K8s Agent Sandbox MCP
kubernetes-sigs/agent-sandbox
An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.
Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools).
$ npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw kubeshark-traffic --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/kubeshark-traffic .claude/skills/kubeshark-traffic && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kubeshark-traffic" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/kubeshark-traffic into .claude/skills/kubeshark-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubeshark-traffic", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/kubeshark-trafficType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw kubeshark-traffic --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/kubeshark-traffic .agents/skills/kubeshark-traffic && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kubeshark-traffic" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/kubeshark-traffic into .agents/skills/kubeshark-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubeshark-traffic", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw kubeshark-traffic --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/kubeshark-traffic .cursor/skills/kubeshark-traffic && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kubeshark-traffic" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/kubeshark-traffic into .cursor/skills/kubeshark-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubeshark-traffic", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/kubeshark-traffic--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw kubeshark-traffic --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/kubeshark-traffic .gemini/skills/kubeshark-traffic && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kubeshark-traffic" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/kubeshark-traffic into .gemini/skills/kubeshark-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubeshark-traffic", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw kubeshark-trafficInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/kubeshark-traffic .github/skills/kubeshark-traffic && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kubeshark-traffic" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/kubeshark-traffic into .github/skills/kubeshark-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubeshark-traffic", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw kubeshark-traffic --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/kubeshark-traffic .opencode/skills/kubeshark-traffic && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kubeshark-traffic" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/kubeshark-traffic into .opencode/skills/kubeshark-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kubeshark-traffic", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kubeshark-trafficKubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools).
Kubeshark Traffic is an agent skill from automateyournetwork/netclaw. Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools). Use when capturing Kubernetes pod traffic, debugging service-to-service latency, exporting pcaps from a cluster, or analyzing encrypted east-west traffic
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes and Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlhelmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comdocs.kubeshark.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Kubeshark Traffic loads about 2k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 680 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 680 words, ~1,967 tokens.
.claude/skills/kubeshark-traffic/SKILL.md (or your agent's skills folder).| Property | Value |
|---|---|
| Source | kubeshark/kubeshark — MCP docs |
| Transport | Remote HTTP (JSON-RPC 2.0, default port 8898) |
| Language | Go (built into Kubeshark Hub) |
| Tools | 6 (capture, export pcap, snapshot, filter, L4 flows, flow summary) |
| Auth | None (cluster-internal); requires kubectl port-forward for remote access |
| Requires | Kubernetes cluster with Kubeshark installed via Helm |
# Install Kubeshark with MCP enabled
helm install kubeshark kubeshark/kubeshark \
--set mcp.enabled=true \
--set mcp.port=8898
# Port-forward for local access (if not in-cluster)
kubectl port-forward svc/kubeshark-hub 8898:8898
# MCP endpoint is now available at:
# http://localhost:8898/mcp| Variable | Required | Example | Description |
|---|---|---|---|
KUBESHARK_MCP_URL | Yes | http://localhost:8898/mcp | Kubeshark MCP endpoint URL |
KUBESHARK_MCP_PORT | No | 8898 | MCP server port (default: 8898) |
| Tool | Parameters | What It Does |
|---|---|---|
capture_traffic | filter?, duration? | Start targeted packet capture across cluster pods |
export_pcap | filter?, time_range? | Export captured traffic as pcap for Wireshark/tshark analysis |
create_snapshot | filter? | Create point-in-time traffic snapshot within retention window |
apply_filter | kfl_expression | Apply Kubeshark Filter Language (KFL) expressions to narrow results |
list_l4_flows | filter? | List TCP/UDP flows with connection stats, RTT metrics, byte counts |
get_l4_flow_summary | filter? | High-level summary: top talkers, protocol distribution, traffic volume |
When investigating connectivity or latency issues between Kubernetes services:
capture_traffic(filter="src.pod.name == 'frontend'") — start targeted capturelist_l4_flows — see all TCP/UDP connections with RTT and statsget_l4_flow_summary — identify top talkers and protocol breakdownapply_filter(kfl_expression="response.status >= 500") — isolate errorsexport_pcap(filter="dst.pod.name == 'api-gateway'") — export for deep analysispacket-analysis skill to analyze exported pcap with tsharkcapture_traffic(filter="dst.pod.name == 'api-gateway'", duration="5m")
