eBPF skill for Linux observability and networking. An agent skill from mohitmishra786/low-level-dev-skills.

MITAuto-check passedDevOps & Cloud

Install Ebpf

skills CLI
$ npx skills add mohitmishra786/low-level-dev-skills --skill ebpf -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitmishra786/low-level-dev-skills ebpf --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/observability/ebpf .claude/skills/ebpf && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ebpf
GitHub stars
253
Token cost
~2.3k tokens
SKILL.md length
412 words
Files
2 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
MIT

At a glance

eBPF skill for Linux observability and networking. An agent skill from mohitmishra786/low-level-dev-skills.

  • Works in 10 steps: Choose the right tool → bpftrace — quick kernel tracing → libbpf skeleton — minimal C program → …
  • Writing eBPF programs with libbpf
  • SKILL.md covers Purpose, Triggers, Workflow and Related skills
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ebpf is an agent skill from mohitmishra786/low-level-dev-skills. eBPF skill for Linux observability and networking. Use when writing eBPF programs with libbpf or bpftrace, attaching kprobes/tracepoints/XDP hooks, debugging verifier errors, working with eBPF maps, or achieving CO-RE portability across kernel versions. Activates on queries about eBPF, bpftool, bpftrace, XDP programs, libbpf, verifier errors, eBPF maps, or kernel tracing with BPF.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/ebpf-map-types.md`).

It sits in DevOps & Cloud, covering Observability. It works with Linux. The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.

When your agent uses it

  • Writing eBPF programs with libbpf
  • Attaching kprobes/tracepoints/XDP hooks
  • Debugging verifier errors
  • Working with eBPF maps

Example prompts

  • “/ebpf”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Choose the right tool
  2. bpftrace — quick kernel tracing
  3. libbpf skeleton — minimal C program
  4. eBPF map types
  5. Verifier error triage
  6. XDP programs
  7. CO-RE — compile once, run everywhere
  8. BPF ring buffer vs perf buffer
  9. BPF iterators
  10. BPF atomics

What it can do on your machine

Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are c and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ebpf loads about 2.3k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 412 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 412 words, ~2,340 tokens.

Download SKILL.mdSave it as .claude/skills/ebpf/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ebpf
description
eBPF skill for Linux observability and networking. Use when writing eBPF programs with libbpf or bpftrace, attaching kprobes/tracepoints/XDP hooks, debugging verifier errors, working with eBPF maps, or achieving CO-RE portability across kernel versions. Activates on queries about eBPF, bpftool, bpftrace, XDP programs, libbpf, verifier errors, eBPF maps, or kernel tracing with BPF.

eBPF

Purpose

Guide agents through writing, loading, and debugging eBPF programs using libbpf, bpftrace, and bpftool. Covers map types, program types, verifier errors, XDP networking, and CO-RE portability.

Triggers

  • "How do I write an eBPF program to trace system calls?"
  • "My eBPF program fails with a verifier error"
  • "How do I use bpftrace to trace kernel events?"
  • "How do I share data between kernel eBPF and userspace?"
  • "How do I write an XDP program for packet filtering?"
  • "How do I make my eBPF program portable across kernel versions (CO-RE)?"

Workflow

1. Choose the right tool
Goal?
├── One-liner kernel tracing / scripting → bpftrace
├── Production eBPF program with userspace → libbpf (C) or aya (Rust)
├── Inspect loaded programs and maps → bpftool
└── High-performance packet processing → XDP + libbpf
2. bpftrace — quick kernel tracing
bash
# Trace all execve calls with comm and args
bpftrace -e 'tracepoint:syscalls:sys_enter_execve { printf("%s %s\n", comm, str(args->filename)); }'

# Count syscalls by process
bpftrace -e 'tracepoint:raw_syscalls:sys_enter { @[comm] = count(); }'

# Latency histogram for read() syscall
bpftrace -e '
  tracepoint:syscalls:sys_enter_read { @start[tid] = nsecs; }
  tracepoint:syscalls:sys_exit_read  { @us = hist((nsecs - @start[tid]) / 1000); delete(@start[tid]); }'

# List available tracepoints
bpftrace -l 'tracepoint:syscalls:*'
bpftrace -l 'kprobe:tcp_*'
3. libbpf skeleton — minimal C program
c
// counter.bpf.c — kernel-side
#include <vmlinux.h>
#include <bpf/bpf_helpers.h>

struct {
    __uint(type, BPF_MAP_TYPE_HASH);
    __type(key, u32);
    __type(value, u64);
    __uint(max_entries, 1024);
} call_count SEC(".maps");

