Agent skill

Pcap Triage Analyst

by criptogus in criptogus/agent-evolve-network

Triages a packet capture summary, surfaces suspicious flows and IOCs, names the likely technique, and recommends the next investigative step.

Apache-2.0Auto-check passed

Install Pcap Triage Analyst

skills CLI
$ npx skills add criptogus/agent-evolve-network --skill pcap-triage-analyst -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install criptogus/agent-evolve-network pcap-triage-analyst --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/criptogus/agent-evolve-network.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pcap-triage-analyst .claude/skills/pcap-triage-analyst && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pcap-triage-analyst
GitHub stars
288
Token cost
~1.1k tokens
SKILL.md length
311 words
Files
1
Skills in repo
107
Repo updated
First seen
Licence
Apache-2.0

At a glance

Triages a packet capture summary, surfaces suspicious flows and IOCs, names the likely technique, and recommends the next investigative step.

  • The user asks for pcap triage analyst work
  • SKILL.md covers Instructions, Always, Never and Input / output contract, plus 2 more sections
  • Calls npx

What it does

Pcap Triage Analyst is an agent skill from criptogus/agent-evolve-network. Triages a packet capture summary, surfaces suspicious flows and IOCs, names the likely technique, and recommends the next investigative step. Use when the user asks for pcap triage analyst work, or mentions pcap, triage, analyst.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The licence is Apache-2.0.

When your agent uses it

  • The user asks for pcap triage analyst work

Example prompts

  • “Use the pcap-triage-analyst skill to triage a packet capture summary, surfaces suspicious flows and IOCs, names the likely technique, and recommends…”
  • “/pcap-triage-analyst”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit d19b920. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • superagentskill.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pcap Triage Analyst loads about 1.1k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 311 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from criptogus/agent-evolve-network at commit d19b920, republished under its Apache-2.0 licence (© criptogus). 311 words, ~1,082 tokens.

Download SKILL.mdSave it as .claude/skills/pcap-triage-analyst/SKILL.md (or your agent's skills folder).
name
pcap-triage-analyst
description
Triages a packet capture summary, surfaces suspicious flows and IOCs, names the likely technique, and recommends the next investigative step. Use when the user asks for pcap triage analyst work, or mentions pcap, triage, analyst.
version
0.1.0
license
Apache-2.0
homepage
https://superagentskill.com/marketplace/pcap-triage-analyst
source
Super Agent Skill (SAK)

PCAP Triage Analyst

Use when you have a Wireshark/tshark summary, flow table, or protocol-hierarchy export and need a fast, structured triage: what looks anomalous, why, the IOCs to pivot on, and what to check next. Built for DNS tunneling, beaconing/C2, data exfiltration and cleartext-credential exposure. Does NOT capture traffic, call out to external services, or assert attribution it cannot support from the provided data.

Adapted for Super Agent Skill from the open Anthropic-Cybersecurity-Skills corpus (Apache-2.0); restructured into a typed input -> output contract and hardened for adversarial review.

Instructions

You are a network forensics analyst triaging a packet capture you did not collect yourself. From the provided summary/flow data, produce: (1) ranked suspicious findings (each: what, the evidence in the data, severity), (2) extracted IOCs (IPs, domains, JA3/hashes, URIs) — redact nothing but never fabricate, (3) the most likely MITRE ATT&CK technique, (4) the single best next step (a filter to run, an artifact to extract). Quote the specific flow/row that justifies each finding. If the capture is too sparse to conclude, say what to capture next instead of guessing.

Always

  • Cite the specific flow/row that supports each finding.
  • Extract IOCs exactly as they appear; never invent IPs, domains or hashes.
  • Give one concrete next investigative step (a filter or extraction).

Never

  • Assert attribution to a named actor without supporting evidence in the data.
  • Recommend offensive action against an observed host.
  • Treat benign high-volume protocols as malicious without a stated rationale.

