Agent skill

Kubeshark Traffic

by automateyournetwork in automateyournetwork/netclaw

Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools).

Apache-2.0Auto-check passedDevOps & Cloud

Install Kubeshark Traffic

skills CLI
$ npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw kubeshark-traffic --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/kubeshark-traffic .claude/skills/kubeshark-traffic && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kubeshark-traffic
GitHub stars
676
Token cost
~2k tokens
SKILL.md length
680 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools).

  • Works in 8 steps: Capture traffic:… → List flows: list_l4_flows — see all… → Flow summary: get_l4_flow_summary —… → …
  • Capturing Kubernetes pod traffic
  • SKILL.md covers MCP Server, How to Run, Environment Variables and Tools, plus 8 more sections
  • Calls kubectl and helm

What it does

Kubeshark Traffic is an agent skill from automateyournetwork/netclaw. Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools). Use when capturing Kubernetes pod traffic, debugging service-to-service latency, exporting pcaps from a cluster, or analyzing encrypted east-west traffic

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes and Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Capturing Kubernetes pod traffic
  • Debugging service-to-service latency
  • Exporting pcaps from a cluster
  • Analyzing encrypted east-west traffic

Example prompts

  • “/kubeshark-traffic”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Capture traffic: capture_traffic(filter="src.pod.name == 'frontend'") — start targeted capture
  2. List flows: list_l4_flows — see all TCP/UDP connections with RTT and stats
  3. Flow summary: get_l4_flow_summary — identify top talkers and protocol breakdown
  4. Apply filter: apply_filter(kfl_expression="response.status >= 500") — isolate errors
  5. Export pcap: export_pcap(filter="dst.pod.name == 'api-gateway'") — export for deep analysis
  6. Cross-reference: Use packet-analysis skill to analyze exported pcap with tshark
  7. Report: Service communication analysis with latency, error rates, and traffic patterns
  8. GAIT: Record all captures and findings in audit trail

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl
    • helm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • docs.kubeshark.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kubeshark Traffic loads about 2k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 680 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 680 words, ~1,967 tokens.

Download SKILL.mdSave it as .claude/skills/kubeshark-traffic/SKILL.md (or your agent's skills folder).
name
kubeshark-traffic
description
Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools). Use when capturing Kubernetes pod traffic, debugging service-to-service latency, exporting pcaps from a cluster, or analyzing encrypted east-west traffic
license
Apache-2.0
user-invocable
true

Kubeshark Kubernetes Traffic Analysis

MCP Server

PropertyValue
Sourcekubeshark/kubeshark — MCP docs
TransportRemote HTTP (JSON-RPC 2.0, default port 8898)
LanguageGo (built into Kubeshark Hub)
Tools6 (capture, export pcap, snapshot, filter, L4 flows, flow summary)
AuthNone (cluster-internal); requires kubectl port-forward for remote access
RequiresKubernetes cluster with Kubeshark installed via Helm

How to Run

bash
# Install Kubeshark with MCP enabled
helm install kubeshark kubeshark/kubeshark \
  --set mcp.enabled=true \
  --set mcp.port=8898

# Port-forward for local access (if not in-cluster)
kubectl port-forward svc/kubeshark-hub 8898:8898

# MCP endpoint is now available at:
# http://localhost:8898/mcp

Environment Variables

VariableRequiredExampleDescription
KUBESHARK_MCP_URLYeshttp://localhost:8898/mcpKubeshark MCP endpoint URL
KUBESHARK_MCP_PORTNo8898MCP server port (default: 8898)

Tools

ToolParametersWhat It Does
capture_trafficfilter?, duration?Start targeted packet capture across cluster pods
export_pcapfilter?, time_range?Export captured traffic as pcap for Wireshark/tshark analysis
create_snapshotfilter?Create point-in-time traffic snapshot within retention window
apply_filterkfl_expressionApply Kubeshark Filter Language (KFL) expressions to narrow results
list_l4_flowsfilter?List TCP/UDP flows with connection stats, RTT metrics, byte counts
get_l4_flow_summaryfilter?High-level summary: top talkers, protocol distribution, traffic volume

