Dinobase Business Data Queries
kappa90/dinobase
Sets up Dinobase, a local DuckDB database that syncs data from 100+ business sources, then answers questions across them with SQL joins and previewed write-backs.
Ad-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB.
$ npx skills add automateyournetwork/netclaw --skill network-data-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw network-data-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/network-data-analysis .claude/skills/network-data-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "network-data-analysis" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/network-data-analysis into .claude/skills/network-data-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "network-data-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/network-data-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill network-data-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw network-data-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/network-data-analysis .agents/skills/network-data-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "network-data-analysis" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/network-data-analysis into .agents/skills/network-data-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "network-data-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill network-data-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw network-data-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/network-data-analysis .cursor/skills/network-data-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "network-data-analysis" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/network-data-analysis into .cursor/skills/network-data-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "network-data-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/network-data-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill network-data-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw network-data-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/network-data-analysis .gemini/skills/network-data-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "network-data-analysis" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/network-data-analysis into .gemini/skills/network-data-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "network-data-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw network-data-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill network-data-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/network-data-analysis .github/skills/network-data-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "network-data-analysis" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/network-data-analysis into .github/skills/network-data-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "network-data-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill network-data-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw network-data-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/network-data-analysis .opencode/skills/network-data-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "network-data-analysis" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/network-data-analysis into .opencode/skills/network-data-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "network-data-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
network-data-analysisAd-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB.
Network Data Analysis is an agent skill from automateyournetwork/netclaw. Ad-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB. Use when aggregating across a packet capture's sessions, correlating IDS alerts with connection metadata, or answering counting and grouping questions that a per-log view cannot
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Data & Analytics, covering Data analysis and SQL. It works with SQL, DuckDB and Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Network Data Analysis loads about 1.3k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 554 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
and `.env`. A generic SQL surface over those would be a backdoor, not an analysis tool.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 554 words, ~1,328 tokens.
.claude/skills/network-data-analysis/SKILL.md (or your agent's skills folder).analysis-mcp (NetClaw-authored, spec 092)analysis_status, analysis_datasets, analysis_queryLoads files from an allowlist of roots — ~/.openclaw/nsm/runs (Zeek/Suricata output
from nsm-mcp), the workspace output directory, and ~/.openclaw/analysis for your own
exports.
NetClaw's own stores are permanently unreachable: ~/.openclaw/memory/,
~/.openclaw/rag/, ~/.openclaw/n2n/ and ~/.openclaw/gait/, plus .ssh, .aws, .kube
and .env. A generic SQL surface over those would be a backdoor, not an analysis tool.
That is not enforced by pattern matching. Datasets are materialised, then DuckDB's own
enable_external_access=false and lock_configuration=true close every filesystem and
network path irreversibly for the life of the process. Verified: read_csv('/etc/passwd'),
glob('/home/**'), ATTACH of the memory or RAG stores, COPY … TO, INSTALL/LOAD, and
re-enabling access all raise.
If you need a file analysed, put it under ~/.openclaw/analysis — do not try to reach it in
SQL, because you cannot.
nsm_analyze (skill nsm-session-pivot) writes Zeek logs and
Suricata eve.json. Without a run, this surface has nothing to read and says so.analysis_status — is the sandbox locked, how many datasets loaded, what are the caps?analysis_datasets — table names, row counts, columns. Read the columns before writing
SQL; guessing column names wastes a round trip.analysis_query — one read statement per call.Zeek tables carry their real column names (id_orig_h, id_resp_p, uid), lifted from
the log's #fields header. Without that they would be column0…columnN and unusable.
