Agent skill

Protocol Participation

by automateyournetwork in automateyournetwork/netclaw

Live BGP and OSPF control-plane participation — NetClaw itself acts as a protocol speaker: peer with real routers, inject/withdraw routes, query its own RIB/LSDB, adjust metrics, GRE tunnel status.

Apache-2.0Auto-check: notes

Install Protocol Participation

skills CLI
$ npx skills add automateyournetwork/netclaw --skill protocol-participation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw protocol-participation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/protocol-participation .claude/skills/protocol-participation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
protocol-participation
GitHub stars
676
Token cost
~2.4k tokens
SKILL.md length
781 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Live BGP and OSPF control-plane participation — NetClaw itself acts as a protocol speaker: peer with real routers, inject/withdraw routes, query its own RIB/LSDB, adjust metrics, GRE tunnel status.

  • Works in 6 steps: Route Injection with Change Control → Traffic Engineering via LOCAL_PREF → OSPF Cost Manipulation → …
  • Withdrawing BGP routes
  • SKILL.md covers MCP Server, Tools, Environment Variables and FRR Lab Testbed, plus 5 more sections
  • Calls bash and docker

What it does

Protocol Participation is an agent skill from automateyournetwork/netclaw. Live BGP and OSPF control-plane participation — NetClaw itself acts as a protocol speaker: peer with real routers, inject/withdraw routes, query its own RIB/LSDB, adjust metrics, GRE tunnel status. Use when injecting or withdrawing BGP routes, checking the state of NetClaw's own BGP peering, querying its own OSPF LSDB, or testing route advertisement in a lab. This does not query an existing device's routing table — for that, use pyats-routing (Cisco) or pyats-junos-routing (Juniper) instead.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Withdrawing BGP routes
  • Checking the state of NetClaws own BGP peering
  • Querying its own OSPF LSDB
  • Testing route advertisement in a lab

Example prompts

  • “/protocol-participation”

Requirements

  • Docker

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Route Injection with Change Control
  2. Traffic Engineering via LOCAL_PREF
  3. OSPF Cost Manipulation
  4. Protocol Health Check
  5. Controlled Route Withdrawal
  6. Lab Testing (no CR required)

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Protocol Participation loads about 2.4k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 781 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:168
    sudo bash scripts/setup-gre.sh

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 781 words, ~2,449 tokens.

Download SKILL.mdSave it as .claude/skills/protocol-participation/SKILL.md (or your agent's skills folder).
name
protocol-participation
description
Live BGP and OSPF control-plane participation — NetClaw itself acts as a protocol speaker: peer with real routers, inject/withdraw routes, query its own RIB/LSDB, adjust metrics, GRE tunnel status. Use when injecting or withdrawing BGP routes, checking the state of NetClaw's own BGP peering, querying its own OSPF LSDB, or testing route advertisement in a lab. This does not query an existing device's routing table — for that, use `pyats-routing` (Cisco) or `pyats-junos-routing` (Juniper) instead.
license
Apache-2.0
user-invocable
true

Protocol Participation — BGP + OSPF + GRE

MCP Server

PropertyValue
SourceWontYouBeMyNeighbour BGP/OSPFv3/GRE modules
Transportstdio
Tools10
Protocol modulesBGP (20 files), OSPFv3 (8 files), GRE (4 files), Connectors (2 files)
Dependenciesscapy, networkx, mcp, fastmcp

Tools

BGP Tools
bgp_get_peers

List BGP peer sessions with state, AS, IP, uptime, and prefix counts.

ParameterTypeDefaultDescription
(none)——No parameters

Returns: { peers: [{peer, peer_as, state, local_addr, is_ibgp, uptime, prefixes_received, prefixes_sent}], count }

bgp_get_rib

Query the Loc-RIB (best routes). Optionally filter by prefix.

ParameterTypeDefaultDescription
prefixstringnullOptional CIDR filter (e.g. 10.0.0.0/24)

Returns: { routes: [{network, next_hop, as_path, local_pref, med, origin, communities}], count }

bgp_inject_route

Inject a route into the BGP RIB and advertise to peers.

ParameterTypeDefaultDescription
networkstringrequiredCIDR prefix (e.g. 192.168.1.0/24)
next_hopstringnullNext-hop IP (defaults to self)
as_pathstringnullComma-separated AS path (e.g. 65001,65002)
local_prefint100LOCAL_PREF value

Returns: { success, network, route_info }

bgp_withdraw_route

Withdraw a route from the BGP RIB and send withdrawal to peers.

ParameterTypeDefaultDescription
networkstringrequiredCIDR prefix to withdraw

Returns: { success, network }

bgp_adjust_local_pref

Change the LOCAL_PREF for a route in the RIB.

ParameterTypeDefaultDescription
networkstringrequiredCIDR prefix
local_prefintrequiredNew LOCAL_PREF (higher = more preferred)

Returns: { success, network, old_local_pref, new_local_pref }

OSPF Tools
ospf_get_neighbors

List OSPF neighbors with state, address, priority, and router ID.

