology-builder) to find the link ID between R1 and R2
  2. Start capture: start_capture with optional filter (e.g., "icmp", "tcp port 179")
  3. Generate traffic: Tell the user to generate traffic (or use execute_command to ping)
  4. Stop capture: stop_capture after sufficient traffic is collected
  5. Download pcap: download_capture to save the pcap file locally
  6. Analyze with Packet Buddy: Hand off to the packet-analysis skill:
    • pcap_summary — overview
    • pcap_protocol_hierarchy — protocol breakdown
    • pcap_conversations — who talked to whom
    • pcap_expert_info — errors, retransmissions
    • pcap_filter — drill into specific traffic
  7. Report findings: Summarize the analysis in plain English

Workflow: Targeted Protocol Capture

When troubleshooting a specific protocol:

BGP Troubleshooting
1. start_capture with pcap_filter="tcp port 179"
2. Wait for BGP events (or trigger with clear ip bgp)
3. stop_capture
4. download_capture
5. Analyze: Look for OPEN, KEEPALIVE, UPDATE, NOTIFICATION messages
6. Check for: hold timer expiry, capability mismatch, prefix limit exceeded
OSPF Troubleshooting
1. start_capture with pcap_filter="ospf"
2. Wait for OSPF events (or trigger with clear ip ospf process)
3. stop_capture
4. download_capture
5. Analyze: Look for Hello, DBD, LSR, LSU, LSAck packets
6. Check for: area mismatch, auth failure, MTU mismatch, dead timer expiry
ICMP / Connectivity
1. start_capture (no filter, or pcap_filter="icmp")
2. execute_command on source node: "ping {destination}"
3. stop_capture
4. download_capture
5. Analyze: Look for echo request/reply, unreachable, TTL exceeded
6. Check for: asymmetric routing, ACL drops, MTU issues
Spanning Tree
1. start_capture with pcap_filter="stp"
2. Wait for STP convergence or trigger topology change
3. stop_capture
4. download_capture
5. Analyze: BPDUs, topology change notifications, root bridge elections

Capture Filters

CML uses BPF (Berkeley Packet Filter) syntax for capture filters:

FilterCaptures
icmpICMP (ping) traffic
tcp port 179BGP traffic
ospfOSPF traffic
tcp port 22SSH traffic
udp port 53DNS traffic
arpARP requests/replies
stpSpanning Tree BPDUs
tcp port 80 or tcp port 443HTTP/HTTPS traffic
host 10.0.0.1Traffic to/from specific host
net 10.0.0.0/24Traffic to/from specific subnet
vlan 100Traffic on VLAN 100

Workflow: Compare Before/After

When verifying a configuration change:

  1. Capture before: Start capture, collect baseline traffic
  2. Stop and download: Save as before.pcap
  3. Make the change: Apply configuration via cml-node-operations
  4. Capture after: Start new capture, collect post-change traffic
  5. Stop and download: Save as after.pcap
  6. Compare: Analyze both pcaps with Packet Buddy
  7. Report: Document the differences (e.g., "BGP converged in 3s after route-map change")
Show full SKILL.md (238 more words)Show less

Integration with Packet Buddy

After downloading a pcap from CML, use these Packet Buddy tools for analysis:

StepPacket Buddy ToolPurpose
1pcap_summaryBig picture: packet count, duration, size
2pcap_protocol_hierarchyWhat protocols are present
3pcap_conversationsWho is talking to whom
4pcap_expert_infoErrors, warnings, retransmissions
5pcap_filterFocus on specific traffic
6pcap_packet_detailDeep dive into a single packet
7pcap_dns_queriesDNS resolution analysis
8pcap_http_requestsHTTP traffic analysis

Important Rules

  • Lab must be running — captures only work on links in a started lab
  • One capture per link — stop an existing capture before starting a new one
  • Use filters for busy links — unfiltered captures on high-traffic links can be large
  • Set max_packets — prevent runaway captures; 10000 packets is usually enough
  • Download before stopping — some CML versions clear the capture buffer on link state change
  • File naming: Save pcaps with descriptive names like r1-r2-bgp-capture.pcap
  • Record in GAIT — log captures and findings for audit trail

Failure Behavior

  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/cml-packet-capture of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Cml Packet Capture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cml Packet Capture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cml Packet Capture this skillautomateyournetwork/netclaw676—~1.6kAutomated safety check: PassApache-2.0
Wireshark Analysiszebbern/claude-code-guide4.7k8 repos~3kAutomated safety check: PassMIT
IotnetBrownFineSecurity/iothackbot8591 repos~1kAutomated safety check: NotesMIT
Netzhinkgit/embeddedskills734—~1.1kAutomated safety check: PassMIT
Performing Network Forensics With Wiresharkmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: NotesApache-2.0
Performing Network Traffic Analysis With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Wireshark Analysis

    zebbern/claude-code-guide

    This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…

    4.7k GitHub starsUsed in 8 repos~3k tokens
    SecurityAuto-check passed
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    859 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Net

    zhinkgit/embeddedskills

    嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills.

    734 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Network Forensics With Wireshark

    mukul975/Anthropic-Cybersecurity-Skills

    Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Performing Network Traffic Analysis With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Analyzing Network Traffic With Wireshark

    mukul975/Anthropic-Cybersecurity-Skills

    Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Cml Packet Capture

What does Cml Packet Capture do?

CML packet capture — start, stop, download pcaps from CML lab links, integrate with Packet Buddy for analysis. Cml Packet Capture is an agent skill from automateyournetwork/netclaw. CML packet capture — start, stop, download pcaps from CML lab links, integrate with Packet Buddy for analysis.

When should I use Cml Packet Capture?

Cml Packet Capture fits situations like: capturing packets in a CML lab; troubleshooting BGP; OSPF with packet analysis; downloading pcap files for Wireshark review.

How do I install Cml Packet Capture in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill cml-packet-capture -a claude-code`. Or copy the skill folder (workspace/skills/cml-packet-capture in automateyournetwork/netclaw) into .claude/skills/cml-packet-capture in your project. Claude Code loads it when a task matches its description.

How do I install Cml Packet Capture in Codex?

Run `npx skills add automateyournetwork/netclaw --skill cml-packet-capture -a codex`. Or copy the skill folder (workspace/skills/cml-packet-capture in automateyournetwork/netclaw) into .agents/skills/cml-packet-capture in your project. Codex loads it when a task matches its description.

Can I use Cml Packet Capture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill cml-packet-capture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cml-packet-capture, .gemini/skills/cml-packet-capture, .github/skills/cml-packet-capture and .opencode/skills/cml-packet-capture in your project.

What does Cml Packet Capture need to run?

Going by SKILL.md and its folder, Cml Packet Capture needs credentials named CML_PASSWORD.

Does Cml Packet Capture access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cml Packet Capture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cml Packet Capture use?

Cml Packet Capture is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cml Packet Capture use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cml Packet Capture?

Skills that share tags, products or a category with Cml Packet Capture: Wireshark Analysis (zebbern/claude-code-guide, 4.7k stars), Iotnet (BrownFineSecurity/iothackbot, 859 stars), Net (zhinkgit/embeddedskills, 734 stars) and Performing Network Forensics With Wireshark (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cml Packet Capture?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.