Agent skill

Gtrace Ip Enrichment

by automateyournetwork in automateyournetwork/netclaw

IP address enrichment — ASN ownership lookup, geolocation (city/region/country/coordinates), and reverse DNS resolution.

Apache-2.0Auto-check passed

Install Gtrace Ip Enrichment

skills CLI
$ npx skills add automateyournetwork/netclaw --skill gtrace-ip-enrichment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw gtrace-ip-enrichment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/gtrace-ip-enrichment .claude/skills/gtrace-ip-enrichment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gtrace-ip-enrichment
GitHub stars
676
Token cost
~1.2k tokens
SKILL.md length
547 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

IP address enrichment — ASN ownership lookup, geolocation (city/region/country/coordinates), and reverse DNS resolution.

  • Works in 3 steps: ASN Lookup → Geolocation → Reverse DNS
  • Identifying who owns an IP address
  • SKILL.md covers How to Call the gtrace MCP Tools, When to Use, Available Tools and Workflow: IP Investigation, plus 6 more sections
  • Calls python3

What it does

Gtrace Ip Enrichment is an agent skill from automateyournetwork/netclaw. IP address enrichment — ASN ownership lookup, geolocation (city/region/country/coordinates), and reverse DNS resolution. Use when identifying who owns an IP address, locating an IP geographically, resolving reverse DNS for a traceroute hop, or enriching unknown IPs from logs or flow data.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Identifying who owns an IP address
  • Locating an IP geographically
  • Resolving reverse DNS for a traceroute hop
  • Enriching unknown IPs from logs

Example prompts

  • “/gtrace-ip-enrichment”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. ASN Lookup
  2. Geolocation
  3. Reverse DNS

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gtrace Ip Enrichment loads about 1.2k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 547 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 547 words, ~1,224 tokens.

Download SKILL.mdSave it as .claude/skills/gtrace-ip-enrichment/SKILL.md (or your agent's skills folder).
name
gtrace-ip-enrichment
description
IP address enrichment — ASN ownership lookup, geolocation (city/region/country/coordinates), and reverse DNS resolution. Use when identifying who owns an IP address, locating an IP geographically, resolving reverse DNS for a traceroute hop, or enriching unknown IPs from logs or flow data.
license
Apache-2.0
user-invocable
true

IP Address Enrichment with gtrace

How to Call the gtrace MCP Tools

bash
python3 $MCP_CALL "gtrace mcp" TOOL_NAME '{"param":"value"}'

When to Use

  • Identify who owns an IP address (ASN, organization name, network range)
  • Determine the geographic location of an IP (city, region, country, coordinates)
  • Resolve an IP address to its PTR/reverse DNS hostname
  • Enrich traceroute hop data with ASN and geo context
  • Investigate unknown IPs appearing in logs, flow data, or routing tables
  • Map network paths to physical geography for latency analysis

Available Tools

ToolPurpose
asn_lookupLook up ASN, organization, and network range for an IP
geo_lookupGet geographic location (city, region, country, lat/lon) for an IP
reverse_dnsResolve an IP to its PTR record (reverse DNS hostname)

Workflow: IP Investigation

When asked "who owns this IP?" or "where is this IP?":

Step 1: ASN Lookup

Identify the Autonomous System and organization that owns the IP.

bash
python3 $MCP_CALL "gtrace mcp" asn_lookup '{"ip":"8.8.8.8"}'

Returns: ASN number, organization name, network CIDR, registry (ARIN, RIPE, APNIC, etc.)

Step 2: Geolocation

Determine the physical location of the IP.

bash
python3 $MCP_CALL "gtrace mcp" geo_lookup '{"ip":"8.8.8.8"}'

Returns: City, region/state, country, latitude/longitude, timezone

Step 3: Reverse DNS

Resolve the IP to its PTR record for hostname identification.

bash
python3 $MCP_CALL "gtrace mcp" reverse_dns '{"ip":"8.8.8.8"}'

Returns: PTR hostname (e.g., dns.google)

Workflow: Traceroute Hop Enrichment

After running a traceroute (via gtrace-path-analysis skill), enrich each hop with ASN and geo data:

  1. Run traceroute to get the path with hop IPs
  2. For each hop IP, run asn_lookup to identify the network owner
  3. For key hops (transit boundaries, high-latency hops), run geo_lookup to map physical location
  4. Use reverse_dns on hops to identify router naming conventions (often reveals ISP, POP location, interface type)
bash
# Example: enrich a traceroute hop
python3 $MCP_CALL "gtrace mcp" asn_lookup '{"ip":"72.14.215.85"}'
python3 $MCP_CALL "gtrace mcp" geo_lookup '{"ip":"72.14.215.85"}'
python3 $MCP_CALL "gtrace mcp" reverse_dns '{"ip":"72.14.215.85"}'

Workflow: BGP Peer Identification

When investigating BGP peers or routes:

  1. Get the peer IP from bgp_get_peers (protocol-participation skill)
  2. Run asn_lookup to verify the peer's ASN matches what BGP reports
  3. Run geo_lookup to confirm the peer's physical location
  4. Run reverse_dns to identify the peer's hostname and operator

Tool Parameters

asn_lookup
  • ip (required): IPv4 or IPv6 address to look up
geo_lookup
  • ip (required): IPv4 or IPv6 address to geolocate
Show full SKILL.md (217 more words)Show less
reverse_dns
  • ip (required): IPv4 or IPv6 address to resolve