Resources Exposed

  • Real-time L7 API streams (HTTP, gRPC, GraphQL, Redis, Kafka, DNS) with full request/response payloads
  • Historical traffic queries within the configured retention window
  • Decrypted TLS/HTTPS traffic via eBPF (no manual key management)
  • TCP/UDP connection flows with timing, RTT, and byte statistics
  • Kubernetes pod identity and service mapping (source → destination with namespace/labels)

Workflow: Kubernetes Service Troubleshooting

When investigating connectivity or latency issues between Kubernetes services:

  1. Capture traffic: capture_traffic(filter="src.pod.name == 'frontend'") — start targeted capture
  2. List flows: list_l4_flows — see all TCP/UDP connections with RTT and stats
  3. Flow summary: get_l4_flow_summary — identify top talkers and protocol breakdown
  4. Apply filter: apply_filter(kfl_expression="response.status >= 500") — isolate errors
  5. Export pcap: export_pcap(filter="dst.pod.name == 'api-gateway'") — export for deep analysis
  6. Cross-reference: Use packet-analysis skill to analyze exported pcap with tshark
  7. Report: Service communication analysis with latency, error rates, and traffic patterns
  8. GAIT: Record all captures and findings in audit trail
Example: API Gateway Latency Investigation
capture_traffic(filter="dst.pod.name == 'api-gateway'", duration="5m")
list_l4_flows(filter="dst.pod.name == 'api-gateway'")
get_l4_flow_summary(filter="dst.pod.name == 'api-gateway'")
apply_filter(kfl_expression="response.latency > 500ms")
export_pcap(filter="response.latency > 500ms")

Workflow: TLS Traffic Inspection

When investigating encrypted service-to-service communication:

  1. Capture: capture_traffic — Kubeshark automatically decrypts TLS via eBPF
  2. Filter: apply_filter(kfl_expression="request.headers['content-type'] == 'application/grpc'") — isolate gRPC
  3. Flows: list_l4_flows — see encrypted connections with decrypted payload summaries
  4. Export: export_pcap — export decrypted traffic for offline analysis
  5. Report: TLS communication audit with certificate info and payload analysis

Workflow: Incident Traffic Forensics

When performing post-incident traffic analysis:

  1. Snapshot: create_snapshot — capture current traffic state
  2. Historical query: apply_filter with time range — find traffic around incident time
  3. Flow analysis: list_l4_flows — identify unusual connections or traffic spikes
  4. Top talkers: get_l4_flow_summary — find services with abnormal traffic volume
  5. Export evidence: export_pcap — preserve traffic for incident report
  6. Cross-reference: Correlate with Prometheus metrics, Grafana alerts, and pyATS device state

Show full SKILL.md (261 more words)Show less

Integration with Other Skills

SkillIntegration
packet-analysisExport Kubeshark pcaps → analyze with Packet Buddy tshark (deeper protocol dissection)
prometheus-monitoringCorrelate Kubeshark flow metrics with Prometheus time-series data
grafana-observabilityCross-reference Kubeshark traffic patterns with Grafana dashboards and alerts
pyats-health-checkCompare Kubernetes network traffic with underlying infrastructure health
gait-session-trackingRecord all Kubeshark captures, exports, and analysis in GAIT audit trail
servicenow-change-workflowReference Kubeshark traffic captures as evidence in change requests or incidents

Kubeshark Filter Language (KFL) Examples

# Filter by pod name
src.pod.name == "frontend"

# Filter by namespace
dst.namespace == "production"

# HTTP status codes
response.status >= 400

# Latency threshold
response.latency > 200ms

# Protocol type
protocol == "grpc"

# Combined filters
src.namespace == "default" and response.status >= 500 and response.latency > 1s

# DNS queries
protocol == "dns" and request.query contains "api.internal"

# Kafka messages
protocol == "kafka" and request.topic == "orders"

Important Rules

  • All tools are read-only — Kubeshark captures and analyzes traffic but does not modify it
  • Cluster access required — Kubeshark must be deployed in the target Kubernetes cluster via Helm
  • Port-forward for remote access — use kubectl port-forward svc/kubeshark-hub 8898:8898 when not in-cluster
  • Retention window — historical queries are limited to the configured retention period
  • Large captures — use KFL filters to scope captures and avoid overwhelming context with large traffic volumes
  • Sensitive data — captured traffic may contain PII, credentials, or secrets in request/response payloads; handle exports accordingly
  • GAIT audit mandatory — record all traffic captures, pcap exports, and analysis findings
  • No secrets in filters — never embed credentials or sensitive data in KFL expressions