SEC("tracepoint/syscalls/sys_enter_read")
int trace_read(struct trace_event_raw_sys_enter *ctx)
{
    u32 pid = bpf_get_current_pid_tgid() >> 32;
    u64 *cnt = bpf_map_lookup_elem(&call_count, &pid);
    if (cnt)
        (*cnt)++;
    else {
        u64 one = 1;
        bpf_map_update_elem(&call_count, &pid, &one, BPF_ANY);
    }
    return 0;
}

char LICENSE[] SEC("license") = "GPL";
c
// counter.c — userspace loader
#include "counter.skel.h"

int main(void) {
    struct counter_bpf *skel = counter_bpf__open();
    if (!skel || counter_bpf__load(skel))
        return 1;
    counter_bpf__attach(skel);
    // read map, print results
    counter_bpf__destroy(skel);
}
bash
# Build with libbpf 1.x
clang -g -O2 -target bpf -D__TARGET_ARCH_x86 -I/usr/include/bpf \
      -c counter.bpf.c -o counter.bpf.o
bpftool gen skeleton counter.bpf.o > counter.skel.h
gcc -o counter counter.c -lbpf -lelf -lz

libbpf 1.x API changes:

c
// Open and load (replaces older bpf_object__open/load split patterns)
struct counter_bpf *skel = counter_bpf__open();
counter_bpf__load(skel);
counter_bpf__attach(skel);

// Or explicit file open
struct bpf_object *obj = bpf_object__open_file("counter.bpf.o", NULL);
bpf_object__load(obj);

// Skeleton generation (always via bpftool)
// bpftool gen skeleton counter.bpf.o name counter > counter.skel.h
4. eBPF map types
Map typeKey→ValueUse case
BPF_MAP_TYPE_HASHarbitrary→arbitraryPer-PID counters, state
BPF_MAP_TYPE_ARRAYu32→fixedConfig, metrics indexed by CPU
BPF_MAP_TYPE_PERCPU_HASHkey→per-CPU valHigh-frequency counters without locks
BPF_MAP_TYPE_RINGBUF—Efficient kernel→userspace events
BPF_MAP_TYPE_PERF_EVENT_ARRAY—Legacy perf event output
BPF_MAP_TYPE_LRU_HASHkey→valConnection tracking, limited size
BPF_MAP_TYPE_PROG_ARRAYu32→progTail calls, program chaining
BPF_MAP_TYPE_XSKMAP—AF_XDP socket redirection

Use BPF_MAP_TYPE_RINGBUF over PERF_EVENT_ARRAY for new code — lower overhead, variable-size records.

5. Verifier error triage
Error messageRoot causeFix
invalid mem access 'scalar'Dereferencing unbounded pointerCheck pointer with null test before use
R0 !read_okReturn without setting R0Ensure all paths set a return value
jump out of rangeBranch target beyond program endRestructure conditionals
back-edge detectedBackward jump (loop)Use bpf_loop() helper (kernel ≥5.17) or bounded loop
unreachable insnDead code after returnRemove dead branches
invalid indirect readStack read of uninitialised bytesZero-init structs: struct foo x = {}
misaligned stack accessPointer arithmetic off alignmentAlign reads to __u64 boundaries
bash
# Get detailed verifier log
bpftool prog load prog.bpf.o /sys/fs/bpf/prog type kprobe \
    2>&1 | head -100

# Check loaded programs
bpftool prog list
bpftool prog dump xlated id 42
Show full SKILL.md (144 more words)Show less
6. XDP programs
c
// xdp_drop_icmp.bpf.c
#include <vmlinux.h>
#include <bpf/bpf_helpers.h>
#include <bpf/bpf_endian.h>

SEC("xdp")
int xdp_filter(struct xdp_md *ctx)
{
    void *data_end = (void *)(long)ctx->data_end;
    void *data     = (void *)(long)ctx->data;
    struct ethhdr *eth = data;

    if ((void *)(eth + 1) > data_end)
        return XDP_PASS;

    if (bpf_ntohs(eth->h_proto) != ETH_P_IP)
        return XDP_PASS;

    struct iphdr *ip = (void *)(eth + 1);
    if ((void *)(ip + 1) > data_end)
        return XDP_PASS;

    if (ip->protocol == IPPROTO_ICMP)
        return XDP_DROP;

    return XDP_PASS;
}
char LICENSE[] SEC("license") = "GPL";
bash
# Attach XDP program to interface
ip link set dev eth0 xdp obj xdp_drop_icmp.bpf.o sec xdp
# Remove
ip link set dev eth0 xdp off
# Use native (driver) mode for best performance
ip link set dev eth0 xdp obj prog.bpf.o sec xdp mode native

XDP return codes: XDP_PASS, XDP_DROP, XDP_TX (hairpin), XDP_REDIRECT.

