Agent skill

Network Troubleshooting

by Mindrally in Mindrally/skills

Systematic, safety-first diagnosis of developer network failures such as connection refused, DNS resolution errors, TLS certificate problems, proxy failures, and package registry timeouts.

Apache-2.0Auto-check passedDevOps & Cloud

Install Network Troubleshooting

skills CLI
$ npx skills add Mindrally/skills --skill network-troubleshooting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Mindrally/skills network-troubleshooting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Mindrally/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/network-troubleshooting .claude/skills/network-troubleshooting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
network-troubleshooting
GitHub stars
268
Token cost
~2.2k tokens
SKILL.md length
826 words
Files
1
Skills in repo
34
Repo updated
First seen
Licence
Apache-2.0

At a glance

Systematic, safety-first diagnosis of developer network failures such as connection refused, DNS resolution errors, TLS certificate problems, proxy failures, and package registry timeouts.

  • Works in 6 steps: Collect — Capture the exact error text,… → Classify — Match the symptom against the… → Diagnose — Run only read-only checks… → …
  • A command fails with a network-shaped error (curl
  • SKILL.md covers Safety Boundaries, Workflow, Error Classification and Safe Target-Scoped Checks, plus 2 more sections
  • Calls curl, openssl and npm

What it does

Network Troubleshooting is an agent skill from Mindrally/skills. Systematic, safety-first diagnosis of developer network failures such as connection refused, DNS resolution errors, TLS certificate problems, proxy failures, and package registry timeouts. Use when a command fails with a network-shaped error (curl, npm, pip, git, docker), when a service is unreachable, or when the user asks to debug connectivity, DNS, TLS, or proxy issues.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud networking and Containers. It works with Docker, Git and npm. The repository describes itself as: 255+ Claude Code skills converted from Cursor rules. Expert coding guidelines for every major framework and language. The licence is Apache-2.0.

When your agent uses it

  • A command fails with a network-shaped error (curl
  • A service is unreachable
  • The user asks to debug connectivity

Example prompts

  • “/network-troubleshooting”

Requirements

  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Collect — Capture the exact error text, the failing command, the target host/URL/port, OS/shell, proxy/VPN context, and whether the…
  2. Classify — Match the symptom against the error classification table below to form a hypothesis.
  3. Diagnose — Run only read-only checks scoped to the failing target, starting with the smallest relevant check.
  4. Explain — Interpret each diagnostic result in plain language before suggesting any fix.
  5. Advise — Present remediation options as choices; wait for explicit user approval before changing any state.
  6. Verify — After an approved change, re-run the original failing command or an equivalent target-scoped check.

What it can do on your machine

Read from SKILL.md and the folder at commit 9718410. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • openssl
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Network Troubleshooting loads about 2.2k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 826 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Mindrally/skills at commit 9718410, republished under its Apache-2.0 licence (© Mindrally). 826 words, ~2,187 tokens.

Download SKILL.mdSave it as .claude/skills/network-troubleshooting/SKILL.md (or your agent's skills folder).
name
network-troubleshooting
description
Systematic, safety-first diagnosis of developer network failures such as connection refused, DNS resolution errors, TLS certificate problems, proxy failures, and package registry timeouts. Use when a command fails with a network-shaped error (curl, npm, pip, git, docker), when a service is unreachable, or when the user asks to debug connectivity, DNS, TLS, or proxy issues.

Network Troubleshooting

This skill provides a concise, safety-first decision guide for diagnosing developer network failures. Diagnostics must stay read-only and target-scoped — this is not an automated remediation toolkit.

