Rust eBPF skill using the Aya framework. An agent skill from mohitmishra786/low-level-dev-skills.

MITAuto-check passedDevelopment

Install Ebpf Rust

skills CLI
$ npx skills add mohitmishra786/low-level-dev-skills --skill ebpf-rust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitmishra786/low-level-dev-skills ebpf-rust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/observability/ebpf-rust .claude/skills/ebpf-rust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ebpf-rust
GitHub stars
253
Token cost
~1.7k tokens
SKILL.md length
258 words
Files
1
Skills in repo
138
Repo updated
First seen
Licence
MIT

At a glance

Rust eBPF skill using the Aya framework. An agent skill from mohitmishra786/low-level-dev-skills.

  • Works in 7 steps: Project setup → Kernel-side BPF program → Userspace loader with tokio → …
  • Writing eBPF programs in Rust with aya-bpf and aya-log
  • SKILL.md covers Purpose, Triggers, Workflow and Related skills
  • Calls cargo; reaches github.com

What it does

Ebpf Rust is an agent skill from mohitmishra786/low-level-dev-skills. Rust eBPF skill using the Aya framework. Use when writing eBPF programs in Rust with aya-bpf and aya-log, defining BPF map types, integrating with tokio userspace, sharing maps between kernel and userspace, or debugging Aya compilation and loading errors. Activates on queries about Aya, aya-bpf, Rust eBPF, aya-log, eBPF in Rust, or BPF programs with tokio.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Observability and Debugging. It works with Rust. The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.

When your agent uses it

  • Writing eBPF programs in Rust with aya-bpf and aya-log
  • Defining BPF map types
  • Integrating with tokio userspace
  • Sharing maps between kernel and userspace

Example prompts

  • “/ebpf-rust”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Project setup
  2. Kernel-side BPF program
  3. Userspace loader with tokio
  4. Map types in Aya
  5. Supported program types
  6. Generating kernel type bindings
  7. Debugging load failures

What it can do on your machine

Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ebpf Rust loads about 1.7k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 258 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 258 words, ~1,651 tokens.

Download SKILL.mdSave it as .claude/skills/ebpf-rust/SKILL.md (or your agent's skills folder).
name
ebpf-rust
description
Rust eBPF skill using the Aya framework. Use when writing eBPF programs in Rust with aya-bpf and aya-log, defining BPF map types, integrating with tokio userspace, sharing maps between kernel and userspace, or debugging Aya compilation and loading errors. Activates on queries about Aya, aya-bpf, Rust eBPF, aya-log, eBPF in Rust, or BPF programs with tokio.

eBPF with Rust (Aya)

Purpose

Guide agents through building production eBPF programs in Rust using the Aya framework: writing kernel-side BPF code with aya-bpf, structured logging with aya-log, sharing maps between BPF and userspace, and integrating with async tokio.

Triggers

  • "How do I write an eBPF program in Rust?"
  • "How do I use the Aya framework?"
  • "How do I share a BPF map between kernel and userspace in Rust?"
  • "How do I log from a BPF program in Rust?"
  • "My Aya program fails to load — how do I debug it?"
  • "How do I integrate an eBPF program with tokio?"

Workflow

1. Project setup
bash
# Install aya-tool (generates bindings from vmlinux BTF)
cargo install aya-tool

# Create new Aya project from template
cargo install cargo-generate
cargo generate https://github.com/aya-rs/aya-template

# Workspace layout (generated)
# my-ebpf/
# ├── my-ebpf-ebpf/    <- kernel-side crate (target: bpf)
# ├── my-ebpf/         <- userspace crate (runs on host)
# └── xtask/           <- build helper (cargo xtask build/run)
bash
# Build both sides
cargo xtask build-ebpf          # builds BPF object
cargo xtask run                 # builds + runs with sudo
2. Kernel-side BPF program
rust
// my-ebpf-ebpf/src/main.rs
#![no_std]
#![no_main]

use aya_bpf::{
    macros::{map, tracepoint},
    maps::HashMap,
    programs::TracePointContext,
    helpers::bpf_get_current_pid_tgid,
};
use aya_log_ebpf::info;

#[map]
static CALL_COUNT: HashMap<u32, u64> = HashMap::with_max_entries(1024, 0);

#[tracepoint]
pub fn trace_read(ctx: TracePointContext) -> u32 {
    let pid = (bpf_get_current_pid_tgid() >> 32) as u32;

    // Lookup or insert
    match unsafe { CALL_COUNT.get(&pid) } {
        Some(count) => {
            let _ = CALL_COUNT.insert(&pid, &(count + 1), 0);
        }
        None => {
            let _ = CALL_COUNT.insert(&pid, &1u64, 0);
        }
    }

    info!(&ctx, "read() called by pid {}", pid);
    0
}

#[panic_handler]
fn panic(_info: &core::panic::PanicInfo) -> ! {
    unsafe { core::hint::unreachable_unchecked() }
}
3. Userspace loader with tokio
rust
// my-ebpf/src/main.rs
use aya::{Bpf, programs::TracePoint, maps::HashMap};
use aya_log::BpfLogger;
use tokio::signal;

