Agent skill

Radkit Remote Access

by automateyournetwork in automateyournetwork/netclaw

Cisco RADKit — cloud-relayed remote device access, CLI execution, SNMP polling, device inventory discovery, attribute inspection.

Apache-2.0Auto-check passedAgent Workflows

Install Radkit Remote Access

skills CLI
$ npx skills add automateyournetwork/netclaw --skill radkit-remote-access -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw radkit-remote-access --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/radkit-remote-access .claude/skills/radkit-remote-access && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
radkit-remote-access
GitHub stars
676
Token cost
~2.4k tokens
SKILL.md length
1,044 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cisco RADKit — cloud-relayed remote device access, CLI execution, SNMP polling, device inventory discovery, attribute inspection.

  • Works in 4 steps: Inventory: get_device_inventory_names —… → Attributes: get_device_attributes for… → Quick health: snmp_get with sysUpTime… → …
  • Accessing remote network devices through a cloud relay
  • SKILL.md covers MCP Server, How RADKit Works, MCP Tools and Workflow: Remote Device…, plus 7 more sections
  • Calls bash

What it does

Radkit Remote Access is an agent skill from automateyournetwork/netclaw. Cisco RADKit — cloud-relayed remote device access, CLI execution, SNMP polling, device inventory discovery, attribute inspection. Use when accessing remote network devices through a cloud relay, running CLI on air-gapped devices, polling SNMP metrics remotely, or discovering device inventory via RADKit.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Accessing remote network devices through a cloud relay
  • Running CLI on air-gapped devices
  • Polling SNMP metrics remotely
  • Discovering device inventory via RADKit

Example prompts

  • “/radkit-remote-access”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Inventory: get_device_inventory_names — what devices are available?
  2. Attributes: get_device_attributes for each device — type, platform, capabilities
  3. Quick health: snmp_get with sysUpTime (1.3.6.1.2.1.1.3.0) for each device
  4. Report: device inventory table with type, platform, and uptime

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Radkit Remote Access loads about 2.4k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 1,044 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 1,044 words, ~2,364 tokens.

Download SKILL.mdSave it as .claude/skills/radkit-remote-access/SKILL.md (or your agent's skills folder).
name
radkit-remote-access
description
Cisco RADKit — cloud-relayed remote device access, CLI execution, SNMP polling, device inventory discovery, attribute inspection. Use when accessing remote network devices through a cloud relay, running CLI on air-gapped devices, polling SNMP metrics remotely, or discovering device inventory via RADKit.
version
1.0.0
license
Apache-2.0
tags
cisco, radkit, remote-access, cli, snmp, inventory, cloud-relay

RADKit Remote Device Access

MCP Server

  • Repository: CiscoDevNet/radkit-mcp-server-community
  • Transport: stdio (Python via FastMCP), SSE, or HTTPS
  • Requires: RADKIT_IDENTITY, RADKIT_DEFAULT_SERVICE_SERIAL, active RADKit service instance
  • Python: 3.10+

How RADKit Works

RADKit provides a cloud-relayed path to on-premises devices:

NetClaw Agent  -->  RADKit Cloud  -->  RADKit Service (on-prem)  -->  Device (CLI/SNMP)
  • The RADKit Service runs inside the network perimeter, onboarded with access to devices
  • The RADKit Client (this MCP server) authenticates via certificate-based identity
  • All communication is encrypted, relayed through Cisco's RADKit cloud infrastructure
  • No direct SSH/SNMP from the agent host to the devices is needed

This is ideal for:

  • Air-gapped networks where the AI agent cannot directly SSH to devices
  • Cloud-hosted agents that need to reach on-premises devices
  • Multi-site operations where a single RADKit service provides access to many devices
  • Secure environments where certificate-based auth is required (no passwords in transit)

MCP Tools

ToolParametersWhat It Does
get_device_inventory_namesnoneList all onboarded device names from the RADKit service
get_device_attributestarget_deviceRetrieve device details in JSON: host, type, configs, SNMP/NETCONF status, capabilities
exec_cli_commands_in_devicetarget_device, commands, timeout?, max_lines?Execute CLI commands on a device with timeout and line-limit controls
snmp_gettarget_device, oid(s), timeout?Perform SNMP GET operations without CLI execution
exec_commandtarget_device, commandsStructured command execution — returns dict/list with status and truncation info
Tool Details
get_device_inventory_names

Discovers all devices onboarded to the RADKit service. Call this first to know what devices are available.

