Kubernetes Network Security Audit
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks.
$ npx skills add automateyournetwork/netclaw --skill pyats-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw pyats-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/pyats-security .claude/skills/pyats-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pyats-security" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/pyats-security into .claude/skills/pyats-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyats-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/pyats-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill pyats-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw pyats-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/pyats-security .agents/skills/pyats-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pyats-security" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/pyats-security into .agents/skills/pyats-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyats-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill pyats-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw pyats-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/pyats-security .cursor/skills/pyats-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pyats-security" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/pyats-security into .cursor/skills/pyats-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyats-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/pyats-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill pyats-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw pyats-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/pyats-security .gemini/skills/pyats-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pyats-security" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/pyats-security into .gemini/skills/pyats-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyats-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw pyats-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill pyats-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/pyats-security .github/skills/pyats-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pyats-security" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/pyats-security into .github/skills/pyats-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyats-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill pyats-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw pyats-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/pyats-security .opencode/skills/pyats-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pyats-security" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/pyats-security into .opencode/skills/pyats-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyats-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pyats-securityNetwork security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks.
Pyats Security is an agent skill from automateyournetwork/netclaw. Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks. Use when auditing device security posture, checking compliance, hardening a router or switch, reviewing access lists, or investigating unauthorized access.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Network security. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ISE_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pyats Security loads about 2.7k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 1,021 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 1,021 words, ~2,710 tokens.
.claude/skills/pyats-security/SKILL.md (or your agent's skills folder).Always start by capturing the full running config for analysis:
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_show_running_config '{"device_name":"R1"}'Scan the full config for the checks below.
Check these items in the running config:
| Check | What to Look For | Finding If Missing |
|---|---|---|
| SSH version | ip ssh version 2 | CRITICAL: SSHv1 vulnerable to MITM |
| Telnet disabled | No transport input telnet on VTY lines | CRITICAL: Telnet sends cleartext credentials |
| VTY ACL | access-class on VTY lines | HIGH: Unrestricted management access |
| Console timeout | exec-timeout on console (not 0 0) | MEDIUM: Unattended console sessions |
| VTY timeout | exec-timeout on VTY lines (not 0 0) | MEDIUM: Stale management sessions |
| Password encryption | service password-encryption | MEDIUM: Type 0 passwords visible |
| Enable secret | enable secret (not enable password) | HIGH: Enable password uses weak hash |
| Login banner | banner login or banner motd | LOW: Legal/compliance requirement |
| HTTP server disabled | no ip http server | MEDIUM: Unnecessary attack surface |
| HTTPS server | ip http secure-server if web management needed | MEDIUM: Use HTTPS not HTTP |
| Aux port disabled | no exec on aux line | LOW: Unused port open |
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show aaa servers"}'AAA checks in running config:
aaa new-model enabledaaa authentication login configured (not just local)aaa authorization exec configuredaaa accounting configured for commands and connectionsaaa authentication enable uses enable secret not enable passwordPYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show ip access-lists"}'ACL analysis:
permit ip any any)deny ip any any log)Check in running config for:
control-plane section with service-policyPYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show policy-map control-plane"}'OSPF authentication:
ip ospf authentication message-digest on interfacesarea X authentication message-digestip ospf message-digest-key is configuredBGP security:
neighbor X password (MD5 authentication)neighbor X ttl-security hops N (GTSM — Generalized TTL Security Mechanism)neighbor X prefix-list or neighbor X maximum-prefix (prefix limits)EIGRP authentication:
af-interface with authentication mode md5 and authentication key-chainip authentication mode eigrp and ip authentication key-chain eigrpCheck in running config:
| Feature | Config | Purpose |
|---|---|---|
| uRPF | ip verify unicast source reachable-via rx | Anti-spoofing |
| TCP keepalives | service tcp-keepalives-in, service tcp-keepalives-out | Dead session cleanup |
| CDP restricted | no cdp enable on external interfaces | Information leak prevention |
| LLDP restricted | no lldp transmit / no lldp receive on external | Information leak prevention |
| IP source routing disabled | no ip source-route | Prevent source-routed attacks |
| Directed broadcast disabled | no ip directed-broadcast per interface | Smurf attack prevention |
| ICMP redirects disabled | no ip redirects per interface | MITM prevention |
| Proxy ARP disabled | no ip proxy-arp on external interfaces | ARP spoofing prevention |
| Gratuitous ARP | no ip gratuitous-arps | ARP cache poisoning prevention |
| IP unreachables limited | no ip unreachables on external | Reconnaissance prevention |
| Timestamps | service timestamps log datetime msec localtime | Forensics |
| Logging buffer | logging buffered with adequate size | Event capture |
| Remote logging | logging host X.X.X.X | Centralized log collection |
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show crypto key mypubkey rsa"}'Check:
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show snmp"}'Checks:
Device: R1 | IOS-XE 17.x.x
Security Audit Date: YYYY-MM-DD
CRITICAL FINDINGS (Fix Immediately):
1. [C-001] SSHv1 enabled — upgrade to SSH version 2 only
2. [C-002] No VTY access-class — management plane exposed
HIGH FINDINGS (Fix This Week):
3. [H-001] No OSPF authentication on Gi1 — route injection risk
4. [H-002] SNMP community 'public' with no ACL
MEDIUM FINDINGS (Fix This Month):
5. [M-001] No CoPP policy — CPU vulnerable to floods
6. [M-002] HTTP server enabled — disable or restrict
LOW / INFORMATIONAL:
7. [L-001] No login banner configured
8. [I-001] CDP enabled globally (acceptable on internal interfaces)
Summary: 2 Critical | 2 High | 2 Medium | 2 LowWhen ISE is available ($ISE_MCP_SCRIPT is set), extend the security audit with identity verification:
Check that the device is registered in ISE as a Network Access Device:
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" network_devices '{}'Flags:
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" active_sessions '{}'Filter sessions for this device's IP to see authenticated endpoints.