7. CO-RE — compile once, run everywhere

CO-RE (Compile Once - Run Everywhere) uses BTF type info to relocate field accesses at load time.

c
// Use BTF-based field access (CO-RE aware)
#include <vmlinux.h>        // generated from running kernel's BTF
#include <bpf/bpf_core_read.h>

SEC("kprobe/tcp_connect")
int trace_connect(struct pt_regs *ctx)
{
    struct sock *sk = (struct sock *)PT_REGS_PARM1(ctx);
    u16 dport = BPF_CORE_READ(sk, __sk_common.skc_dport);
    // BPF_CORE_READ relocates the field offset at load time
    bpf_printk("connect to port %d\n", bpf_ntohs(dport));
    return 0;
}
bash
# Generate vmlinux.h from running kernel
bpftool btf dump file /sys/kernel/btf/vmlinux format c > vmlinux.h

# Verify BTF is enabled
ls /sys/kernel/btf/vmlinux
8. BPF ring buffer vs perf buffer
c
// Ring buffer (preferred for new programs — better perf, no per-CPU loss)
struct {
    __uint(type, BPF_MAP_TYPE_RINGBUF);
    __uint(max_entries, 256 * 1024);
} rb SEC(".maps");

SEC("kprobe/sys_open")
int handle_open(struct pt_regs *ctx)
{
    struct event *e = bpf_ringbuf_reserve(&rb, sizeof(*e), 0);
    if (!e)
        return 0;
    e->pid = bpf_get_current_pid_tgid() >> 32;
    bpf_ringbuf_submit(e, 0);
    // bpf_ringbuf_discard(e, 0) on error paths
    return 0;
}
FeatureRing bufferPerf buffer
APIbpf_ringbuf_reserve/submitbpf_perf_event_output
BackpressureReserve fails if fullMay drop events
Userspacering_buffer__poll (libbpf)perf_buffer__poll
Multi-producerYesPer-CPU buffers
9. BPF iterators
c
struct {
    __uint(type, BPF_MAP_TYPE_PROG_ARRAY);
    __uint(max_entries, 1);
} iter_prog SEC(".maps");

SEC("iter/task")
int dump_tasks(struct bpf_iter__task *ctx)
{
    struct task_struct *task = ctx->task;
    if (task)
        bpf_seq_printf(ctx->meta->seq, "%d %s\n", task->tgid, task->comm);
    return 0;
}
bash
# Read iterator output from userspace
bpftool prog tracelog   # or attach iter to seq_file reader
cat /sys/kernel/debug/tracing/trace_pipe

Iterators walk kernel data structures (tasks, maps, TCP sockets) without kprobe overhead per element.

10. BPF atomics
c
// GCC/Clang atomic builtins in BPF programs (kernel 5.12+)
static __always_inline void inc_counter(__u32 *counter)
{
    __sync_fetch_and_add(counter, 1);
}

// Use for per-CPU or map-backed counters under concurrent probes

Prefer per-CPU array maps for high-frequency counters; use atomics when aggregating into a single map value.

For the full map types reference, see references/ebpf-map-types.md.

  • Use skills/observability/ebpf-rust for Aya framework Rust eBPF programs
  • Use skills/profilers/linux-perf for perf-based tracing without eBPF
  • Use skills/runtimes/binary-hardening for seccomp-bpf syscall filtering
  • Use skills/low-level-programming/linux-kernel-modules for kernel module development
  • Use skills/async-io/af-xdp for XDP_REDIRECT to AF_XDP sockets

© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/observability/ebpf of mohitmishra786/low-level-dev-skills.

