Agent skill

Network Data Analysis

by automateyournetwork in automateyournetwork/netclaw

Ad-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB.

Apache-2.0Auto-check: notesData & Analytics

Install Network Data Analysis

skills CLI
$ npx skills add automateyournetwork/netclaw --skill network-data-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw network-data-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/network-data-analysis .claude/skills/network-data-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
network-data-analysis
GitHub stars
675
Token cost
~1.3k tokens
SKILL.md length
554 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Ad-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB.

  • Works in 4 steps: Produce the data first. nsm_analyze… → analysis_status — is the sandbox locked,… → analysis_datasets — table names, row… → …
  • Aggregating across a packet captures sessions
  • SKILL.md covers MCP Server, What this reads, and what it…, Workflow: analyse a capture and The pivot that makes this…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Network Data Analysis is an agent skill from automateyournetwork/netclaw. Ad-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB. Use when aggregating across a packet capture's sessions, correlating IDS alerts with connection metadata, or answering counting and grouping questions that a per-log view cannot

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Data & Analytics, covering Data analysis and SQL. It works with SQL, DuckDB and Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Aggregating across a packet captures sessions
  • Correlating IDS alerts with connection metadata
  • Answering counting and grouping questions that a per-log view cannot

Example prompts

  • “/network-data-analysis”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Produce the data first. nsm_analyze (skill nsm-session-pivot) writes Zeek logs and
  2. analysis_status — is the sandbox locked, how many datasets loaded, what are the caps?
  3. analysis_datasets — table names, row counts, columns. **Read the columns before writing
  4. analysis_query — one read statement per call.

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Network Data Analysis loads about 1.3k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 554 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:25
    and `.env`. A generic SQL surface over those would be a backdoor, not an analysis tool.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 554 words, ~1,328 tokens.

Download SKILL.mdSave it as .claude/skills/network-data-analysis/SKILL.md (or your agent's skills folder).
name
network-data-analysis
description
Ad-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB. Use when aggregating across a packet capture's sessions, correlating IDS alerts with connection metadata, or answering counting and grouping questions that a per-log view cannot
version
1.0.0
license
Apache-2.0
tags
analysis, sql, duckdb, zeek, suricata, forensics, read-only

Network Data Analysis (read-only SQL)

MCP Server

  • Server: analysis-mcp (NetClaw-authored, spec 092)
  • Tools: analysis_status, analysis_datasets, analysis_query
  • Engine: DuckDB, in-memory, sandboxed and locked

What this reads, and what it can never read

Loads files from an allowlist of roots — ~/.openclaw/nsm/runs (Zeek/Suricata output from nsm-mcp), the workspace output directory, and ~/.openclaw/analysis for your own exports.

NetClaw's own stores are permanently unreachable: ~/.openclaw/memory/, ~/.openclaw/rag/, ~/.openclaw/n2n/ and ~/.openclaw/gait/, plus .ssh, .aws, .kube and .env. A generic SQL surface over those would be a backdoor, not an analysis tool.

That is not enforced by pattern matching. Datasets are materialised, then DuckDB's own enable_external_access=false and lock_configuration=true close every filesystem and network path irreversibly for the life of the process. Verified: read_csv('/etc/passwd'), glob('/home/**'), ATTACH of the memory or RAG stores, COPY … TO, INSTALL/LOAD, and re-enabling access all raise.

If you need a file analysed, put it under ~/.openclaw/analysis — do not try to reach it in SQL, because you cannot.

Workflow: analyse a capture

  1. Produce the data first. nsm_analyze (skill nsm-session-pivot) writes Zeek logs and Suricata eve.json. Without a run, this surface has nothing to read and says so.
  2. analysis_status — is the sandbox locked, how many datasets loaded, what are the caps?
  3. analysis_datasets — table names, row counts, columns. Read the columns before writing SQL; guessing column names wastes a round trip.
  4. analysis_query — one read statement per call.

Zeek tables carry their real column names (id_orig_h, id_resp_p, uid), lifted from the log's #fields header. Without that they would be column0…columnN and unusable.

The pivot that makes this worth using

Every Zeek log shares uid with conn.log, so a join is the session pivot — and unlike walking logs one at a time, it aggregates:

sql
SELECT c.id_orig_h, c.id_resp_h, c.service, h.method, h.host, h.uri
FROM zeek_<run>_conn c
LEFT JOIN zeek_<run>_http h USING (uid)
ORDER BY c.ts

Counting questions a per-log view cannot answer:

sql
-- top talkers by connection count
SELECT id_orig_h, count(*) AS conns FROM zeek_<run>_conn
GROUP BY 1 ORDER BY conns DESC LIMIT 20

-- which services appeared at all
SELECT service, count(*) FROM zeek_<run>_conn GROUP BY 1 ORDER BY 2 DESC

-- Suricata alert signatures by frequency
SELECT json_extract_string(alert, '$.signature') AS sig, count(*)
FROM suricata_<run>_eve WHERE event_type = 'alert' GROUP BY 1 ORDER BY 2 DESC
Show full SKILL.md (269 more words)Show less

Reading results honestly

  • truncated: true means you are looking at a page. Never present a capped result as a total — run COUNT(*) for the real number. The tool reports this in gaps.
  • Zeek columns are all text. Datasets load as varchar so a malformed field cannot abort the load; cast explicitly (CAST(duration AS DOUBLE)) and say that you did.
  • A row count reflects what was LOADED, not what existed. Files above the size cap are skipped and listed in notes; a per-table row cap applies. Check analysis_status before claiming completeness.
  • 0 datasets means no exports exist, never "the network was quiet."
  • This inherits every caveat of its source. A Zeek run made with checksum validation on may be missing whole protocol logs (see nsm-session-pivot) — and SQL over an incomplete log is confidently wrong. Check the posture of the run you are querying.

