Agent skill

Magicnet Device Debugging

by LIghtJUNction in LIghtJUNction/MagicNet

Debug and verify MagicNet on a real Android root device. An agent skill from LIghtJUNction/MagicNet.

MITAuto-check: notesMobile

Install Magicnet Device Debugging

skills CLI
$ npx skills add LIghtJUNction/MagicNet --skill magicnet-device-debugging -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LIghtJUNction/MagicNet magicnet-device-debugging --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LIghtJUNction/MagicNet.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/magicnet-device-debugging .claude/skills/magicnet-device-debugging && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
magicnet-device-debugging
GitHub stars
185
Token cost
~2.9k tokens
SKILL.md length
1,127 words
Files
2
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Debug and verify MagicNet on a real Android root device. An agent skill from LIghtJUNction/MagicNet.

  • Working on MagicNet MCP usage
  • SKILL.md covers Execution Environment, Ground Rules, Baseline Snapshot and MCP Usage, plus 5 more sections
  • Calls adb and curl; reaches chatgpt.com and gemini.google.com; needs MCP_SECRET
  • Adb/root validation

What it does

Magicnet Device Debugging is an agent skill from LIghtJUNction/MagicNet. Debug and verify MagicNet on a real Android root device. Use when working on MagicNet MCP usage, adb/root validation, TUN/eBPF transparent status, DNS leak diagnosis, sing-box behavior, certificate-less packet capture, eCapture/tcpdump checks, support bundles, device logs, or module runtime issues under /data/adb/modules/MagicNet.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Mobile, covering Mobile testing and debugging and Debugging. It works with Model Context Protocol and Android. The repository describes itself as: Consciously set all groups to block. The licence is MIT.

When your agent uses it

  • Working on MagicNet MCP usage
  • Adb/root validation
  • TUN/eBPF transparent status
  • DNS leak diagnosis

Example prompts

  • “/magicnet-device-debugging”

Requirements

  • A credential in MCP_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit e558026. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • adb
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • chatgpt.com
    • gemini.google.com
    • grok.com
    • claude.ai
    • cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • MCP_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Magicnet Device Debugging loads about 2.9k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,127 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:21
    - Never print or commit secrets from `.env`, subscriptions, MCP secrets, device tokens, or raw logs containing private t
  • NoteMentions a .env fileSKILL.md:22
    - Read `.env` only when a task needs local private defaults; do not copy its values into docs, patches, issues, commits,

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LIghtJUNction/MagicNet at commit e558026, republished under its MIT licence (© LIghtJUNction). 1,127 words, ~2,948 tokens.

Download SKILL.mdSave it as .claude/skills/magicnet-device-debugging/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
magicnet-device-debugging
description
Debug and verify MagicNet on a real Android root device. Use when working on MagicNet MCP usage, adb/root validation, TUN/eBPF transparent status, DNS leak diagnosis, sing-box behavior, certificate-less packet capture, eCapture/tcpdump checks, support bundles, device logs, or module runtime issues under /data/adb/modules/MagicNet.

MagicNet Device Debugging

Use the connected Android device as the source of truth. MagicNet is a root module; local config checks cannot prove vendor networking, KernelSU/Magisk behavior, TUN state, DNS routing, or real packet capture.

Execution Environment

This skill may run in either of two environments:

  • Android Termux (the current device): commands execute on the Android device itself. Do not use adb; inspect /data/adb/modules/MagicNet directly and use su -M -c '...' for root-only operations.
  • Computer/host shell: commands execute on a separate computer. Use adb shell/adb pull only when a connected device is actually needed, and first select the reported device serial.

Determine the environment before collecting evidence: uname -a, getprop ro.build.version.sdk 2>/dev/null, and command -v adb. The presence of adb alone does not mean the shell is a host; Android Termux may have adb installed while still being the device shell. Prefer direct local access when /data/adb/modules/MagicNet exists.