  • SKILL.md
  • references/ebpf-map-types.md

Open the folder on GitHubat commit bdc5847

Compare with similar skills

Ebpf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ebpf compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ebpf this skillmohitmishra786/low-level-dev-skills253—~2.3kAutomated safety check: PassMIT
Implementing Ebpf Security Monitoringmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: NotesApache-2.0
Aliyun Sls Openclaw Integrationcinience/alicloud-skills397—~2.6kAutomated safety check: NotesMIT
Linux Troubleshooting with Inspektor Gadgetinspektor-gadget/inspektor-gadget2.9k—~2.4kAutomated safety check: NotesApache-2.0
Loggingy5-snowies/nourish233—~753Automated safety check: PassApache-2.0
Enterprise Agent Opsaffaan-m/ECC276k4 repos~384Automated safety check: PassMIT

Similar skills

  • Implementing Ebpf Security Monitoring

    mukul975/Anthropic-Cybersecurity-Skills

    Implements eBPF-based security monitoring using Cilium Tetragon for real-time process execution tracking, network connection observability, file access auditing, and runtime enforcement.

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Aliyun Sls Openclaw Integration

    cinience/alicloud-skills

    A skill your agent uses when the user needs to integrate OpenClaw with Alibaba Cloud SLS/Observability, including collector setup, machine groups, indexes, dashboards, collection configs, or Logtail…

    397 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Linux Troubleshooting with Inspektor Gadget

    inspektor-gadget/inspektor-gadget

    Debugs a single Linux host or container runtime at the kernel level with the standalone ig binary and eBPF gadgets, read-only and without Kubernetes.

    2.9k GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Logging

    y5-snowies/nourish

    How to log in the y5 compositor. An agent skill from y5-snowies/nourish.

    233 GitHub stars~753 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Operational controls for long-lived or cloud-hosted agent systems — runtime lifecycle (start, pause, stop, restart), observability (logs, metrics, traces), least-privilege safety scopes and kill…

    276k GitHub starsUsed in 4 repos~384 tokens
    DevOps & CloudAuto-check passed
  • Motel Debug

    kitlangton/motel

    Debug applications with motel, a local OpenTelemetry ingest and query server.

    298 GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from mohitmishra786/low-level-dev-skills

All 138 skills in this repo
  • ARM and AArch64 Assembly

    mohitmishra786/low-level-dev-skills

    Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.

    253 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • RISC-V Assembly Guide

    mohitmishra786/low-level-dev-skills

    Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.

    253 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • x86-64 Assembly Reference

    mohitmishra786/low-level-dev-skills

    Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Bazel for C and C++

    mohitmishra786/low-level-dev-skills

    Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Binary Hardening

    mohitmishra786/low-level-dev-skills

    Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Binutils

    mohitmishra786/low-level-dev-skills

    GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Questions about Ebpf

What does Ebpf do?

eBPF skill for Linux observability and networking. An agent skill from mohitmishra786/low-level-dev-skills. Ebpf is an agent skill from mohitmishra786/low-level-dev-skills. eBPF skill for Linux observability and networking.

When should I use Ebpf?

Ebpf fits situations like: writing eBPF programs with libbpf; attaching kprobes/tracepoints/XDP hooks; debugging verifier errors; working with eBPF maps.

How do I install Ebpf in Claude Code?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill ebpf -a claude-code`. Or copy the skill folder (skills/observability/ebpf in mohitmishra786/low-level-dev-skills) into .claude/skills/ebpf in your project. Claude Code loads it when a task matches its description.

How do I install Ebpf in Codex?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill ebpf -a codex`. Or copy the skill folder (skills/observability/ebpf in mohitmishra786/low-level-dev-skills) into .agents/skills/ebpf in your project. Codex loads it when a task matches its description.

Can I use Ebpf in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill ebpf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ebpf, .gemini/skills/ebpf, .github/skills/ebpf and .opencode/skills/ebpf in your project.

What does Ebpf need to run?

SKILL.md names no scripts, command-line tools or credentials: Ebpf is instructions for the agent only.

Does Ebpf access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ebpf safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ebpf use?

Ebpf is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ebpf use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Ebpf?

Skills that share tags, products or a category with Ebpf: Implementing Ebpf Security Monitoring (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Aliyun Sls Openclaw Integration (cinience/alicloud-skills, 397 stars), Linux Troubleshooting with Inspektor Gadget (inspektor-gadget/inspektor-gadget, 2.9k stars) and Logging (y5-snowies/nourish, 233 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ebpf?

mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 253 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.

Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.