list_l4_flows(filter="dst.pod.name == 'api-gateway'")
get_l4_flow_summary(filter="dst.pod.name == 'api-gateway'")
apply_filter(kfl_expression="response.latency > 500ms")
export_pcap(filter="response.latency > 500ms")When investigating encrypted service-to-service communication:
capture_traffic — Kubeshark automatically decrypts TLS via eBPFapply_filter(kfl_expression="request.headers['content-type'] == 'application/grpc'") — isolate gRPClist_l4_flows — see encrypted connections with decrypted payload summariesexport_pcap — export decrypted traffic for offline analysisWhen performing post-incident traffic analysis:
create_snapshot — capture current traffic stateapply_filter with time range — find traffic around incident timelist_l4_flows — identify unusual connections or traffic spikesget_l4_flow_summary — find services with abnormal traffic volumeexport_pcap — preserve traffic for incident report| Skill | Integration |
|---|---|
| packet-analysis | Export Kubeshark pcaps → analyze with Packet Buddy tshark (deeper protocol dissection) |
| prometheus-monitoring | Correlate Kubeshark flow metrics with Prometheus time-series data |
| grafana-observability | Cross-reference Kubeshark traffic patterns with Grafana dashboards and alerts |
| pyats-health-check | Compare Kubernetes network traffic with underlying infrastructure health |
| gait-session-tracking | Record all Kubeshark captures, exports, and analysis in GAIT audit trail |
| servicenow-change-workflow | Reference Kubeshark traffic captures as evidence in change requests or incidents |
# Filter by pod name
src.pod.name == "frontend"
# Filter by namespace
dst.namespace == "production"
# HTTP status codes
response.status >= 400
# Latency threshold
response.latency > 200ms
# Protocol type
protocol == "grpc"
# Combined filters
src.namespace == "default" and response.status >= 500 and response.latency > 1s
# DNS queries
protocol == "dns" and request.query contains "api.internal"
# Kafka messages
protocol == "kafka" and request.topic == "orders"kubectl port-forward svc/kubeshark-hub 8898:8898 when not in-clusterkubectl get pods -n kubeshark) and port-forward is active.mcp.enabled=true in Helm values; verify MCP port matches KUBESHARK_MCP_URL.© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/kubeshark-traffic of automateyournetwork/netclaw.
Open the folder on GitHubat commit aa90e7d
Kubeshark Traffic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kubeshark Traffic this skillautomateyournetwork/netclaw | 676 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| K8s Agent Sandbox MCPkubernetes-sigs/agent-sandbox | 4.2k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Apex Azure Diagnosticsjonathan-vella/apex | 217 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Eks Best Practicesaws-samples/appmod-blueprints | 115 | — | ~5k | Automated safety check: Pass | MIT-0 | |
| Ksaildevantler-tech/ksail | 165 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Azure Kubernetes Automatic Readinessmicrosoft/GitHub-Copilot-for-Azure | 255 | 1 repos | ~4.4k | Automated safety check: Pass | MIT |
kubernetes-sigs/agent-sandbox
An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.
jonathan-vella/apex
WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.
aws-samples/appmod-blueprints
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
devantler-tech/ksail
Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.
microsoft/GitHub-Copilot-for-Azure
Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.
fluxcd/agent-skills
Debug and troubleshoot Flux CD on live Kubernetes clusters (not local repo files) via the Flux MCP server — inspects Flux resource status, reads controller logs, traces dependency chains, and…
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
Works with
Categories
Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools). Kubeshark Traffic is an agent skill from automateyournetwork/netclaw. Kubeshark Kubernetes traffic analysis — L4/L7 deep packet inspection, TLS decryption, pcap export, flow analysis, service mapping (6 tools).
Kubeshark Traffic fits situations like: capturing Kubernetes pod traffic; debugging service-to-service latency; exporting pcaps from a cluster; analyzing encrypted east-west traffic.
Run `npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a claude-code`. Or copy the skill folder (workspace/skills/kubeshark-traffic in automateyournetwork/netclaw) into .claude/skills/kubeshark-traffic in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a codex`. Or copy the skill folder (workspace/skills/kubeshark-traffic in automateyournetwork/netclaw) into .agents/skills/kubeshark-traffic in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill kubeshark-traffic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kubeshark-traffic, .gemini/skills/kubeshark-traffic, .github/skills/kubeshark-traffic and .opencode/skills/kubeshark-traffic in your project.
Going by SKILL.md and its folder, Kubeshark Traffic needs the command-line tools its instructions call (kubectl and helm).
SKILL.md names 2 domains. As links in the text: github.com and docs.kubeshark.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Kubeshark Traffic is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Kubeshark Traffic: K8s Agent Sandbox MCP (kubernetes-sigs/agent-sandbox, 4.2k stars), Apex Azure Diagnostics (jonathan-vella/apex, 217 stars), Eks Best Practices (aws-samples/appmod-blueprints, 115 stars) and Ksail (devantler-tech/ksail, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.