#[tokio::main]
async fn main() -> anyhow::Result<()> {
    // Load compiled BPF object (embedded at build time)
    let mut bpf = Bpf::load(include_bytes_aligned!(
        "../../target/bpf/my-ebpf-ebpf.bpf.o"
    ))?;

    // Initialize structured logging from BPF programs
    BpfLogger::init(&mut bpf)?;

    // Attach tracepoint
    let program: &mut TracePoint = bpf.program_mut("trace_read").unwrap().try_into()?;
    program.load()?;
    program.attach("syscalls", "sys_enter_read")?;

    // Read from shared map
    let map: HashMap<_, u32, u64> = HashMap::try_from(bpf.map("CALL_COUNT").unwrap())?;

    // Wait for Ctrl+C
    signal::ctrl_c().await?;

    // Print final counts
    for (pid, count) in map.iter().filter_map(|r| r.ok()) {
        println!("PID {}: {} reads", pid, count);
    }
    Ok(())
}
4. Map types in Aya
rust
use aya_bpf::maps::{HashMap, Array, RingBuf, PerfEventArray, LruHashMap};

// Hash map
#[map]
static MY_MAP: HashMap<u32, u64> = HashMap::with_max_entries(1024, 0);

// Ring buffer (preferred for events)
#[map]
static EVENTS: RingBuf = RingBuf::with_byte_size(256 * 1024, 0);

// LRU hash (connection tracking)
#[map]
static CONNS: LruHashMap<u32, ConnInfo> = LruHashMap::with_max_entries(10000, 0);

// Sending events via RingBuf (kernel side)
if let Ok(mut entry) = unsafe { EVENTS.reserve::<MyEvent>(0) } {
    entry.write(MyEvent { pid, ts });
    entry.submit(0);
}
rust
// Reading RingBuf events (userspace)
use aya::maps::RingBuf;
use tokio::io::unix::AsyncFd;

let ring = RingBuf::try_from(bpf.take_map("EVENTS").unwrap())?;
let mut ring = AsyncFd::new(ring)?;

loop {
    let mut guard = ring.readable_mut().await?;
    let rb = guard.get_inner_mut();
    while let Some(item) = rb.next() {
        let event: &MyEvent = unsafe { &*(item.as_ptr() as *const MyEvent) };
        println!("Event from PID {}", event.pid);
    }
    guard.clear_ready();
}
5. Supported program types
Aya macroProgram typeAttach target
#[tracepoint]Tracepoint"syscalls", "sys_enter_read"
#[kprobe]kprobefunction name
#[kretprobe]kretprobefunction name
#[uprobe]uprobeuserspace binary + offset
#[xdp]XDPnetwork interface
#[tc]TC (traffic control)netdevice + direction
#[socket_filter]Socket filterraw socket fd
#[perf_event]Perf eventperf_event fd
#[lsm]LSM hooksecurity hook name
#[sk_msg]Sockmapsocket map
6. Generating kernel type bindings
bash
# Generate bindings from running kernel's BTF
aya-tool generate task_struct > src/vmlinux.rs

# Or use btf_type_tag and CO-RE
# aya-bpf supports CO-RE via bpf_core_read! macro
rust
// CO-RE field access in Aya
use aya_bpf::helpers::bpf_core_read;

let dport: u16 = unsafe {
    bpf_core_read!(sk, __sk_common.skc_dport)?
};
7. Debugging load failures
bash
# Check verifier errors (Aya surfaces them as Rust errors)
# Run with RUST_LOG=debug for verbose output
RUST_LOG=debug cargo xtask run 2>&1 | grep -A 20 "verifier"

# Check BTF info
bpftool btf dump file /sys/kernel/btf/vmlinux | grep task_struct

# Inspect loaded programs after load
bpftool prog list
bpftool prog dump xlated name trace_read
ErrorCauseFix
invalid mem accessUnbounded pointer dereferenceAdd null check before reading
Type not foundBTF mismatch with kernelRegenerate vmlinux bindings
Permission deniedNo CAP_BPF or CAP_SYS_ADMINRun with sudo or set capability
map already existsMap pinned, name collisionUnpin or rename map
  • Use skills/observability/ebpf for C-based eBPF with libbpf
  • Use skills/rust/rust-async-internals for tokio async patterns used in userspace
  • Use skills/rust/rust-unsafe for unsafe code patterns in BPF helpers

© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/observability/ebpf-rust of mohitmishra786/low-level-dev-skills.

