Agent skill

Network Administration

by cbrock84 in cbrock84/headcount

Designs and operates the corporate network — segmentation, remote access, wireless, DNS and addressing, and diagnosing network problems.

MITAuto-check passed

Install Network Administration

skills CLI
$ npx skills add cbrock84/headcount --skill network-administration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cbrock84/headcount network-administration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cbrock84/headcount.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/it-operations/skills/network-administration .claude/skills/network-administration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
network-administration
GitHub stars
2k
Token cost
~1.3k tokens
SKILL.md length
737 words
Files
2 (incl. references)
Skills in repo
175
Repo updated
First seen
Licence
MIT

At a glance

Designs and operates the corporate network — segmentation, remote access, wireless, DNS and addressing, and diagnosing network problems.

  • SKILL.md covers Segment by trust, and mean it, Remote access, DNS and addressing are… and Diagnose in layers, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Network Administration is an agent skill from cbrock84/headcount. Designs and operates the corporate network — segmentation, remote access, wireless, DNS and addressing, and diagnosing network problems. Use this to segment a network, set up or fix remote access, diagnose intermittent connectivity, plan addressing or DNS, or assess whether the network's trust assumptions still hold.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/sources.md`).

The repository describes itself as: An agent organization structured as a company — 15+ departments, 125+ skills, each independently installable, citing the standards and regulators that settle the question. Runs… The licence is MIT.

Example prompts

  • “Use the network-administration skill to design and operates the corporate network — segmentation, remote access, wireless, DNS and addressing, and…”
  • “/network-administration”

What it can do on your machine

Read from SKILL.md and the folder at commit 98d1c17. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Network Administration loads about 1.3k tokens when it runs, and up to ~1.8k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 737 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cbrock84/headcount at commit 98d1c17, republished under its MIT licence (© cbrock84). 737 words, ~1,270 tokens.

Download SKILL.mdSave it as .claude/skills/network-administration/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
network-administration
description
Designs and operates the corporate network — segmentation, remote access, wireless, DNS and addressing, and diagnosing network problems. Use this to segment a network, set up or fix remote access, diagnose intermittent connectivity, plan addressing or DNS, or assess whether the network's trust assumptions still hold.

Network administration

The network is the substrate everything else assumes works. It gets attention when it fails and is otherwise expected to be invisible, which is why its design debts persist for years.

Segment by trust, and mean it

A flat network means one compromised laptop reaches the finance server. Segmentation is the highest- value structural control available and the most commonly deferred.

Separate at minimum: user devices, servers, management interfaces, guest, and anything unmanaged — printers, cameras, building systems, contractor equipment. That last category is the recurring entry point, because it is rarely patched and rarely owned.

Default deny between segments, and permit specific flows. Rules that accumulate without review become an allow-all with extra steps; review them on a cadence and remove what no longer has a reason.

Remote access

The perimeter stopped being a perimeter when the workforce and the workloads left it. Treat network location as weak evidence of trust: being on the corporate network should not by itself grant access to anything sensitive.

Prefer per-application access over full network access. A remote user needing one internal application does not need a route to the entire internal estate, which is what a traditional VPN grants by default.

Authentication and authorization policy belongs to security:access-and-identity; this skill implements the network path.

DNS and addressing are load-bearing

DNS failure presents as everything being broken, which is why it is misdiagnosed for the first twenty minutes of many incidents. Run it redundantly, monitor resolution from the client's perspective rather than the server's, and keep records under change control.

Plan addressing with room to grow and document it. Overlapping private ranges is the problem that surfaces years later during an acquisition or a site merge and is expensive at exactly that moment.

Diagnose in layers

Work bottom-up and prove each layer before moving on: physical, then addressing, then routing, then name resolution, then the application. Most misdiagnosis comes from starting at the application because that is where the complaint originated.

Intermittent problems are the hard case and need data over time, not a test at the moment someone complains. Capture continuously at the affected point; a test that passes while nobody is suffering proves nothing.