Returns a set of device names, e.g.: {"edge-rtr-01", "core-sw-01", "dc-fw-01"}

get_device_attributes

Retrieves detailed JSON attributes for a specific device:

  • Name and host address
  • Device type (router, switch, firewall, etc.)
  • Configuration capabilities (SSH, NETCONF, RESTCONF)
  • SNMP status (enabled, community/v3 config)
  • Platform details (model, OS, version)

Safe for parallel execution across multiple devices.

exec_cli_commands_in_device

Executes CLI commands on a device through the RADKit relay:

  • timeout — maximum wait time per command (prevents hung sessions)
  • max_lines — truncate output to N lines (prevents massive output from flooding context)
  • Returns raw CLI output as text

Use this for standard show commands, debug captures, and configuration inspection.

snmp_get

Performs SNMP GET without executing CLI:

  • Query one or more OIDs in a single call
  • Useful for metric polling (uptime, interface counters, CPU utilization)
  • Lower overhead than CLI for structured data retrieval

Common OIDs:

OIDMetric
1.3.6.1.2.1.1.1.0System Description
1.3.6.1.2.1.1.3.0System Uptime
1.3.6.1.2.1.1.5.0System Name
1.3.6.1.2.1.2.2.1.2Interface Description
1.3.6.1.2.1.2.2.1.8Interface Operational Status
exec_command

Structured command execution that returns a dictionary or list:

  • Includes status (success/failure) per command
  • Includes truncation info if output exceeded limits
  • Better for programmatic processing than raw CLI output

Workflow: Remote Device Discovery

When first connecting via RADKit:

  1. Inventory: get_device_inventory_names — what devices are available?
  2. Attributes: get_device_attributes for each device — type, platform, capabilities
  3. Quick health: snmp_get with sysUpTime (1.3.6.1.2.1.1.3.0) for each device
  4. Report: device inventory table with type, platform, and uptime

Workflow: Remote CLI Troubleshooting

When investigating an issue on a remote device:

  1. Identify device: get_device_inventory_names — find the target device name
  2. Check capabilities: get_device_attributes — confirm CLI access is available
  3. Execute commands: exec_cli_commands_in_device with timeout and max_lines
    • show ip interface brief — interface status
    • show ip route summary — routing table health
    • show processes cpu sorted — CPU utilization
    • show logging last 50 — recent syslog messages
  4. Structured output: exec_command for commands needing programmatic parsing
  5. Report: troubleshooting findings with device state

Workflow: Remote SNMP Polling

When collecting metrics from remote devices:

  1. Inventory: get_device_inventory_names — target devices
  2. System info: snmp_get with sysDescr, sysName, sysUpTime
  3. Interface status: snmp_get with ifOperStatus for key interfaces
  4. Counters: snmp_get with ifInOctets, ifOutOctets for bandwidth tracking
  5. Report: SNMP metric summary with uptime and interface health

Workflow: Multi-Site Health Check via RADKit

When checking health across sites served by the RADKit service:

  1. Inventory: get_device_inventory_names — all devices across sites
  2. Attributes: get_device_attributes for each — group by type and site
  3. Health commands: exec_cli_commands_in_device per device:
    • show version — uptime, software version
    • show processes cpu | include CPU utilization
    • show memory statistics
  4. SNMP baseline: snmp_get for sysUpTime, interface counters
  5. Report: multi-site health dashboard with per-device status
Show full SKILL.md (398 more words)Show less

Integration with Other Skills

SkillHow They Work Together
pyats-networkRADKit for cloud-relayed access, pyATS for direct SSH — complementary paths to devices
pyats-health-checkRADKit provides remote device data; pyATS health-check procedures analyze it
pyats-troubleshootRADKit CLI exec for remote devices that pyATS can't reach directly
pyats-routingUse RADKit to collect routing state from remote sites, analyze with routing skill
pyats-securityRADKit CLI for remote security audit commands (ACLs, AAA, CoPP)
meraki-monitoringMeraki for cloud-managed devices, RADKit for on-prem devices behind Meraki MX
te-path-analysisThousandEyes external path + RADKit internal CLI for end-to-end troubleshooting
nso-device-opsNSO for orchestrated config, RADKit for raw CLI access to same devices
gait-session-trackingRecord all RADKit remote access sessions in GAIT
servicenow-change-workflowGate any config changes through RADKit with ServiceNow CRs