Safety Boundaries

These boundaries apply to every step of the workflow below and must never be relaxed, even if asked:

  • Prefer read-only diagnostics and trusted project-provided diagnostic scripts.
  • Use the failing host, URL, registry, or service as the default probe target — do not probe unrelated hosts.
  • Ask before probing unrelated external services.
  • Never print proxy URLs, credentials, tokens, auth headers, package index URLs, registry hostnames from config, or raw config values in shared output.
  • Internal hosts and URLs may be collected for target-scoped local diagnostics, but replace them with placeholders before sharing logs or reports unless the user explicitly approves including them.
  • Never dump local configuration from npm, pnpm, yarn, pip, Git, Docker, shell, OS proxy, VPN, or certificate stores.
  • Never disable, bypass, or skip TLS or certificate verification (no -k/--insecure, no NODE_TLS_REJECT_UNAUTHORIZED=0, no verify=False), even temporarily "just to test."
  • Never change OS networking, DNS, proxy, package manager, Git, Docker, shell, VPN, or trust-store settings without explicit user approval for the exact action being taken.

Workflow

  1. Collect — Capture the exact error text, the failing command, the target host/URL/port, OS/shell, proxy/VPN context, and whether the failure affects one target or many.
  2. Classify — Match the symptom against the error classification table below to form a hypothesis.
  3. Diagnose — Run only read-only checks scoped to the failing target, starting with the smallest relevant check.
  4. Explain — Interpret each diagnostic result in plain language before suggesting any fix.
  5. Advise — Present remediation options as choices; wait for explicit user approval before changing any state.
  6. Verify — After an approved change, re-run the original failing command or an equivalent target-scoped check.

Error Classification

Error PatternLikely Category
ECONNREFUSED, ERR_CONNECTION_REFUSED, Connection refusedTarget service or port is not listening
ECONNRESET, socket hang up, Connection resetConnection dropped by target, proxy, firewall, or middlebox
ETIMEDOUT, ERR_CONNECTION_TIMED_OUT, timed outRouting, firewall, proxy, or target availability
ENOTFOUND, EAI_NONAME, ERR_NAME_NOT_RESOLVED, getaddrinfoDNS or hostname issue
ERR_PROXY_CONNECTION_FAILED, proxy tunnel errors, HTTP 407Proxy configuration or proxy authentication
UNABLE_TO_VERIFY_LEAF_SIGNATURE, CERT_HAS_EXPIRED, self signed, ERR_CERT_*TLS certificate or local trust issue
HTTP 403Authorization, IP allowlist, CORS, or policy block
HTTP 502, 503, 504Upstream service, gateway, CDN, or transient server issue
npm ERR! network, package install timeout, pip timeoutPackage registry, proxy, DNS, or network path issue
fatal: unable to access, Git fetch/push timeoutGit remote, proxy, DNS, TLS, or network path issue

Safe Target-Scoped Checks

Choose the smallest relevant check and explain what it does before running it. Always substitute the specific failing <target-host>, <port>, and <path> — never a broader or unrelated target.

Connectivity

Linux/macOS:

bash
ping -c 4 <target-host>
curl -v telnet://<target-host>:<port> --connect-timeout 5

Windows PowerShell:

powershell
Test-Connection -ComputerName <target-host> -Count 4
Test-NetConnection -ComputerName <target-host> -Port <port>
DNS

Linux/macOS:

bash
nslookup <target-host>
dig <target-host>

Windows PowerShell:

powershell
Resolve-DnsName <target-host>
HTTP

Linux/macOS:

bash
curl -vvv -o /dev/null -w "HTTP %{http_code}\nTime: %{time_total}s\nDNS: %{time_namelookup}s\nConnect: %{time_connect}s\nTLS: %{time_appconnect}s\n" https://<target-host>/<path>
curl -I https://<target-host>/<path>

Windows PowerShell:

powershell
$uri = "https://<target-host>/<path>"
try {
  $resp = Invoke-WebRequest -Uri $uri -Method Head -TimeoutSec 10
  "HTTP status: $([int]$resp.StatusCode)"
} catch [Net.WebException] {
  if ($_.Exception.Response) {
    "HTTP status: $([int]$_.Exception.Response.StatusCode)"
  } else {
    "HTTP request failed: $($_.Exception.Message)"
  }
}
TLS

Linux/macOS:

bash
openssl s_client -connect <target-host>:<port> -servername <target-host> -showcerts </dev/null
echo | openssl s_client -connect <target-host>:<port> -servername <target-host> 2>/dev/null | openssl x509 -noout -subject -issuer -dates