Show full SKILL.md (373 more words)Show less

Multiple sites multiply the failure modes, not the work

A second location does not double the network; it introduces a class of problem the first site never had. Traffic now crosses a link you do not own, and every service the remote site depends on becomes a question of where it lives.

Decide deliberately what is central and what is local. Authentication, name resolution, and print are the three that hurt most when a site link drops — a location that cannot log in because the domain controller is elsewhere is offline for every purpose, not just the one that failed. Local survivability for those three is usually worth the cost; centralizing everything else usually is.

Site links fail partially more often than completely. A circuit that is up but degraded is harder than one that is down, because nothing alerts and everything is slow. Monitor the link from both ends and on the path rather than trusting the provider's portal, which reports their view of their equipment.

Where a software-defined WAN is in use, it makes the degraded case survivable by steering traffic between circuits, and it makes the topology something you configure centrally rather than per site. That is a real gain and a real concentration of risk: the controller becomes a thing whose failure is everyone's failure, so treat it as production infrastructure rather than a management tool.

Small sites accumulate exceptions. A closet without cooling, a switch nobody has patched, an address range someone reused. Budget for a periodic physical visit — remote management does not show you the cable run someone added, and the sites without permanent IT staff are exactly the ones that drift furthest from the standard.

Sources

references/sources.md in this skill lists the outside authorities that settle the questions here — what each one is authoritative for, and what you may do with it. Check them before answering on anything they cover, and cite what you used. Most are free to read and not free to reproduce; the use note on each is binding.

Never

  • Run a flat network and rely on host controls alone.
  • Grant full network access where application access would do.
  • Treat network location as sufficient evidence of trust.
  • Diagnose from the application layer down.

© cbrock84, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/it-operations/skills/network-administration of cbrock84/headcount.

  • SKILL.md
  • references/sources.md

Open the folder on GitHubat commit 98d1c17

Compare with similar skills

Network Administration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Network Administration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Network Administration this skillcbrock84/headcount2k—~1.3kAutomated safety check: PassMIT
Design Systemaffaan-m/ECC275k—~698Automated safety check: PassMIT
Design Guidepaperclipai/paperclip99k1 repos~3.1kAutomated safety check: PassMIT
Design Audit Against Rams' Principlesthedotmack/claude-mem98k—~4.6kAutomated safety check: PassApache-2.0
Figma Design to Codewarpdotdev/warp65k4 repos~2.9kAutomated safety check: PassAGPL-3.0
Design Consultationgarrytan/gstack136k—~15kAutomated safety check: NotesMIT

Similar skills

  • Design System

    affaan-m/ECC

    Generate a design system from an existing codebase or audit one for visual consistency: extract tokens (colors, typography, spacing, shadows) into design-tokens.json and CSS custom properties with…

    275k GitHub stars~698 tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed
  • Design Guide

    paperclipai/paperclip

    Paperclip UI design system guide for building consistent, reusable frontend components.

    99k GitHub starsUsed in 1 repo~3.1k tokens
    Frontend & DesignAuto-check passed
  • Audits a design against Dieter Rams' ten principles of good design, scores each with evidence, and hands off a make-plan prompt for a new, refined or redesigned outcome.

    98k GitHub stars~4.6k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Figma Design to Code

    warpdotdev/warp

    Turns a Figma frame or component into production code that matches the design, using the Figma MCP server and the project's own design system.

    65k GitHub starsUsed in 4 repos~2.9k tokens
    Frontend & DesignAuto-check passed
  • Design Consultation

    garrytan/gstack

    Learns about your product, studies the landscape and writes a DESIGN.md with a full design system covering type, color, layout, spacing and motion.

    136k GitHub stars~15k tokensUpdated today
    Frontend & DesignAuto-check: notes
  • Brand and Design Toolkit

    nextlevelbuilder/ui-ux-pro-max-skill

    Bundles design tasks behind one skill: brand identity, tokens, UI styling, logos, corporate identity mockups, slides, banners, icons and social images.

