Agent skill

Junos Network

by automateyournetwork in automateyournetwork/netclaw

Juniper JunOS device automation via PyEZ/NETCONF — CLI execution, configuration management, Jinja2 template rendering, device facts, batch operations, config diff and rollback comparison (10 tools).

Apache-2.0Auto-check passedDevOps & Cloud

Install Junos Network

skills CLI
$ npx skills add automateyournetwork/netclaw --skill junos-network -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw junos-network --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/junos-network .claude/skills/junos-network && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
junos-network
GitHub stars
676
Token cost
~2.7k tokens
SKILL.md length
829 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Juniper JunOS device automation via PyEZ/NETCONF — CLI execution, configuration management, Jinja2 template rendering, device facts, batch operations, config diff and rollback comparison (10 tools).

  • Works in 6 steps: JunOS Device Discovery → JunOS Health Check → JunOS Configuration Audit → …
  • Managing Juniper routers
  • SKILL.md covers MCP Server, Device Inventory, Environment Variables and Tools (10), plus 6 more sections
  • Calls pip, git and python3

What it does

Junos Network is an agent skill from automateyournetwork/netclaw. Juniper JunOS device automation via PyEZ/NETCONF — CLI execution, configuration management, Jinja2 template rendering, device facts, batch operations, config diff and rollback comparison (10 tools). Use when managing Juniper routers, pushing JunOS configs, running show commands on Juniper devices, or comparing rollback versions

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Model Context Protocol and Python. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Managing Juniper routers
  • Pushing JunOS configs
  • Running show commands on Juniper devices
  • Comparing rollback versions

Example prompts

  • “/junos-network”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. JunOS Device Discovery
  2. JunOS Health Check
  3. JunOS Configuration Audit
  4. JunOS Configuration Deployment
  5. JunOS Batch Operations
  6. JunOS Rollback Investigation

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip
    • git
    • python3
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Junos Network loads about 2.7k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 829 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 829 words, ~2,703 tokens.

Download SKILL.mdSave it as .claude/skills/junos-network/SKILL.md (or your agent's skills folder).
name
junos-network
description
Juniper JunOS device automation via PyEZ/NETCONF — CLI execution, configuration management, Jinja2 template rendering, device facts, batch operations, config diff and rollback comparison (10 tools). Use when managing Juniper routers, pushing JunOS configs, running show commands on Juniper devices, or comparing rollback versions
license
Apache-2.0
user-invocable
true

Juniper JunOS Network Automation

MCP Server

FieldValue
RepositoryJuniper/junos-mcp-server
Transportstdio (default for CLI), streamable-http (for IDE)
Python3.10+ (3.11 recommended)
ProtocolSSH → NETCONF → PyEZ (junos-eznc)
Dependenciesjunos-eznc>=2.7.4, jxmlease>=1.0.3, lxml>=6.0.0, mcp[cli]>=1.12.2, ncclient>=0.6.15, paramiko>=3.5.1
Installgit clone + pip install -r requirements.txt or pip install .
Entry Pointjunos-mcp-server -f devices.json -t stdio or python3 jmcp.py -f devices.json -t stdio
Containerdocker build -t junos-mcp-server . (python:3.11-slim based)

Device Inventory

Devices are defined in a devices.json file (not environment variables):

json
{
  "core-rtr-01": {
    "ip": "10.0.0.1",
    "port": 22,
    "username": "netops",
    "auth": {
      "type": "ssh_key",
      "private_key_path": "/home/user/.ssh/junos_key"
    }
  },
  "edge-rtr-02": {
    "ip": "10.0.0.2",
    "port": 22,
    "username": "admin",
    "auth": {
      "type": "password",
      "password": "changeme"
    }
  }
}

SSH key authentication is strongly recommended for production. Jumphost/ProxyCommand is supported via ssh_config field.

Environment Variables

VariableDefaultPurpose
JUNOS_DEVICES_FILEdevices.jsonPath to device inventory JSON
JUNOS_TIMEOUT360Default command timeout in seconds

Tools (10)

Device Inventory (3 tools)
ToolParametersDescription
get_router_list—List all available Junos routers (passwords/keys filtered from output)
add_devicedevice_name?, device_ip?, device_port?, username?, ssh_key_path?Add a new Junos device interactively (streamable-http only)
reload_devicesfile_nameReload the device dictionary from a new JSON file
CLI Execution (2 tools)
ToolParametersDescription
execute_junos_commandrouter_name, command, timeout?Execute a JunOS CLI command on a single router
execute_junos_command_batchrouter_names, command, timeout?Execute the same command on multiple routers in parallel
Configuration Management (3 tools)
ToolParametersDescription
get_junos_configrouter_nameRetrieve the full running configuration (show configuration | display set)
junos_config_diffrouter_name, version?Compare current config against a rollback version (1-49)
load_and_commit_configrouter_name, config_text, config_format?, commit_comment?Load and commit configuration (formats: set, text, xml)
Template & Facts (2 tools)
ToolParametersDescription
render_and_apply_j2_templatetemplate_content, vars_content, router_name?, router_names?, apply_config?, dry_run?, commit_comment?Render Jinja2 template with YAML variables; optionally apply to one or many routers with dry-run support
gather_device_factsrouter_name, timeout?Gather device facts: hostname, model, serial, version, uptime, RE info