Important Rules

  • Read-only. INSERT/UPDATE/DELETE/DROP/CREATE/ATTACH/COPY/INSTALL/SET are refused, and independently impossible after lockdown.
  • One statement per call. A stacked second statement is refused.
  • Queries time out (default 30s) and are interrupted, not left running.
  • Record in GAIT — log the query and the dataset it ran against, not just the answer.

Integration with Other Skills

SkillHow They Work Together
nsm-session-pivotProduces the Zeek logs this queries; use it for single-session detail
nsm-ids-triageProduces eve.json; use SQL here to aggregate alerts across a capture
packet-analysisDrop to individual packet decode once SQL narrows the field
document-generationTurn a query result into a report table
gait-session-trackingRecord all analysis runs

Environment Variables

  • ANALYSIS_QUERY_TIMEOUT — per-query seconds (default 30)
  • ANALYSIS_MAX_RESULT_ROWS — result cap (default 500)
  • ANALYSIS_EXTRA_ROOTS — extra allowlisted roots, os.pathsep-separated
  • ANALYSIS_MAX_FILE_BYTES / ANALYSIS_MAX_ROWS — load caps

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/network-data-analysis of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Network Data Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Network Data Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Network Data Analysis this skillautomateyournetwork/netclaw675—~1.3kAutomated safety check: NotesApache-2.0
Dinobase Business Data Querieskappa90/dinobase263—~1.5kAutomated safety check: PassCustom licence
Semantic Analystsidequery/sidemantic129—~982Automated safety check: PassAGPL-3.0
Excel and CSV Data Analysisbytedance/deer-flow83k4 repos~2.2kAutomated safety check: PassMIT
Find Hypertable Candidatestimescale/pg-aiguide1.9k1 repos~2.6kAutomated safety check: PassApache-2.0
SlKaelio/ktx1.6k—~2.7kAutomated safety check: PassApache-2.0

Similar skills

  • Sets up Dinobase, a local DuckDB database that syncs data from 100+ business sources, then answers questions across them with SQL joins and previewed write-backs.

    263 GitHub stars~1.5k tokensUpdated 3 mo ago
    Data & AnalyticsAuto-check passed
  • Semantic Analyst

    sidequery/sidemantic

    Answer analytical, KPI, metric, trend, cohort, and business-performance questions through a Sidemantic semantic layer.

    129 GitHub stars~982 tokensUpdated today
    DatabasesAuto-check passed
  • Excel and CSV Data Analysis

    bytedance/deer-flow

    Analyzes uploaded Excel and CSV files with SQL through DuckDB, producing schema inspections, statistical summaries and exports to CSV, JSON or Markdown.

    83k GitHub starsUsed in 4 repos~2.2k tokens
    Data & AnalyticsAuto-check passed
  • Find Hypertable Candidates

    timescale/pg-aiguide

    A skill your agent uses to analyze an existing PostgreSQL database and identify which tables should be converted to Timescale/TimescaleDB hypertables.

    1.9k GitHub starsUsed in 1 repo~2.6k tokens
    Data & AnalyticsAuto-check passed
  • Sl

    Kaelio/ktx

    ktx's semantic layer - a structured catalog of sources (tables/views), measures, joins, and segments expressed as YAML.

    1.6k GitHub stars~2.7k tokensUpdated 27 days ago
    Data & AnalyticsAuto-check passed
  • Modeler

    sidequery/sidemantic

    Build, validate, and manage semantic models using Sidemantic.

    129 GitHub stars~4.2k tokensUpdated today
    DatabasesAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    675 GitHub stars~612 tokensUpdated 2 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    675 GitHub stars~4.2k tokensUpdated 2 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    675 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    675 GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    675 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    675 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed

Questions about Network Data Analysis

What does Network Data Analysis do?

Ad-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB. Network Data Analysis is an agent skill from automateyournetwork/netclaw.json, generated reports) using DuckDB.

When should I use Network Data Analysis?

Network Data Analysis fits situations like: aggregating across a packet captures sessions; correlating IDS alerts with connection metadata; answering counting and grouping questions that a per-log view cannot.

How do I install Network Data Analysis in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill network-data-analysis -a claude-code`. Or copy the skill folder (workspace/skills/network-data-analysis in automateyournetwork/netclaw) into .claude/skills/network-data-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Network Data Analysis in Codex?

Run `npx skills add automateyournetwork/netclaw --skill network-data-analysis -a codex`. Or copy the skill folder (workspace/skills/network-data-analysis in automateyournetwork/netclaw) into .agents/skills/network-data-analysis in your project. Codex loads it when a task matches its description.

Can I use Network Data Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill network-data-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/network-data-analysis, .gemini/skills/network-data-analysis, .github/skills/network-data-analysis and .opencode/skills/network-data-analysis in your project.

What does Network Data Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Network Data Analysis is instructions for the agent only.

Does Network Data Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Network Data Analysis safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Network Data Analysis use?

Network Data Analysis is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Network Data Analysis use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Network Data Analysis?

Skills that share tags, products or a category with Network Data Analysis: Dinobase Business Data Queries (kappa90/dinobase, 263 stars), Semantic Analyst (sidequery/sidemantic, 129 stars), Excel and CSV Data Analysis (bytedance/deer-flow, 83k stars) and Find Hypertable Candidates (timescale/pg-aiguide, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Network Data Analysis?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 675 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.