After Step 1 (show version), extract the IOS-XE version and scan for known vulnerabilities:
python3 $MCP_CALL "npx -y nvd-cve-mcp-server" search_cves '{"keyword":"Cisco IOS XE 17.9.4","resultsPerPage":10}'For each CVE found:
ip http server is configured)Severity mapping:
Run the full 9-step audit on ALL devices simultaneously using multiple exec commands. Aggregate findings across the fleet and sort by severity for prioritized remediation.
Record the security audit in GAIT:
python3 $MCP_CALL "python3 -u $GAIT_MCP_SCRIPT" gait_record_turn '{"user_text":"Example only: replace with the actual authorized request.","assistant_text":"Security audit on R1: 2 CRITICAL (no enable secret, telnet enabled), 2 HIGH, 2 MEDIUM, 2 LOW findings.","artifacts":[]}'GAIT_MCP_SCRIPT, ISE_MCP_SCRIPT, ISE_PASSWORD, ISE_USERNAME, PYATS_MCP_SCRIPT, PYATS_TESTBED_PATH are set and valid before assuming a data or device problem.Audit examples are illustrative. Replace request, outcomes, identifiers and counts
with observed session evidence; do not record these example results as facts.
Inspect MCP isError, returned ok, and the recorded turn with gait_show when
validating a new client/schema. Follow gait-session-tracking for branch checkout.
© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/pyats-security of automateyournetwork/netclaw.
Open the folder on GitHubat commit 95bb17e
Pyats Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pyats Security this skillautomateyournetwork/netclaw | 676 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Wireshark Analysiszebbern/claude-code-guide | 4.7k | 8 repos | ~3k | Automated safety check: Pass | MIT | |
| IotnetBrownFineSecurity/iothackbot | 859 | 1 repos | ~1k | Automated safety check: Notes | MIT | |
| mTLS Configurationwshobson/agents | 40k | 9 repos | ~588 | Automated safety check: Pass | MIT | |
| Netzhinkgit/embeddedskills | 734 | — | ~1.1k | Automated safety check: Pass | MIT |
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
zebbern/claude-code-guide
This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…
BrownFineSecurity/iothackbot
IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.
wshobson/agents
Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging.
zhinkgit/embeddedskills
嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills.
sickn33/agentic-awesome-skills
Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills.
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
Categories
Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks. Pyats Security is an agent skill from automateyournetwork/netclaw. Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks.
Pyats Security fits situations like: auditing device security posture; checking compliance; hardening a router; reviewing access lists.
Run `npx skills add automateyournetwork/netclaw --skill pyats-security -a claude-code`. Or copy the skill folder (workspace/skills/pyats-security in automateyournetwork/netclaw) into .claude/skills/pyats-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill pyats-security -a codex`. Or copy the skill folder (workspace/skills/pyats-security in automateyournetwork/netclaw) into .agents/skills/pyats-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill pyats-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pyats-security, .gemini/skills/pyats-security, .github/skills/pyats-security and .opencode/skills/pyats-security in your project.
Going by SKILL.md and its folder, Pyats Security needs the command-line tools its instructions call (python3) and credentials named ISE_PASSWORD. Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pyats Security is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pyats Security: Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Wireshark Analysis (zebbern/claude-code-guide, 4.7k stars), Iotnet (BrownFineSecurity/iothackbot, 859 stars) and mTLS Configuration (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.