Windows PowerShell — check the certificate and HTTP status separately so a non-2xx response is never mislabeled as a certificate failure:

powershell
try {
  $req = [Net.HttpWebRequest]::Create("https://<target-host>:<port>/<path>")
  $req.Method = "HEAD"
  $req.Timeout = 5000
  try {
    $resp = $req.GetResponse()
  } catch [Net.WebException] {
    $resp = $_.Exception.Response
    if ($req.ServicePoint.Certificate) {
      $cert = $req.ServicePoint.Certificate
      "Cert subject: $($cert.Subject)"
      "Cert expires: $($cert.GetExpirationDateString())"
    }
    if ($resp) {
      "HTTP status: $([int]$resp.StatusCode) $($resp.StatusDescription)"
      $resp.Close()
    } else {
      "TLS/network error: $($_.Exception.Message)"
    }
    return
  }
  $cert = $req.ServicePoint.Certificate
  if ($cert) {
    "Cert subject: $($cert.Subject)"
    "Cert expires: $($cert.GetExpirationDateString())"
  }
  "HTTP status: $([int]$resp.StatusCode) $($resp.StatusDescription)"
  $resp.Close()
} catch {
  "TLS/network error: $($_.Exception.Message)"
}
Show full SKILL.md (341 more words)Show less
Proxy and Package Managers
  • Avoid raw config reads for proxy, package manager, Git, Docker, or OS network configuration.
  • Report only whether relevant settings appear present when this can be checked without printing values.
  • If the available command would print a URL, token, internal hostname, auth header, or full config value, do not run it.
  • Only perform package registry probes when the failed operation already targeted that registry, or after the user approves that exact probe target.

User-Approved Remediation Options

Present these as choices for the user to approve — never apply them automatically.

DiagnosisSafe Advice
Target service is not listeningCheck whether the local or remote service is running and whether the expected port is correct.
DNS lookup failsCheck the hostname, hosts-file expectations, DNS service status, or approved DNS changes.
Proxy appears required or unavailableAsk whether the user wants to start or adjust the proxy/VPN, then verify only the approved target.
TLS certificate expiredRenew or replace the certificate, fix system time, install a trusted local development CA, or update the trust store. Never bypass TLS verification.
TLS unknown CAImport the correct CA into the appropriate trust store after the user confirms the source and scope.
HTTP 407Ask the user to confirm proxy authentication requirements before changing credentials or tool settings.
HTTP 403Check authentication, API key scope, IP allowlist, CORS policy, or service policy.
HTTP 502/503/504Treat as upstream or gateway instability; check status pages when approved and retry with backoff.
Package install timeoutDiscuss approved registry, proxy, or network-path options without printing or changing stored config values.
Git network failureDiscuss approved remote URL, proxy, credential, TLS, or network-path options without changing global Git settings automatically.
Docker pull failureDiscuss approved registry mirror, proxy, or daemon settings as a user-approved configuration change.

Verification

  • After any user-approved change, re-run the original failing command whenever possible.
  • If a smaller check is needed instead, keep it scoped to the same failing host, URL, registry, or service.
  • Always explain what each diagnostic result means before recommending the next step.

© Mindrally, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in network-troubleshooting of Mindrally/skills.

Open the folder on GitHubat commit 9718410

Compare with similar skills

Network Troubleshooting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Network Troubleshooting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Network Troubleshooting this skillMindrally/skills268—~2.2kAutomated safety check: PassApache-2.0
Tokf Runmpecan/tokf199—~571Automated safety check: PassMIT
Whendone PlusEliasOulkadi/shokunin114—~1.7kAutomated safety check: PassMIT
Devops AgentLeoYeAI/openclaw-master-skills2.2k—~5.3kAutomated safety check: NotesMIT
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0
Ssh Skillbadseal/ssh-skill536—~2.4kAutomated safety check: NotesNone

Similar skills

  • Tokf Run

    mpecan/tokf

    Compress verbose CLI output with tokf before returning results.