    134k GitHub starsUsed in 1 repo~3.5k tokens
    Media & CreativeAuto-check passed

More from cbrock84/headcount

All 175 skills in this repo
  • Agent Hierarchy

    cbrock84/headcount

    Designs orchestrator-and-subagent hierarchies for a repository — splitting agents by exclusive write surface, pairing every producer with an independent auditor, and enforcing the split with a…

    2k GitHub stars~1.2k tokensUpdated 20 days ago
    Auto-check passed
  • Access And Identity

    cbrock84/headcount

    Designs and audits who can reach what — authentication, authorization models, privileged access, service credentials, and joiner-mover-leaver process.

    2k GitHub stars~1.1k tokensUpdated 20 days ago
    Auto-check passed
  • Account Based Marketing

    cbrock84/headcount

    Concentrates marketing and sales effort on a named set of accounts rather than on volume — qualifying whether the model fits your economics at all, building the account list and the buying group…

    2k GitHub stars~1.2k tokensUpdated 20 days ago
    Auto-check passed
  • Activation

    cbrock84/headcount

    Gets new users from signup to first real value — signup flow, onboarding, time-to-value, and the early experience that determines whether someone becomes a user or a lapsed account.

    2k GitHub stars~865 tokensUpdated 20 days ago
    Auto-check passed
  • AI Research Analyst

    cbrock84/headcount

    Produces executive-level research — market sizing, competitor mapping, trend analysis, and strategic intelligence — grounded in cited sources with the confidence in each claim made explicit.

    2k GitHub stars~916 tokensUpdated 20 days ago
    Auto-check passed
  • AI Search Optimization

    cbrock84/headcount

    Optimizes for AI assistants and AI-generated answers — being retrievable, being cited, and being represented accurately when a model answers on your behalf.

    2k GitHub stars~829 tokensUpdated 20 days ago
    Auto-check passed

Questions about Network Administration

What does Network Administration do?

Designs and operates the corporate network — segmentation, remote access, wireless, DNS and addressing, and diagnosing network problems. Network Administration is an agent skill from cbrock84/headcount. Designs and operates the corporate network — segmentation, remote access, wireless, DNS and addressing, and diagnosing network problems.

How do I install Network Administration in Claude Code?

Run `npx skills add cbrock84/headcount --skill network-administration -a claude-code`. Or copy the skill folder (plugins/it-operations/skills/network-administration in cbrock84/headcount) into .claude/skills/network-administration in your project. Claude Code loads it when a task matches its description.

How do I install Network Administration in Codex?

Run `npx skills add cbrock84/headcount --skill network-administration -a codex`. Or copy the skill folder (plugins/it-operations/skills/network-administration in cbrock84/headcount) into .agents/skills/network-administration in your project. Codex loads it when a task matches its description.

Can I use Network Administration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cbrock84/headcount --skill network-administration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/network-administration, .gemini/skills/network-administration, .github/skills/network-administration and .opencode/skills/network-administration in your project.

What does Network Administration need to run?

SKILL.md names no scripts, command-line tools or credentials: Network Administration is instructions for the agent only.

Does Network Administration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Network Administration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Network Administration use?

Network Administration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Network Administration use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 521 tokens, read only when the agent opens those files.

What are the alternatives to Network Administration?

Skills that share tags, products or a category with Network Administration: Design System (affaan-m/ECC, 275k stars), Design Guide (paperclipai/paperclip, 99k stars), Design Audit Against Rams' Principles (thedotmack/claude-mem, 98k stars) and Figma Design to Code (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Network Administration?

cbrock84 (a GitHub user) maintains it in cbrock84/headcount, which has 2,007 GitHub stars. The repository holds 175 skills in this directory. The repository was last updated on September 17, 2026.

Source: cbrock84/headcount on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.