Safety Features

Command Blocklist (block.cmd)

The server ships with a blocklist that prevents destructive CLI commands:

  • request system reboot
  • request system halt
  • request system power-cycle
  • request system power-off
  • request system zeroize

Custom patterns (regex) can be added to block.cmd.

Configuration Blocklist (block.cfg)

Prevents dangerous configuration changes:

  • set system root-authentication — blocks root password changes
  • set system login user ... authentication — blocks user credential changes

Custom patterns (regex) can be added to block.cfg.

Credential Filtering

get_router_list automatically strips passwords and SSH key paths before returning device data.


Workflows

1. JunOS Device Discovery
get_router_list → inventory all available Junos routers
→ gather_device_facts(router) per device → hostname, model, serial, version, uptime
→ Cross-reference with NetBox/Nautobot → flag discrepancies
→ GAIT
2. JunOS Health Check
get_router_list → identify target routers
→ execute_junos_command_batch(routers, "show chassis alarms") → alarm check
→ execute_junos_command_batch(routers, "show system processes extensive") → CPU/memory
→ execute_junos_command_batch(routers, "show interfaces terse") → interface status
→ execute_junos_command_batch(routers, "show bgp summary") → BGP peer health
→ Severity-sort findings → GAIT
3. JunOS Configuration Audit
get_router_list → select target routers
→ get_junos_config(router) → retrieve running config
→ junos_config_diff(router, version=1) → check for uncommitted or recent changes
→ Compare against golden config templates → flag deviations
→ GAIT
4. JunOS Configuration Deployment
ServiceNow CR must be in Implement state
→ get_junos_config(router) → baseline current config
→ render_and_apply_j2_template(template, vars, router, dry_run=true) → preview changes
→ render_and_apply_j2_template(template, vars, router, apply_config=true, commit_comment="CR-12345") → apply
→ get_junos_config(router) → verify post-change config
→ execute_junos_command(router, "show bgp summary") → verify protocol health
→ GAIT
5. JunOS Batch Operations
get_router_list → filter to target group (e.g., all edge routers)
→ execute_junos_command_batch(routers, "show version") → version inventory
→ execute_junos_command_batch(routers, "show ospf neighbor") → protocol health
→ Aggregate results → severity-sort → GAIT
6. JunOS Rollback Investigation
junos_config_diff(router, version=1) → compare against last committed config
→ junos_config_diff(router, version=2) → compare against version before that
→ Identify what changed, when, and the impact
→ execute_junos_command(router, "show system commit") → commit history
→ GAIT

Integration with Other Skills

SkillIntegration
pyats-networkJunOS MCP for Juniper devices, pyATS MCP for Cisco devices — unified multi-vendor fleet management
netbox-reconcileCross-reference JunOS device facts (model, serial, version) against NetBox source of truth
nautobot-sotSame as NetBox — validate Juniper device IPAM data in Nautobot
infrahub-sotCross-reference Infrahub node data with Juniper device inventory
itential-automationItential workflows can orchestrate JunOS config deployments; Junos command templates complement Itential's
servicenow-change-workflowGate all JunOS config commits behind ServiceNow Change Requests
gait-session-trackingEvery JunOS command, config push, and batch operation logged in GAIT
nso-device-opsNSO for multi-vendor orchestration, JunOS MCP for direct Juniper device access
te-network-monitoringValidate network health via ThousandEyes after JunOS config changes
fmc-firewall-opsCorrelate Juniper ACL/firewall-filter config with Cisco FMC security policies
subnet-calculatorVLSM planning for Juniper interface addressing
nvd-cveScan Junos OS versions against NVD vulnerability database

Show full SKILL.md (310 more words)Show less

JunOS MCP vs pyATS MCP

CapabilityJunOS MCPpyATS MCP
VendorJuniper onlyCisco (IOS-XE, NX-OS, IOS-XR)
ProtocolNETCONF via PyEZSSH + Genie parsers
CLI Executionexecute_junos_commandpyats_run_command
Batch Operationsexecute_junos_command_batch (native parallel)pyats_pcall (parallel pCall)
Config Retrievalget_junos_config (set format)pyats_run_command("show run")
Config Pushload_and_commit_config (NETCONF commit)pyats_configure_device (SSH configure terminal)
Template SupportBuilt-in Jinja2 rendering + applyExternal (Jinja2 → configure)
Config Diffjunos_config_diff (rollback compare)Manual diff via show commands
Device Factsgather_device_facts (PyEZ facts)pyats_learn("platform")
Safetyblock.cmd + block.cfg regex blocklistsBuilt-in destructive command blocking
MCP Tools108