Every Zeek log shares uid with conn.log, so a join is the session pivot — and unlike
walking logs one at a time, it aggregates:
SELECT c.id_orig_h, c.id_resp_h, c.service, h.method, h.host, h.uri
FROM zeek_<run>_conn c
LEFT JOIN zeek_<run>_http h USING (uid)
ORDER BY c.tsCounting questions a per-log view cannot answer:
-- top talkers by connection count
SELECT id_orig_h, count(*) AS conns FROM zeek_<run>_conn
GROUP BY 1 ORDER BY conns DESC LIMIT 20
-- which services appeared at all
SELECT service, count(*) FROM zeek_<run>_conn GROUP BY 1 ORDER BY 2 DESC
-- Suricata alert signatures by frequency
SELECT json_extract_string(alert, '$.signature') AS sig, count(*)
FROM suricata_<run>_eve WHERE event_type = 'alert' GROUP BY 1 ORDER BY 2 DESCtruncated: true means you are looking at a page. Never present a capped result as a
total — run COUNT(*) for the real number. The tool reports this in gaps.CAST(duration AS DOUBLE)) and say that you did.notes; a per-table row cap applies. Check analysis_status before
claiming completeness.0 datasets means no exports exist, never "the network was quiet."nsm-session-pivot) — and SQL over an incomplete
log is confidently wrong. Check the posture of the run you are querying.INSERT/UPDATE/DELETE/DROP/CREATE/ATTACH/COPY/INSTALL/SET
are refused, and independently impossible after lockdown.| Skill | How They Work Together |
|---|---|
nsm-session-pivot | Produces the Zeek logs this queries; use it for single-session detail |
nsm-ids-triage | Produces eve.json; use SQL here to aggregate alerts across a capture |
packet-analysis | Drop to individual packet decode once SQL narrows the field |
document-generation | Turn a query result into a report table |
gait-session-tracking | Record all analysis runs |
ANALYSIS_QUERY_TIMEOUT — per-query seconds (default 30)ANALYSIS_MAX_RESULT_ROWS — result cap (default 500)ANALYSIS_EXTRA_ROOTS — extra allowlisted roots, os.pathsep-separatedANALYSIS_MAX_FILE_BYTES / ANALYSIS_MAX_ROWS — load caps© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/network-data-analysis of automateyournetwork/netclaw.
Open the folder on GitHubat commit 95bb17e
Network Data Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Network Data Analysis this skillautomateyournetwork/netclaw | 675 | — | ~1.3k | Automated safety check: Notes | Apache-2.0 | |
| Dinobase Business Data Querieskappa90/dinobase | 263 | — | ~1.5k | Automated safety check: Pass | Custom licence | |
| Semantic Analystsidequery/sidemantic | 129 | — | ~982 | Automated safety check: Pass | AGPL-3.0 | |
| Excel and CSV Data Analysisbytedance/deer-flow | 83k | 4 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Find Hypertable Candidatestimescale/pg-aiguide | 1.9k | 1 repos | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| SlKaelio/ktx | 1.6k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 |
kappa90/dinobase
Sets up Dinobase, a local DuckDB database that syncs data from 100+ business sources, then answers questions across them with SQL joins and previewed write-backs.
sidequery/sidemantic
Answer analytical, KPI, metric, trend, cohort, and business-performance questions through a Sidemantic semantic layer.
bytedance/deer-flow
Analyzes uploaded Excel and CSV files with SQL through DuckDB, producing schema inspections, statistical summaries and exports to CSV, JSON or Markdown.
timescale/pg-aiguide
A skill your agent uses to analyze an existing PostgreSQL database and identify which tables should be converted to Timescale/TimescaleDB hypertables.
Kaelio/ktx
ktx's semantic layer - a structured catalog of sources (tables/views), measures, joins, and segments expressed as YAML.
sidequery/sidemantic
Build, validate, and manage semantic models using Sidemantic.
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
Works with
Categories
Ad-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB. Network Data Analysis is an agent skill from automateyournetwork/netclaw.json, generated reports) using DuckDB.
Network Data Analysis fits situations like: aggregating across a packet captures sessions; correlating IDS alerts with connection metadata; answering counting and grouping questions that a per-log view cannot.
Run `npx skills add automateyournetwork/netclaw --skill network-data-analysis -a claude-code`. Or copy the skill folder (workspace/skills/network-data-analysis in automateyournetwork/netclaw) into .claude/skills/network-data-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill network-data-analysis -a codex`. Or copy the skill folder (workspace/skills/network-data-analysis in automateyournetwork/netclaw) into .agents/skills/network-data-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill network-data-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/network-data-analysis, .gemini/skills/network-data-analysis, .github/skills/network-data-analysis and .opencode/skills/network-data-analysis in your project.
SKILL.md names no scripts, command-line tools or credentials: Network Data Analysis is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Network Data Analysis is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Network Data Analysis: Dinobase Business Data Queries (kappa90/dinobase, 263 stars), Semantic Analyst (sidequery/sidemantic, 129 stars), Excel and CSV Data Analysis (bytedance/deer-flow, 83k stars) and Find Hypertable Candidates (timescale/pg-aiguide, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 675 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.