ParameterTypeDefaultDescription
(none)——No parameters

Returns: { neighbors: [{neighbor_id, state, address, priority}], count }

ospf_get_lsdb

Query the OSPF Link State Database.

ParameterTypeDefaultDescription
(none)——No parameters

Returns: { lsdb: [{type, advertising_router, ls_id, sequence, age}], count }

ospf_adjust_cost

Change the OSPF cost on an interface.

ParameterTypeDefaultDescription
interfacestringrequiredInterface name (e.g. gre-netclaw)
costintrequiredNew OSPF cost (1-65535)

Returns: { success, interface, old_cost, new_cost }

GRE Tools
gre_tunnel_status

Check GRE tunnel status via system commands (ip tunnel show, ip addr show).

ParameterTypeDefaultDescription
(none)——No parameters

Returns: { tunnels: [...], addresses: [...], count }

Meta Tools
protocol_summary

Consolidated BGP + OSPF + GRE state summary in a single call.

ParameterTypeDefaultDescription
(none)——No parameters

Returns: { router_id, local_as, lab_mode, bgp: {configured, peer_count, peers, rib_size}, ospf: {configured, neighbor_count, neighbors}, gre: {tunnels, addresses, count} }


Environment Variables

VariableExampleDescription
NETCLAW_ROUTER_ID4.4.4.4BGP/OSPF router ID
NETCLAW_LOCAL_AS65001BGP local autonomous system number
NETCLAW_BGP_PEERS[{"ip":"172.16.0.1","as":65000}]JSON array of BGP peers
NETCLAW_OSPF_AREAS["0.0.0.0"]JSON array of OSPF area IDs
NETCLAW_GRE_TUNNELS[{"name":"gre-netclaw","local":"...","remote":"..."}]JSON array of GRE tunnels
NETCLAW_LAB_MODEtrueRelaxes CR requirement for lab testing

FRR Lab Testbed

A Docker-based 3-router FRR topology is provided in lab/frr-testbed/ for testing:

NetClaw (AS 65001) ──GRE── Edge1 (AS 65000) ──OSPF── Core (RR) ──OSPF── Edge2
  host/WSL                  1.1.1.1              2.2.2.2           3.3.3.3
  172.16.0.2                172.16.0.1
  eBGP                      iBGP→Core            iBGP hub          iBGP→Core
bash
# Start lab
cd lab/frr-testbed && docker compose up -d

# Create GRE tunnel (requires sudo)
sudo bash scripts/setup-gre.sh

# Verify
bash scripts/verify.sh

Workflows

1. Route Injection with Change Control
servicenow-change-workflow → CR approved
→ bgp_inject_route(network, next_hop, local_pref)
→ bgp_get_rib(prefix) → verify route in table
→ pyats-routing → verify on remote devices
→ gait-session-tracking → record change
2. Traffic Engineering via LOCAL_PREF
bgp_get_rib() → current routes
→ bgp_adjust_local_pref(network, local_pref)
→ bgp_get_peers() → verify advertisement
→ gait-session-tracking
3. OSPF Cost Manipulation
ospf_get_neighbors() → verify adjacencies
→ ospf_adjust_cost(interface, cost)
→ ospf_get_lsdb() → verify LSA update
→ pyats-routing → verify SPF reconvergence
→ gait-session-tracking
4. Protocol Health Check
protocol_summary() → full state snapshot
→ bgp_get_peers() → check all Established
→ ospf_get_neighbors() → check all Full
→ gre_tunnel_status() → check all tunnels up
→ gait-session-tracking
5. Controlled Route Withdrawal
servicenow-change-workflow → CR approved
→ bgp_get_rib(prefix) → verify route exists
→ bgp_withdraw_route(network)
→ bgp_get_rib(prefix) → verify withdrawal
→ pyats-routing → verify removal on peers
→ gait-session-tracking
6. Lab Testing (no CR required)
NETCLAW_LAB_MODE=true
→ bgp_inject_route / bgp_withdraw_route
→ bgp_get_rib → verify
→ ospf_adjust_cost → test convergence
→ protocol_summary → snapshot

Show full SKILL.md (337 more words)Show less

Integration with Other Skills

SkillIntegration
servicenow-change-workflowMUST gate all route inject/withdraw/cost changes in production
gait-session-trackingRecord every protocol mutation in the audit trail
pyats-routingCross-verify protocol state from the device CLI side
uml-diagramGenerate BGP state machines and OSPF area diagrams
markmap-vizVisualise RIB hierarchy and OSPF LSDB as mind maps
netbox-reconcileCross-reference peering with NetBox IPAM/circuits
drawio-diagramTopology diagrams showing GRE underlay + BGP/OSPF overlay
cml-topology-builderProvision lab topologies that NetClaw can then peer with