Input / output contract

Input:

json
{
  "type": "object",
  "properties": {
    "capture_summary": {
      "type": "string"
    },
    "flows": {
      "type": "array",
      "items": {
        "type": "object"
      }
    }
  },
  "required": [
    "capture_summary"
  ]
}

Output:

json
{
  "type": "object",
  "properties": {
    "findings": {
      "type": "array",
      "items": {
        "type": "object"
      }
    },
    "iocs": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "likely_technique": {
      "type": "string"
    },
    "next_step": {
      "type": "string"
    }
  },
  "required": [
    "findings",
    "next_step"
  ]
}

Examples

DNS tunneling suspicion

Input:

capture_summary: |
  High count of TXT queries to *.dataxfer.example, avg label length 48,
  110 queries/min from 10.0.4.7, no matching A records resolved.

Expected output:

Findings:
- HIGH — Probable DNS tunneling: 110 TXT/min to *.dataxfer.example with 48-char
  labels and no resolved A records (classic encoded-payload pattern).
IOCs: dataxfer.example, 10.0.4.7
Likely technique: T1071.004 (Application Layer Protocol: DNS).
Next step: `dns.qry.type == 16 && dns.qry.name contains "dataxfer.example"` and
decode the base32/hex labels; isolate 10.0.4.7 for host triage.
Sparse capture

Input:

capture_summary: "37 packets, only TLS handshakes to a CDN, no payload."

Expected output:

Insufficient evidence to conclude. 37 TLS handshakes to a CDN are not inherently
suspicious. Next step: capture a longer window with full payload (or JA3/JA3S +
SNI logging) before triaging; nothing actionable in the current data.

Trust & telemetry

This skill is graded on the Super Agent Skill network: format, substance and adversarial (prompt-injection) testing produce a public Trust Score.

Reinstall or update with npx skills update, or pull the live graded version with npx super-agent install pcap-triage-analyst.

© criptogus, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/pcap-triage-analyst of criptogus/agent-evolve-network.

Open the folder on GitHubat commit d19b920

Compare with similar skills

Pcap Triage Analyst next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pcap Triage Analyst compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pcap Triage Analyst this skillcriptogus/agent-evolve-network288—~1.1kAutomated safety check: PassApache-2.0
Triaging Issuespytorch/pytorch104k—~4.2kAutomated safety check: PassCustom licence
Issue Triagepaperclipai/paperclip98k—~1kAutomated safety check: PassMIT
Triagepnpm/pnpm37k—~2.9kAutomated safety check: PassMIT
Herdr Issue Triageherdrdev/herdr43k—~517Automated safety check: PassApache-2.0
RTK Combined Issue and PR Triagertk-ai/rtk83k—~1.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Triaging Issues

    pytorch/pytorch

    Triages GitHub issues by routing to oncall teams, applying labels, and closing questions.

    104k GitHub stars~4.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Issue Triage

    paperclipai/paperclip

    Triage Paperclip inbox issues that are stale, blocked, in-review, or assigned-but-not-progressing, and decide a single next action per issue (resume, reassign, unblock, escalate, or close).

    98k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Triage

    pnpm/pnpm

    Triage an incoming GitHub issue against the pnpm codebase and related open issues, then apply exactly one implementation-readiness label using pnpm's state: taxonomy.

    37k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Herdr Issue Triage

    herdrdev/herdr

    Triages open herdr GitHub issues into a short decision-first Markdown table with a priority light, recommendation, age, reactions and a reason for each.

    43k GitHub stars~517 tokensUpdated today
    DevelopmentAuto-check passed
  • Runs issue triage and PR triage in parallel, then cross-analyzes the results to flag duplicate coverage, security gaps, P0 issues with no PR, and PR conflicts.

    83k GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Triage

    TalAter/annyang

    Triage and close GitHub issues on TalAter/annyang. An agent skill from TalAter/annyang.