Ground Rules

  • Never print or commit secrets from .env, subscriptions, MCP secrets, device tokens, or raw logs containing private traffic.
  • Read .env only when a task needs local private defaults; do not copy its values into docs, patches, issues, commits, or replies.
  • Use /sdcard/Download/MagicNet/ for device-side temporary transfer files. Do not use /data/local/tmp.
  • Use su -M -c on KernelSU devices unless the current device proves another root invocation is required.
  • Keep packet capture diagnostic-only. Do not restore the removed proxy MITM/TProxy capture path, cli capture, capture config files, or lib/magicnet/capture_*.
  • Do not reintroduce Android CA injection. system/etc/security/cacerts, cli cert, and generated MagicNet local CA support were removed; use tcpdump or eCapture for no-certificate diagnostics.
  • Do not add module-level post-fs-data.sh or placeholder uninstall.sh just for compatibility. MagicNet uses service.sh and boot-completed.sh; uninstall hooks belong in kamfw only when real cleanup exists.
  • Current MagicNet mainline explicitly supports sing-box tun|ebpf, with tun as the default. Do not add auto or restore TProxy, Redirect, or netd ALLOW_MULTI; use cli transparent status and cli health, not cli ebpf status.

Baseline Snapshot

Start with read-only evidence:

sh
adb devices -l
adb shell 'getprop ro.product.model; getprop ro.build.version.release; getprop ro.build.version.sdk'
adb shell 'su -M -c "id"'
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli service status"'
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli health"'
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli transparent status"'
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli ecapture status || true"'

For network work, capture routes and listeners before changing anything:

sh
adb shell 'su -M -c "ip addr; ip route; ip rule"'
adb shell 'su -M -c "ss -lntup 2>/dev/null | grep -E \"sing-box|magicnet|789|909|876\" || true"'

MCP Usage

MagicNet exposes a Streamable HTTP MCP server from the device module. Enable it explicitly, read the actual bind/port from cli mcp status, forward that port to localhost, then call it with the device-generated secret.

sh
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli mcp enable 127.0.0.1 8766"'
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli mcp status"'
adb forward tcp:8766 tcp:8766

If cli mcp status reports a different port, use that port in adb forward and in any local .mcp.json endpoint. Do not assume stale docs or client config are correct.

Read the secret into a local shell variable without echoing it:

sh
MCP_SECRET="$(adb shell 'su -M -c "/data/adb/modules/MagicNet/cli mcp secret"' | tr -d '\r')"
curl -fsS -X POST http://127.0.0.1:8766/mcp \
  -H "Authorization: Bearer ${MCP_SECRET}" \
  -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
unset MCP_SECRET

If the local MCP client reads .mcp.json, verify it points at http://127.0.0.1:8766/mcp unless cli mcp status reports a different port. If calls fail, inspect /data/adb/modules/MagicNet/.log/mcp-server.log with redaction.

Transparent Dataplane Status

Use cli transparent status and cli health as the first-line status view. Never infer effective mode from magicnet0 alone and never treat the capability probe as attachment proof.

sh
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli transparent status"'
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli health"'
adb shell 'su -M -c "ip -o link show magicnet0 2>/dev/null || true"'
adb shell 'su -M -c "test -f /sys/fs/cgroup/cgroup.controllers && cat /sys/fs/cgroup/cgroup.controllers || true"'
adb shell 'su -M -c "ip rule; ip route; tc qdisc show 2>/dev/null || true"'

Interpret status conservatively:

  • Configured/effective tun, a healthy Dataplane check, and a present magicnet0 are the expected TUN state.
  • Configured ebpf must not require magicnet0. Verify local cgroup backend state; for hybrid, verify that every reported shared interface is an actual current downstream interface and that TC attachment is reported. shared=pending is valid when no confirmed downstream interface exists.
  • Capability/probe success means the kernel can load the requested programs; it does not prove the current sing-box process owns active cgroup/TC attachments. Preserve that distinction in reports.
  • A mode mismatch, rollback/pending state, missing expected attachment, or health warning can be a startup, routing, kernel, or vendor-network issue; collect surrounding health, process, cgroup, TC, and route evidence before changing anything.
  • cli ebpf status remains intentionally unavailable. Do not report its absence as a device fault or add an eBPF/netd fallback path. The internal sing-box tools ebpf status command is a non-destructive capability probe only.
Show full SKILL.md (504 more words)Show less

AI Website Routing Acceptance

Do not accept an AI routing fix from config inspection alone. On the installed device, verify all four public websites through MagicNet's local HTTP proxy at 127.0.0.1:7892:

sh
adb shell 'su -M -c '\''for url in https://chatgpt.com/ https://gemini.google.com/ https://grok.com/ https://claude.ai/; do curl -sS -o /dev/null -w "%{http_code} $url\n" --max-time 30 -x http://127.0.0.1:7892 "$url"; done'\'''
  • Require an HTTP response from every site. A redirect, authentication response, or application response proves reachability; timeout, DNS failure, TLS failure, or proxy failure does not.
  • For each request, collect sing-box logs proving traffic selected its dedicated outbound: ai-chatgpt, ai-gemini, ai-grok, or ai-claude. Reject any missing outbound, outbound not found, or equivalent error.
  • Follow command-line probes with a real browser visit when the user's acceptance criterion is website usability. Confirm the page loads through MagicNet rather than only proving TCP/TLS reachability.
  • If testing temporarily changes a selector through the Clash API or WebUI, record its original selection and restore it before finishing.
  • Redact subscription URLs, node credentials, tokens, cookies, authorization headers, and private browsing data from commands, logs, screenshots, and reports.

Certificate-Less Packet Capture

Use these methods when the user wants packet evidence without installing a CA certificate.

Metadata Capture With tcpdump

tcpdump needs no certificate and can prove whether traffic leaves a given interface, port, or DNS path. It does not decrypt HTTPS payloads.

sh
adb shell 'su -M -c "timeout 15 tcpdump -i any -nn -c 40 '\''tcp port 443 or udp port 53 or tcp port 53 or tcp port 853 or udp port 853'\''"'

Trigger traffic in parallel from another shell:

sh
adb shell 'am start -a android.intent.action.VIEW -d "https://www.cloudflare.com/cdn-cgi/trace?magicnet_probe=1"'

For DNS leak checks, capture on the physical egress interface when known, such as wlan0 or rmnet_data0, and verify no plain DNS/DoT leaves unexpectedly:

sh
adb shell 'su -M -c "timeout 12 tcpdump -ni wlan0 '\''port 53 or port 853'\''"'

If the interface is unclear, list candidates:

sh
adb shell 'su -M -c "ip -o link show | cut -d: -f2 | tr -d \" \""'
eCapture Packet Or TLS Diagnostics

Use the bundled eCapture wrapper when cli ecapture status says the binary is installed and executable. Treat a successful process exit as "probe started"; verify capture success by checking the output file is non-empty.

sh
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli ecapture status"'
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli ecapture pcap 15 wlan0 tcp port 443"'
adb shell 'su -M -c "/data/adb/modules/MagicNet/cli ecapture tls 15 all all"'

Expected outputs are under /data/adb/modules/MagicNet/.log/, such as ecapture.pcapng, ecapture-pcap.log, ecapture-tls.log, and ecapture-tls-events.log. Confirm file content:

sh
adb shell 'su -M -c "ls -lh /data/adb/modules/MagicNet/.log/ecapture.pcapng; wc -c /data/adb/modules/MagicNet/.log/ecapture.pcapng"'

Boundaries:

  • cli ecapture pcap can write packet captures, not decrypted application payloads. If the file is 0 bytes, report pcap output as not validated even if probes started.
  • cli ecapture tls can expose TLS plaintext events without installing a CA, but only when the kernel, eBPF probes, architecture, and target TLS library are compatible.
  • Browser/app HTTPS plaintext is not guaranteed. If TLS mode is silent, fall back to packet metadata and routing/DNS evidence.