Guardrails

  • Always call get_router_list first — verify the target device exists before executing commands
  • Always baseline before changes — call get_junos_config before any load_and_commit_config or template apply
  • Use dry_run for templates — set dry_run=true on render_and_apply_j2_template to preview changes before committing
  • Gate config changes — all load_and_commit_config and render_and_apply_j2_template(apply_config=true) calls must have a ServiceNow CR in Implement state
  • Use batch for fleet ops — prefer execute_junos_command_batch over looping execute_junos_command for multi-router operations
  • Set reasonable timeouts — default is 360s; reduce for simple show commands, increase for large config operations
  • Include commit comments — always provide a commit_comment referencing the ServiceNow CR number
  • Verify after config pushes — call get_junos_config and protocol-specific show commands after changes
  • Respect the blocklists — block.cmd and block.cfg prevent destructive operations; do not bypass them
  • Record in GAIT — every command, config push, batch operation, and template rendering must be logged

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that JUNOS_DEVICES_FILE is set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • Do not automatically retry a write/mutating operation after a failure — surface the error and get explicit confirmation before retrying, since a blind retry on a partially-applied change can leave state inconsistent.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/junos-network of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Junos Network next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Junos Network compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Junos Network this skillautomateyournetwork/netclaw676—~2.7kAutomated safety check: PassApache-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Unraiddinglebear-ai/unraid135—~5.4kAutomated safety check: NotesMIT
Unraiddinglebear-ai/unraid135—~2.8kAutomated safety check: PassMIT
Flow Contextflowexec/flow137—~654Automated safety check: PassApache-2.0
Dv Solutionmicrosoft/Dataverse-skills243—~3kAutomated safety check: PassMIT

Similar skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Unraid

    dinglebear-ai/unraid

    This skill should be used when the user mentions Unraid, asks to check server health, monitor array or disk status, list or restart Docker containers, start or stop VMs, read system logs, check…

    135 GitHub stars~5.4k tokensUpdated 5 days ago
    DevOps & CloudAuto-check: notes
  • Unraid

    dinglebear-ai/unraid

    Query and monitor an Unraid NAS/homelab server — array health, disk temperatures, Docker containers, virtual machines, system metrics, notifications, alerts, shares, UPS status, log files, network…

    135 GitHub stars~2.8k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Flow Context

    flowexec/flow

    This project uses flow for automation. An agent skill from flowexec/flow.

    137 GitHub stars~654 tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Dv Solution

    microsoft/Dataverse-skills

    Official

    Dataverse solution lifecycle — create, export, import, promote across environments, and validate deployments.

    243 GitHub stars~3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    sickn33/agentic-awesome-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated 3 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated 3 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Junos Network

What does Junos Network do?

Juniper JunOS device automation via PyEZ/NETCONF — CLI execution, configuration management, Jinja2 template rendering, device facts, batch operations, config diff and rollback comparison (10 tools). Junos Network is an agent skill from automateyournetwork/netclaw. Juniper JunOS device automation via PyEZ/NETCONF — CLI execution, configuration management, Jinja2 template rendering, device facts, batch operations, config diff and rollback comparison (10 tools).

When should I use Junos Network?

Junos Network fits situations like: managing Juniper routers; pushing JunOS configs; running show commands on Juniper devices; comparing rollback versions.

How do I install Junos Network in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill junos-network -a claude-code`. Or copy the skill folder (workspace/skills/junos-network in automateyournetwork/netclaw) into .claude/skills/junos-network in your project. Claude Code loads it when a task matches its description.

How do I install Junos Network in Codex?

Run `npx skills add automateyournetwork/netclaw --skill junos-network -a codex`. Or copy the skill folder (workspace/skills/junos-network in automateyournetwork/netclaw) into .agents/skills/junos-network in your project. Codex loads it when a task matches its description.

Can I use Junos Network in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill junos-network -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/junos-network, .gemini/skills/junos-network, .github/skills/junos-network and .opencode/skills/junos-network in your project.

What does Junos Network need to run?

Going by SKILL.md and its folder, Junos Network needs the command-line tools its instructions call (pip, git, python3 and docker). Our summary lists: Python 3; Docker.

Does Junos Network access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Junos Network safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Junos Network use?

Junos Network is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Junos Network use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Junos Network?

Skills that share tags, products or a category with Junos Network: AWS Cdk Development (zxkane/aws-skills, 367 stars), Unraid (dinglebear-ai/unraid, 135 stars), Unraid (dinglebear-ai/unraid, 135 stars) and Flow Context (flowexec/flow, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Junos Network?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.