Output Format

  • asn_lookup — ASN number, organization name, network CIDR prefix, RIR (ARIN/RIPE/APNIC/LACNIC/AFRINIC)
  • geo_lookup — city, region/state, country, country code, latitude, longitude, timezone
  • reverse_dns — PTR hostname, or indication that no PTR record exists

Important Rules

  • These tools require internet access for IP intelligence lookups
  • Geolocation accuracy varies — typically city-level for broadband, region-level for mobile/cloud
  • ASN lookup is the most reliable enrichment — it uses RIR delegation data
  • Reverse DNS depends on the IP owner having configured PTR records
  • Use all three tools together for comprehensive IP enrichment
  • Cross-reference ASN data with BGP RIB entries for routing consistency verification
  • Record all IP enrichment in GAIT

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that GTRACE_MCP_BIN is set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/gtrace-ip-enrichment of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Gtrace Ip Enrichment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gtrace Ip Enrichment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gtrace Ip Enrichment this skillautomateyournetwork/netclaw676—~1.2kAutomated safety check: PassApache-2.0
Add Enrichmentsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Documentation Lookupaffaan-m/ECC276k1 repos~670Automated safety check: PassMIT
Documentation Lookupaffaan-m/ECC276k—~640Automated safety check: PassMIT
Pathway EnrichmentK-Dense-AI/scientific-agent-skills48k1 repos~4.2kAutomated safety check: PassMIT
Performing Ioc Enrichment Automationmukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Add Enrichment

    simstudioai/sim

    Add a code-defined table enrichment (registry entry) under apps/sim/enrichments/ backed by an ordered provider cascade, ensuring every provider tool it calls has hosted-key support.

    30k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • 通过 Context7 MCP 使用最新的库和框架文档,而非训练数据。当用户提出设置问题、API参考、代码示例或命名框架(例如 React、Next.js、Prisma)时激活。

    276k GitHub starsUsed in 1 repo~670 tokens
    DatabasesAuto-check passed
  • 訓練データの代わりにContext7 MCP経由で最新のライブラリとフレームワークドキュメント使用。セットアップの質問、APIリファレンス、コード例、またはユーザーがフレームワーク(例:React、Next.js、Prisma)に名前を付けるときにアクティベーション。

    276k GitHub stars~640 tokensUpdated yesterday
    DatabasesAuto-check passed
  • Pathway Enrichment

    K-Dense-AI/scientific-agent-skills

    Performs pathway and gene-set enrichment analysis on gene lists or ranked gene data and interprets the results.

    48k GitHub starsUsed in 1 repo~4.2k tokens
    Research & ScienceAuto-check passed
  • Performing Ioc Enrichment Automation

    mukul975/Anthropic-Cybersecurity-Skills

    Automates Indicator of Compromise (IOC) enrichment by orchestrating lookups across VirusTotal, AbuseIPDB, Shodan, MISP, and other intelligence sources to provide contextual scoring and disposition…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Fetches current library and framework documentation through the Context7 MCP instead of relying on training data, resolving a library ID before each query.

    277k GitHub starsUsed in 4 repos~1.2k tokens
    DevelopmentAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Questions about Gtrace Ip Enrichment

What does Gtrace Ip Enrichment do?

IP address enrichment — ASN ownership lookup, geolocation (city/region/country/coordinates), and reverse DNS resolution. Gtrace Ip Enrichment is an agent skill from automateyournetwork/netclaw. IP address enrichment — ASN ownership lookup, geolocation (city/region/country/coordinates), and reverse DNS resolution.

When should I use Gtrace Ip Enrichment?

Gtrace Ip Enrichment fits situations like: identifying who owns an IP address; locating an IP geographically; resolving reverse DNS for a traceroute hop; enriching unknown IPs from logs.

How do I install Gtrace Ip Enrichment in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill gtrace-ip-enrichment -a claude-code`. Or copy the skill folder (workspace/skills/gtrace-ip-enrichment in automateyournetwork/netclaw) into .claude/skills/gtrace-ip-enrichment in your project. Claude Code loads it when a task matches its description.

How do I install Gtrace Ip Enrichment in Codex?

Run `npx skills add automateyournetwork/netclaw --skill gtrace-ip-enrichment -a codex`. Or copy the skill folder (workspace/skills/gtrace-ip-enrichment in automateyournetwork/netclaw) into .agents/skills/gtrace-ip-enrichment in your project. Codex loads it when a task matches its description.

Can I use Gtrace Ip Enrichment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill gtrace-ip-enrichment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gtrace-ip-enrichment, .gemini/skills/gtrace-ip-enrichment, .github/skills/gtrace-ip-enrichment and .opencode/skills/gtrace-ip-enrichment in your project.

What does Gtrace Ip Enrichment need to run?

Going by SKILL.md and its folder, Gtrace Ip Enrichment needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Gtrace Ip Enrichment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gtrace Ip Enrichment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gtrace Ip Enrichment use?

Gtrace Ip Enrichment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gtrace Ip Enrichment use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gtrace Ip Enrichment?

Skills that share tags, products or a category with Gtrace Ip Enrichment: Add Enrichment (simstudioai/sim, 30k stars), Documentation Lookup (affaan-m/ECC, 276k stars), Documentation Lookup (affaan-m/ECC, 276k stars) and Pathway Enrichment (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gtrace Ip Enrichment?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.