Legacy Cleanup Checks

When auditing stale MagicNet files, treat these paths as removed mainline features:

sh
find /data/adb/modules/MagicNet -maxdepth 4 \( \
  -path '*/system/etc/security/cacerts*' \
  -o -name 'post-fs-data.sh' \
  -o -name 'sepolice.rule' \
  -o -name 'capture_common.sh' \
  -o -name 'capture_singbox.sh' \
  -o -name 'capture.conf' \
\) -print

Expected result for a current install is no output. If old files appear on a device, they are migration residue; do not build new behavior around them.

For kamfw uninstall behavior, check the framework, not MagicNet module root:

sh
adb shell 'su -M -c "test -f /data/adb/modules/MagicNet/uninstall.sh && sed -n '\''1,120p'\'' /data/adb/modules/MagicNet/uninstall.sh || true"'

An uninstall script is only meaningful if it contains real rollback commands or calls kamfw run uninstall -- "$@".

To pull a capture for local inspection, copy through the approved transfer directory and clean it after use:

sh
adb shell 'mkdir -p /sdcard/Download/MagicNet'
adb shell 'su -M -c "cp /data/adb/modules/MagicNet/.log/ecapture.pcapng /sdcard/Download/MagicNet/ecapture.pcapng"'
adb pull /sdcard/Download/MagicNet/ecapture.pcapng .
adb shell 'rm -f /sdcard/Download/MagicNet/ecapture.pcapng'

Reporting

Report only concise evidence:

  • Device model, Android version, and root availability.
  • MagicNet service, health, configured/effective transparent dataplane, MCP, and capture status.
  • Whether tcpdump or eCapture captured packets.
  • Whether HTTPS plaintext was expected, observed, or unavailable.
  • Any DNS leak evidence by interface and port, without exposing private domains beyond what the user asked to test.

© LIghtJUNction, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/magicnet-device-debugging of LIghtJUNction/MagicNet.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit e558026

Compare with similar skills

Magicnet Device Debugging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Magicnet Device Debugging compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Magicnet Device Debugging this skillLIghtJUNction/MagicNet185—~2.9kAutomated safety check: NotesMIT
Slay the Amethyst Feedback DiagnosisModinMobileSTS/SlayTheAmethystModded400—~2.6kAutomated safety check: PassCustom licence
Maui AI DebuggingRedth/Maui.Gtk101—~4.1kAutomated safety check: PassMIT
Scrcpy GotchasJuanCF/scrcpy-mcp112—~5.8kAutomated safety check: PassMIT
Generate Appclaw Flowappclawhq/AppClaw116—~3.4kAutomated safety check: NotesApache-2.0
Inspect Network TrafficHedvigInsurance/android154—~756Automated safety check: PassAGPL-3.0

Similar skills

  • Slay the Amethyst Feedback Diagnosis

    ModinMobileSTS/SlayTheAmethystModded

    Reads Slay the Amethyst diagnostics bundles to decide whether a problem comes from the launcher, a mod or the device, citing exact files and lines.

    400 GitHub stars~2.6k tokensUpdated 8 days ago
    MobileAuto-check passed
  • Maui AI Debugging

    Redth/Maui.Gtk

    End-to-end workflow for building, deploying, inspecting, and debugging .NET MAUI and MAUI Blazor Hybrid apps as an AI agent.

    101 GitHub stars~4.1k tokensUpdated 5 mo ago
    MobileAuto-check passed
  • Scrcpy Gotchas

    JuanCF/scrcpy-mcp

    A skill your agent uses when interacting with Android devices via scrcpy-mcp tools (tap, swipe, inputtext, keyevent, uidump, uifindelement, appstart, etc.).