    199 GitHub stars~571 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Whendone Plus

    EliasOulkadi/shokunin

    Automatically notify the user when long-running terminal commands finish (npm test, docker build, git push, etc.).

    114 GitHub stars~1.7k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Devops Agent

    LeoYeAI/openclaw-master-skills

    Your on-call DevOps assistant — one-click deploy, monitoring setup, scheduled backups, and fault diagnosis.

    2.2k GitHub stars~5.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Ssh Skill

    badseal/ssh-skill

    A skill your agent uses when a task requires SSH or SCP/SFTP behavior, a remote server, server alias/IP/hostname/user@host, bastion or jump-host access, remote command execution, upload/download…

    536 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from Mindrally/skills

All 34 skills in this repo
  • Analytics Data Analysis

    Mindrally/skills

    Best practices for analytics, data analysis, and visualization using Python, pandas, matplotlib, seaborn, and Jupyter notebooks.

    268 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Best practices for AutoML and hyperparameter search with Optuna, Ray Tune, and PyCaret, covering search-space design, validation splits, and leakage prevention.

    268 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Blender Python Addon

    Mindrally/skills

    Best practices for writing Blender Python add-ons using the bpy API, covering operators, panels, properties, registration, and API-safe scripting.

    268 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Expert guidelines for Chrome extension development with Manifest V3, covering security, performance, and best practices.

    268 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Clean Code

    Mindrally/skills

    Clean, maintainable, human-readable code principles combined with anti-over-engineering discipline: naming, single responsibility, DRY, and scoping changes to exactly what was requested.

    268 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Design Systems

    Mindrally/skills

    Comprehensive design system guidelines for building consistent, accessible, and scalable component libraries.

    268 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Network Troubleshooting

What does Network Troubleshooting do?

Systematic, safety-first diagnosis of developer network failures such as connection refused, DNS resolution errors, TLS certificate problems, proxy failures, and package registry timeouts. Network Troubleshooting is an agent skill from Mindrally/skills. Systematic, safety-first diagnosis of developer network failures such as connection refused, DNS resolution errors, TLS certificate problems, proxy failures, and package registry timeouts.

When should I use Network Troubleshooting?

Network Troubleshooting fits situations like: A command fails with a network-shaped error (curl; A service is unreachable; the user asks to debug connectivity.

How do I install Network Troubleshooting in Claude Code?

Run `npx skills add Mindrally/skills --skill network-troubleshooting -a claude-code`. Or copy the skill folder (network-troubleshooting in Mindrally/skills) into .claude/skills/network-troubleshooting in your project. Claude Code loads it when a task matches its description.

How do I install Network Troubleshooting in Codex?

Run `npx skills add Mindrally/skills --skill network-troubleshooting -a codex`. Or copy the skill folder (network-troubleshooting in Mindrally/skills) into .agents/skills/network-troubleshooting in your project. Codex loads it when a task matches its description.

Can I use Network Troubleshooting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mindrally/skills --skill network-troubleshooting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/network-troubleshooting, .gemini/skills/network-troubleshooting, .github/skills/network-troubleshooting and .opencode/skills/network-troubleshooting in your project.

What does Network Troubleshooting need to run?

Going by SKILL.md and its folder, Network Troubleshooting needs the command-line tools its instructions call (curl, openssl and npm). Our summary lists: Docker.

Does Network Troubleshooting access the network?

SKILL.md contains no URLs. Its commands use curl and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Network Troubleshooting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Network Troubleshooting use?

Network Troubleshooting is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Network Troubleshooting use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Network Troubleshooting?

Skills that share tags, products or a category with Network Troubleshooting: Tokf Run (mpecan/tokf, 199 stars), Whendone Plus (EliasOulkadi/shokunin, 114 stars), Devops Agent (LeoYeAI/openclaw-master-skills, 2.2k stars) and Devcontainer Dev (stacklok/toolhive-studio, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Network Troubleshooting?

Mindrally (a GitHub organization) maintains it in Mindrally/skills, which has 268 GitHub stars. The repository holds 34 skills in this directory. The repository was last updated on September 3, 2026.

Source: Mindrally/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.