    6.8k GitHub stars~810 tokensUpdated yesterday
    AI & LLM EngineeringAuto-check: notes

More from criptogus/agent-evolve-network

All 107 skills in this repo
  • Brand Research

    criptogus/agent-evolve-network

    Kickoff research for a brand you haven't worked on before — web research, existing-ad analysis from the Meta Ad Library, editorial-grammar profiling, sourced + AI-generated brand assets, hook/CTA…

    288 GitHub stars~3.9k tokensUpdated 28 days ago
    Auto-check passed
  • Create Apple Notes Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad recreating the iPhone Apple Notes typing experience — the note begins with 1–2 visible lines, then progressively types additional paragraphs character-by-character…

    288 GitHub stars~4.9k tokensUpdated 28 days ago
    Auto-check passed
  • Create Chatgpt Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad that recreates a ChatGPT mobile chat — user types in the composer with the iOS keyboard visible, taps send, keyboard slides down, header right-cluster swaps…

    288 GitHub stars~5k tokensUpdated 28 days ago
    Auto-check passed
  • Create Imessage Video Ad

    criptogus/agent-evolve-network

    Produce a 9:16 social-native ad that recreates an iMessage conversation reveal — bubbles pop in over time, composer types char-by-char, real Apple iMessage SFX hit on every send/receive, music bed…

    288 GitHub stars~7.4k tokensUpdated 28 days ago
    Auto-check passed
  • Cloud Misconfig Auditor

    criptogus/agent-evolve-network

    Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.

    288 GitHub stars~965 tokensUpdated 28 days ago
    Auto-check passed
  • Cloudflare Workers Expert

    criptogus/agent-evolve-network

    Builds and debugs Cloudflare Workers, Durable Objects, KV, R2, D1, and Queues with edge-correct patterns.

    288 GitHub stars~619 tokensUpdated 28 days ago
    Auto-check passed

Questions about Pcap Triage Analyst

What does Pcap Triage Analyst do?

Triages a packet capture summary, surfaces suspicious flows and IOCs, names the likely technique, and recommends the next investigative step. Pcap Triage Analyst is an agent skill from criptogus/agent-evolve-network. Triages a packet capture summary, surfaces suspicious flows and IOCs, names the likely technique, and recommends the next investigative step.

When should I use Pcap Triage Analyst?

Pcap Triage Analyst fits situations like: the user asks for pcap triage analyst work.

How do I install Pcap Triage Analyst in Claude Code?

Run `npx skills add criptogus/agent-evolve-network --skill pcap-triage-analyst -a claude-code`. Or copy the skill folder (skills/pcap-triage-analyst in criptogus/agent-evolve-network) into .claude/skills/pcap-triage-analyst in your project. Claude Code loads it when a task matches its description.

How do I install Pcap Triage Analyst in Codex?

Run `npx skills add criptogus/agent-evolve-network --skill pcap-triage-analyst -a codex`. Or copy the skill folder (skills/pcap-triage-analyst in criptogus/agent-evolve-network) into .agents/skills/pcap-triage-analyst in your project. Codex loads it when a task matches its description.

Can I use Pcap Triage Analyst in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add criptogus/agent-evolve-network --skill pcap-triage-analyst -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pcap-triage-analyst, .gemini/skills/pcap-triage-analyst, .github/skills/pcap-triage-analyst and .opencode/skills/pcap-triage-analyst in your project.

What does Pcap Triage Analyst need to run?

Going by SKILL.md and its folder, Pcap Triage Analyst needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Pcap Triage Analyst access the network?

SKILL.md names 1 domain. As links in the text: superagentskill.com. This is read from the text; nothing was executed.

Is Pcap Triage Analyst safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pcap Triage Analyst use?

Pcap Triage Analyst is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pcap Triage Analyst use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pcap Triage Analyst?

Skills that share tags, products or a category with Pcap Triage Analyst: Triaging Issues (pytorch/pytorch, 104k stars), Issue Triage (paperclipai/paperclip, 98k stars), Triage (pnpm/pnpm, 37k stars) and Herdr Issue Triage (herdrdev/herdr, 43k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pcap Triage Analyst?

criptogus (a GitHub user) maintains it in criptogus/agent-evolve-network, which has 288 GitHub stars. The repository holds 107 skills in this directory. The repository was last updated on September 9, 2026.

Source: criptogus/agent-evolve-network on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.