Important Rules

  • RADKit is read-write capable — if the onboarded user has write access, CLI commands can push configuration. Always gate config changes with ServiceNow CRs.
  • Certificate security is critical — the RADKit private key must never be shared. Use strong passphrases.
  • Timeout controls prevent hung sessions — always set reasonable timeouts on CLI commands (default: 30 seconds).
  • max_lines prevents context overflow — use line limits for commands with potentially large output (show tech, show run on large configs).
  • SNMP is lighter than CLI — prefer snmp_get over CLI for structured metrics (uptime, counters, status).
  • One RADKit service can serve many devices — the service runs on-prem and proxies to all onboarded devices.
  • Record in GAIT — log all remote access sessions, commands executed, and findings.
  • This is a community project — not an official Cisco product. Use for experimentation, learning, and authorized operations.

Environment Variables

  • RADKIT_IDENTITY — User email address for RADKit authentication
  • RADKIT_DEFAULT_SERVICE_SERIAL — RADKit service instance identifier
Container/CI Deployment (base64-encoded credentials)
  • RADKIT_CERT_B64 — Base64-encoded client certificate
  • RADKIT_KEY_B64 — Base64-encoded private key
  • RADKIT_CA_B64 — Base64-encoded CA chain
  • RADKIT_KEY_PASSWORD_B64 — Base64-encoded key password
Local Development

For local use, RADKit auto-detects certificates in ~/.radkit/identities/ generated during the setup onboarding wizard (bash setup.sh in the cloned repo).

Failure Behavior

  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/radkit-remote-access of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Radkit Remote Access next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Radkit Remote Access compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Radkit Remote Access this skillautomateyournetwork/netclaw676—~2.4kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
MemPalace Memory SearchMemPalace/mempalace59k—~1.4kAutomated safety check: PassMIT
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • MemPalace Memory Search

    MemPalace/mempalace

    Mines project files and conversation exports into a local, searchable memory palace and recalls past work by semantic search through the mempalace CLI.

    59k GitHub stars~1.4k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated 4 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Radkit Remote Access

What does Radkit Remote Access do?

Cisco RADKit — cloud-relayed remote device access, CLI execution, SNMP polling, device inventory discovery, attribute inspection. Radkit Remote Access is an agent skill from automateyournetwork/netclaw. Cisco RADKit — cloud-relayed remote device access, CLI execution, SNMP polling, device inventory discovery, attribute inspection.

When should I use Radkit Remote Access?

Radkit Remote Access fits situations like: accessing remote network devices through a cloud relay; running CLI on air-gapped devices; polling SNMP metrics remotely; discovering device inventory via RADKit.

How do I install Radkit Remote Access in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill radkit-remote-access -a claude-code`. Or copy the skill folder (workspace/skills/radkit-remote-access in automateyournetwork/netclaw) into .claude/skills/radkit-remote-access in your project. Claude Code loads it when a task matches its description.

How do I install Radkit Remote Access in Codex?

Run `npx skills add automateyournetwork/netclaw --skill radkit-remote-access -a codex`. Or copy the skill folder (workspace/skills/radkit-remote-access in automateyournetwork/netclaw) into .agents/skills/radkit-remote-access in your project. Codex loads it when a task matches its description.

Can I use Radkit Remote Access in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill radkit-remote-access -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/radkit-remote-access, .gemini/skills/radkit-remote-access, .github/skills/radkit-remote-access and .opencode/skills/radkit-remote-access in your project.

What does Radkit Remote Access need to run?

Going by SKILL.md and its folder, Radkit Remote Access needs the command-line tools its instructions call (bash). Our summary lists: Python 3.

Does Radkit Remote Access access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Radkit Remote Access safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Radkit Remote Access use?

Radkit Remote Access is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Radkit Remote Access use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Radkit Remote Access?

Skills that share tags, products or a category with Radkit Remote Access: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and MemPalace Memory Search (MemPalace/mempalace, 59k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Radkit Remote Access?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.