    112 GitHub stars~5.8k tokensUpdated 14 days ago
    MobileAuto-check passed
  • Generate Appclaw Flow

    appclawhq/AppClaw

    Generate YAML flow files for AppClaw mobile automation. An agent skill from appclawhq/AppClaw.

    116 GitHub stars~3.4k tokensUpdated 1 mo ago
    MobileAuto-check: notes
  • Inspect Network Traffic

    HedvigInsurance/android

    Read the HTTP and GraphQL calls a debug build of the Android app made, with request and response bodies, status codes, timings and errors, over adb.

    154 GitHub stars~756 tokensUpdated today
    MobileAuto-check passed
  • Spock Adb

    WahdanZ/SpockAdb

    Debug Android apps on a connected device or emulator through the Spock ADB MCP server (tools named android).

    114 GitHub stars~3.3k tokensUpdated 2 days ago
    MobileAuto-check passed

More from LIghtJUNction/MagicNet

  • Kamfw

    LIghtJUNction/MagicNet

    Maintain MagicNet's shell KAM framework under src/MagicNet/lib/kamfw, including helpers, imports, i18n, logging, install filters, dependency checks, and EXIT handlers.

    185 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Magicnet Device Debugging

What does Magicnet Device Debugging do?

Debug and verify MagicNet on a real Android root device. An agent skill from LIghtJUNction/MagicNet. Magicnet Device Debugging is an agent skill from LIghtJUNction/MagicNet. Debug and verify MagicNet on a real Android root device.

When should I use Magicnet Device Debugging?

Magicnet Device Debugging fits situations like: working on MagicNet MCP usage; adb/root validation; TUN/eBPF transparent status; DNS leak diagnosis.

How do I install Magicnet Device Debugging in Claude Code?

Run `npx skills add LIghtJUNction/MagicNet --skill magicnet-device-debugging -a claude-code`. Or copy the skill folder (.agents/skills/magicnet-device-debugging in LIghtJUNction/MagicNet) into .claude/skills/magicnet-device-debugging in your project. Claude Code loads it when a task matches its description.

How do I install Magicnet Device Debugging in Codex?

Run `npx skills add LIghtJUNction/MagicNet --skill magicnet-device-debugging -a codex`. Or copy the skill folder (.agents/skills/magicnet-device-debugging in LIghtJUNction/MagicNet) into .agents/skills/magicnet-device-debugging in your project. Codex loads it when a task matches its description.

Can I use Magicnet Device Debugging in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LIghtJUNction/MagicNet --skill magicnet-device-debugging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/magicnet-device-debugging, .gemini/skills/magicnet-device-debugging, .github/skills/magicnet-device-debugging and .opencode/skills/magicnet-device-debugging in your project.

What does Magicnet Device Debugging need to run?

Going by SKILL.md and its folder, Magicnet Device Debugging needs the command-line tools its instructions call (adb and curl) and credentials named MCP_SECRET. Our summary lists: A credential in MCP_SECRET.

Does Magicnet Device Debugging access the network?

SKILL.md names 5 domains. In commands or code: chatgpt.com, gemini.google.com, grok.com, claude.ai and cloudflare.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Magicnet Device Debugging safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Magicnet Device Debugging use?

Magicnet Device Debugging is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Magicnet Device Debugging use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Magicnet Device Debugging?

Skills that share tags, products or a category with Magicnet Device Debugging: Slay the Amethyst Feedback Diagnosis (ModinMobileSTS/SlayTheAmethystModded, 400 stars), Maui AI Debugging (Redth/Maui.Gtk, 101 stars), Scrcpy Gotchas (JuanCF/scrcpy-mcp, 112 stars) and Generate Appclaw Flow (appclawhq/AppClaw, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Magicnet Device Debugging?

LIghtJUNction (a GitHub user) maintains it in LIghtJUNction/MagicNet, which has 185 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 7, 2026.

Source: LIghtJUNction/MagicNet on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.