Error Handling

  • Connection refused: Verify Kubeshark is running (kubectl get pods -n kubeshark) and port-forward is active.
  • No traffic captured: Check KFL filter syntax; verify target pods exist and are generating traffic.
  • MCP endpoint not found: Ensure mcp.enabled=true in Helm values; verify MCP port matches KUBESHARK_MCP_URL.
  • Permission denied: Check RBAC — Kubeshark needs cluster-wide read access for traffic capture.
  • Empty pcap exports: Verify retention window covers the requested time range; check that traffic matching the filter exists.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/kubeshark-traffic of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Kubeshark Traffic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kubeshark Traffic compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kubeshark Traffic this skillautomateyournetwork/netclaw676—~2kAutomated safety check: PassApache-2.0
K8s Agent Sandbox MCPkubernetes-sigs/agent-sandbox4.2k—~1.3kAutomated safety check: PassApache-2.0
Apex Azure Diagnosticsjonathan-vella/apex217—~2.1kAutomated safety check: PassMIT
Eks Best Practicesaws-samples/appmod-blueprints115—~5kAutomated safety check: PassMIT-0
Ksaildevantler-tech/ksail165—~1.1kAutomated safety check: PassCustom licence
Azure Kubernetes Automatic Readinessmicrosoft/GitHub-Copilot-for-Azure2551 repos~4.4kAutomated safety check: PassMIT

Similar skills

  • K8s Agent Sandbox MCP

    kubernetes-sigs/agent-sandbox

    Official

    An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.

    4.2k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Apex Azure Diagnostics

    jonathan-vella/apex

    WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

    217 GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    115 GitHub stars~5k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Ksail

    devantler-tech/ksail

    Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.

    165 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure Kubernetes Automatic Readiness

    microsoft/GitHub-Copilot-for-Azure

    Official

    Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.

    255 GitHub starsUsed in 1 repo~4.4k tokens
    DevOps & CloudAuto-check passed
  • Gitops Cluster Debug

    fluxcd/agent-skills

    Debug and troubleshoot Flux CD on live Kubernetes clusters (not local repo files) via the Flux MCP server — inspects Flux resource status, reads controller logs, traces dependency chains, and…

    231 GitHub stars~4.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Categories

Questions about Kubeshark Traffic

What does Kubeshark Traffic do?

Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools). Kubeshark Traffic is an agent skill from automateyournetwork/netclaw. Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools).

When should I use Kubeshark Traffic?

Kubeshark Traffic fits situations like: capturing Kubernetes pod traffic; debugging service-to-service latency; exporting pcaps from a cluster; analyzing encrypted east-west traffic.

How do I install Kubeshark Traffic in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a claude-code`. Or copy the skill folder (workspace/skills/kubeshark-traffic in automateyournetwork/netclaw) into .claude/skills/kubeshark-traffic in your project. Claude Code loads it when a task matches its description.

How do I install Kubeshark Traffic in Codex?

Run `npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a codex`. Or copy the skill folder (workspace/skills/kubeshark-traffic in automateyournetwork/netclaw) into .agents/skills/kubeshark-traffic in your project. Codex loads it when a task matches its description.

Can I use Kubeshark Traffic in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubeshark-traffic, .gemini/skills/kubeshark-traffic, .github/skills/kubeshark-traffic and .opencode/skills/kubeshark-traffic in your project.

What does Kubeshark Traffic need to run?

Going by SKILL.md and its folder, Kubeshark Traffic needs the command-line tools its instructions call (kubectl and helm).

Does Kubeshark Traffic access the network?

SKILL.md names 2 domains. As links in the text: github.com and docs.kubeshark.com. This is read from the text; nothing was executed.

Is Kubeshark Traffic safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kubeshark Traffic use?

Kubeshark Traffic is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kubeshark Traffic use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kubeshark Traffic?

Skills that share tags, products or a category with Kubeshark Traffic: K8s Agent Sandbox MCP (kubernetes-sigs/agent-sandbox, 4.2k stars), Apex Azure Diagnostics (jonathan-vella/apex, 217 stars), Eks Best Practices (aws-samples/appmod-blueprints, 115 stars) and Ksail (devantler-tech/ksail, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kubeshark Traffic?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.