Open the folder on GitHubat commit bdc5847

Compare with similar skills

Ebpf Rust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ebpf Rust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ebpf Rust this skillmohitmishra786/low-level-dev-skills253—~1.7kAutomated safety check: PassMIT
Debugging Techniquesancoleman/ai-design-components526—~3.3kAutomated safety check: PassMIT
Claude Session Router Debuggerweave-os/router5.6k—~2.9kAutomated safety check: PassApache-2.0
Logging Patternsdecebals/claude-code-java7511 repos~3.3kAutomated safety check: PassMIT
Mecatl Perf MCP Interpretationstacklok/mecatl241—~2.3kAutomated safety check: PassApache-2.0
NanoClaw Container Debuggingnanocoai/nanoclaw31k—~3.8kAutomated safety check: NotesMIT

Similar skills

  • Debugging Techniques

    ancoleman/ai-design-components

    Debugging workflows for Python (pdb, debugpy), Go (delve), Rust (lldb), and Node.js, including container debugging (kubectl debug, ephemeral containers) and production-safe debugging techniques with…

    526 GitHub stars~3.3k tokensUpdated 10 mo ago
    DevelopmentAuto-check passed
  • Correlates a Claude Code session's local transcript with a model router's production cloud logs to explain why a specific response rendered the way it did.

    5.6k GitHub stars~2.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Logging Patterns

    decebals/claude-code-java

    Java logging best practices with SLF4J, structured logging (JSON), and MDC for request tracing.

    751 GitHub starsUsed in 1 repo~3.3k tokens
    DevelopmentAuto-check passed
  • Guides reading mecatl's perf MCP data to find why a running harness is slow, leaking goroutines or growing in memory, using cheap reads before any CPU capture.

    241 GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Troubleshooting guide for NanoClaw's containerized agents: where the logs are, how the two session databases show message flow, and how to raise the log level.

    31k GitHub stars~3.8k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • LoopX Performance Diagnosis

    loopx-project/loopx

    Profiles a slow command or runtime you own with the right profiler for its language, using uninstrumented baseline timings and keeping raw profiling evidence local and private.

    6.2k GitHub stars~880 tokensUpdated today
    DevelopmentAuto-check passed

More from mohitmishra786/low-level-dev-skills

All 138 skills in this repo
  • ARM and AArch64 Assembly

    mohitmishra786/low-level-dev-skills

    Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.

    253 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • RISC-V Assembly Guide

    mohitmishra786/low-level-dev-skills

    Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.

    253 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • x86-64 Assembly Reference

    mohitmishra786/low-level-dev-skills

    Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Bazel for C and C++

    mohitmishra786/low-level-dev-skills

    Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Binary Hardening

    mohitmishra786/low-level-dev-skills

    Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Binutils

    mohitmishra786/low-level-dev-skills

    GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Questions about Ebpf Rust

What does Ebpf Rust do?

Rust eBPF skill using the Aya framework. An agent skill from mohitmishra786/low-level-dev-skills. Ebpf Rust is an agent skill from mohitmishra786/low-level-dev-skills. Rust eBPF skill using the Aya framework.

When should I use Ebpf Rust?

Ebpf Rust fits situations like: writing eBPF programs in Rust with aya-bpf and aya-log; defining BPF map types; integrating with tokio userspace; sharing maps between kernel and userspace.

How do I install Ebpf Rust in Claude Code?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill ebpf-rust -a claude-code`. Or copy the skill folder (skills/observability/ebpf-rust in mohitmishra786/low-level-dev-skills) into .claude/skills/ebpf-rust in your project. Claude Code loads it when a task matches its description.

How do I install Ebpf Rust in Codex?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill ebpf-rust -a codex`. Or copy the skill folder (skills/observability/ebpf-rust in mohitmishra786/low-level-dev-skills) into .agents/skills/ebpf-rust in your project. Codex loads it when a task matches its description.

Can I use Ebpf Rust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill ebpf-rust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ebpf-rust, .gemini/skills/ebpf-rust, .github/skills/ebpf-rust and .opencode/skills/ebpf-rust in your project.

What does Ebpf Rust need to run?

Going by SKILL.md and its folder, Ebpf Rust needs the command-line tools its instructions call (cargo).

Does Ebpf Rust access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Ebpf Rust safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ebpf Rust use?

Ebpf Rust is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ebpf Rust use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ebpf Rust?

Skills that share tags, products or a category with Ebpf Rust: Debugging Techniques (ancoleman/ai-design-components, 526 stars), Claude Session Router Debugger (weave-os/router, 5.6k stars), Logging Patterns (decebals/claude-code-java, 751 stars) and Mecatl Perf MCP Interpretation (stacklok/mecatl, 241 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ebpf Rust?

mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 253 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.

Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.