Safety Rules

  1. NEVER inject or withdraw routes without an approved ServiceNow CR — unless NETCLAW_LAB_MODE=true
  2. ALWAYS verify current RIB (bgp_get_rib) before injecting to prevent routing loops
  3. ALWAYS verify peer state (bgp_get_peers) before advertising — only to Established peers
  4. ALWAYS record protocol changes in GAIT (gait-session-tracking)
  5. GRE tunnels require sudo — the install wizard handles initial setup; runtime queries via gre_tunnel_status do not require elevated privileges
  6. Lab mode (NETCLAW_LAB_MODE=true) relaxes the CR requirement for the FRR testbed — never set this in production

Guardrails

  • Route mutations are gated — ServiceNow CR approval required in production
  • Read operations are always safe — bgp_get_peers, bgp_get_rib, ospf_get_neighbors, ospf_get_lsdb, gre_tunnel_status, protocol_summary
  • GRE is the default tunnel transport — native Linux kernel support, every major vendor supports it (Cisco, Juniper, Arista, FRR, Nokia), RFC 2784/2890 compliant
  • Raw sockets require root for protocol speakers — BGP (TCP/179), OSPF (IP/89), GRE (IP/47)
  • No secrets in protocol state — RIB/LSDB queries return routing information, not credentials

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that NETCLAW_ROUTER_ID is set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/protocol-participation of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Protocol Participation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Protocol Participation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Protocol Participation this skillautomateyournetwork/netclaw676—~2.4kAutomated safety check: NotesApache-2.0
Planejeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: PassMIT
Network Bgp Diagnosticsaffaan-m/ECC276k1 repos~1.4kAutomated safety check: PassMIT
Nasiko Control Planeaffaan-m/ECC276k1 repos~660Automated safety check: PassMIT
Implementing Bgp Security With Rpkimukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: NotesApache-2.0
Azure Bgpbenchflow-ai/skillsbench1.8k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Plane

    jeremylongshore/tons-of-skills-marketplace

    Plane is a team behavior observatory — synthesize Plane API data into observations about how teams actually behave under pressure, not just ticket state.

    2.8k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection.

    276k GitHub starsUsed in 1 repo~1.4k tokens
    SecurityAuto-check passed
  • Manage the experimental Nasiko CLI lifecycle through ECC — read-only status checks, consent-gated install of the pinned qualified version with dry-run preview, and ownership-checked uninstall, under…

    276k GitHub starsUsed in 1 repo~660 tokens
    Auto-check passed
  • Implementing Bgp Security With Rpki

    mukul975/Anthropic-Cybersecurity-Skills

    Implement RPKI-based BGP route origin validation by creating Route Origin Authorizations (ROAs) at RIRs (ARIN, RIPE, APNIC, AFRINIC, LACNIC), deploying validator software (Routinator, FORT…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    Marketing & SEOAuto-check: notes
  • Azure Bgp

    benchflow-ai/skillsbench

    Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments).

    1.8k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Builds categorized release notes for a Plane release pull request from its commits and writes them into the PR description, for both the plane-cloud and plane-ee repos.

    61k GitHub stars~2.5k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated 4 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated 4 days ago
    Auto-check passed

Questions about Protocol Participation

What does Protocol Participation do?

Live BGP and OSPF control-plane participation — NetClaw itself acts as a protocol speaker: peer with real routers, inject/withdraw routes, query its own RIB/LSDB, adjust metrics, GRE tunnel status. Protocol Participation is an agent skill from automateyournetwork/netclaw. Live BGP and OSPF control-plane participation — NetClaw itself acts as a protocol speaker: peer with real routers, inject/withdraw routes, query its own RIB/LSDB, adjust metrics, GRE tunnel status.

When should I use Protocol Participation?

Protocol Participation fits situations like: withdrawing BGP routes; checking the state of NetClaws own BGP peering; querying its own OSPF LSDB; testing route advertisement in a lab.

How do I install Protocol Participation in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill protocol-participation -a claude-code`. Or copy the skill folder (workspace/skills/protocol-participation in automateyournetwork/netclaw) into .claude/skills/protocol-participation in your project. Claude Code loads it when a task matches its description.

How do I install Protocol Participation in Codex?

Run `npx skills add automateyournetwork/netclaw --skill protocol-participation -a codex`. Or copy the skill folder (workspace/skills/protocol-participation in automateyournetwork/netclaw) into .agents/skills/protocol-participation in your project. Codex loads it when a task matches its description.

Can I use Protocol Participation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill protocol-participation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/protocol-participation, .gemini/skills/protocol-participation, .github/skills/protocol-participation and .opencode/skills/protocol-participation in your project.

What does Protocol Participation need to run?

Going by SKILL.md and its folder, Protocol Participation needs the command-line tools its instructions call (bash and docker). Our summary lists: Docker.

Does Protocol Participation access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Protocol Participation safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Protocol Participation use?

Protocol Participation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Protocol Participation use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Protocol Participation?

Skills that share tags, products or a category with Protocol Participation: Plane (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Network Bgp Diagnostics (affaan-m/ECC, 276k stars), Nasiko Control Plane (affaan-m/ECC, 276k stars) and Implementing Bgp Security With Rpki (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Protocol Participation?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.