Agent skill

Query Snmp Traps

by netdata in netdata/netdata

Query, explain or review SNMP trap logs and recipes through Cloud or an Agent, including severity, senders, dedup, decode errors and TRAP fields.

GPL-3.0Auto-check passedDevOps & Cloud

Install Query Snmp Traps

skills CLI
$ npx skills add netdata/netdata --skill query-snmp-traps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install netdata/netdata query-snmp-traps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/netdata-ai/skills/query-snmp-traps .claude/skills/query-snmp-traps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
query-snmp-traps
GitHub stars
81k
Token cost
~2.1k tokens
SKILL.md length
834 words
Files
9
Skills in repo
27
Repo updated
First seen
Licence
GPL-3.0

At a glance

Query, explain or review SNMP trap logs and recipes through Cloud or an Agent, including severity, senders, dedup, decode errors and TRAP fields.

  • DevOps & Cloud work in your project
  • SKILL.md covers Choose The Task, Guides, Safe Execution and Trap Field Reference, plus 5 more sections
  • Calls git

What it does

Query Snmp Traps is an agent skill from netdata/netdata. Query, explain or review SNMP trap logs and recipes through Cloud or an Agent, including severity, senders, dedup, decode errors and TRAP fields. Guide installed custom-MIB conversion; profile development belongs to collectors-snmp-trap-profiles.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files (for example `fields.md`, `how-tos/INDEX.md` and `how-tos/convert-custom-mibs-to-trap-profiles.md`).

It sits in DevOps & Cloud. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/query-snmp-traps”

What it can do on your machine

Read from SKILL.md and the folder at commit 9fe30d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Query Snmp Traps loads about 2.1k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 834 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from netdata/netdata at commit 9fe30d9, republished under its GPL-3.0 licence (© netdata). 834 words, ~2,134 tokens.

Download SKILL.mdSave it as .claude/skills/query-snmp-traps/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
query-snmp-traps
description
Query, explain or review SNMP trap logs and recipes through Cloud or an Agent, including severity, senders, dedup, decode errors and TRAP_* fields. Guide installed custom-MIB conversion; profile development belongs to collectors-snmp-trap-profiles.

Query SNMP Traps

Use this operator skill for the snmp:traps Function provided by the snmp_traps collector. Direct-journal jobs appear in __logs_sources, normally by listener job name. OTLP-only jobs (journal.enabled: false) create no local journal files and do not appear as local log sources.

Choose The Task

  • Explain or review: read the selected recipe, field reference or helper as reference material. Do not source helpers, load credentials or query live nodes just because this skill was loaded.
  • Run a requested trap query: follow Safe Execution, Standard Setup and the selected recipe. Existing authorization covers ordinary query steps.
  • Convert custom MIBs for an installed Agent: follow the operator conversion recipe. Conversion/review does not authorize installing profiles, restarting jobs or sending MIB content to a classifier endpoint; those operations must be within the user's requested scope.
  • Develop collector code: use the project collectors-authoring skill and the collector's developer owners. Profile/schema work and stock-profile regeneration use collectors-snmp-trap-profiles; query recipes remain available for authorized operator checks.

Guides

TaskHow-to
Recent security traps from one devicehow-tos/recent-security-traps-from-device.md
Critical and emergency traps across a roomhow-tos/filter-by-severity-across-fleet.md
Top trap senders in the last hourhow-tos/top-trap-senders-last-hour.md
Dedup summaries during a flap stormhow-tos/inspect-dedup-summary-entries.md
Filter by indexed varbind fields; inspect TRAP_JSON when neededhow-tos/search-varbind-value-in-trap-json.md
Convert custom MIBs into trap profileshow-tos/convert-custom-mibs-to-trap-profiles.md
Operational how-tos cataloghow-tos/INDEX.md

Safe Execution

Credential-bearing calls MUST use the shared Agent query helpers. Their masked command logging does not sanitize responses or arbitrary body fields. Do not paste Cloud tokens, Agent bearers or token-bearing curl commands. Use the Cloud logs request contract for log query parameters; trap-specific selection and interpretation belong here.

  • Use structured selections first. The Function already scopes to SNMP trap journals; selections.__logs_sources selects a listener job. Usually narrow TRAP_REPORT_TYPE to trap, deduplication_summary or decode_error. Use full-text query only as residual search over the narrowed results.
  • Cloud-proxied calls target one node. For a room/fleet, list nodes, call each node's Function and aggregate locally; the fleet recipe handles current-run isolation, failures and severity-facet filtering.
  • Trap rows, communities, USM secrets, MACs, usernames, public device IPs, customer hostnames and full TRAP_JSON MUST NOT enter durable artifacts. Return summaries; raw output MAY be inspected privately when the user explicitly needs it locally. A hostname/message projection is not automatically sanitized.
  • Capture raw responses in each recipe's private run directory. Local processing MAY use ordinary jq/shell commands; wrapper use is required for credential-bearing requests, not every command in a recipe.

Trap Field Reference

fields.md covers report types, severities, source identity, enrichment, indexed TRAP_VAR_*, TRAP_JSON, suppression and decode-error fields. Read it when interpreting fields; ordinary setup does not need the full field table.

Standard Setup

For an authorized live query, run from the repository checkout with Bash, Git, jq and curl. Follow the shared configuration instructions for local credentials:

bash
source "$(git rev-parse --show-toplevel)/docs/netdata-ai/skills/query-netdata-agents/scripts/_lib.sh"
agents_load_env

Cloud-proxied query, preferred by default; capture discovery privately:

bash
NODE_UUID="YOUR_NODE_UUID"
SNMP_TRAPS_FUNCTION="snmp:traps"

TRAPS_INFO_JSON="$(agents_call_function \
  --via cloud \
  --node "$NODE_UUID" \
  --function "$SNMP_TRAPS_FUNCTION" \
  --body '{"info":true}')"

Direct-agent query when that route is requested. During a Cloud outage it needs a bearer accepted by the cache policy; otherwise the helper still needs Cloud access to mint. There is no automatic transport fallback. See the Agent transport contract.

bash
NODE_UUID="YOUR_NODE_UUID"
AGENT_HOST="agent.example.invalid:19999"
MACHINE_GUID="YOUR_MACHINE_GUID"
SNMP_TRAPS_FUNCTION="snmp:traps"

TRAPS_INFO_JSON="$(agents_call_function \
  --via agent \
  --node "$NODE_UUID" \
  --host "$AGENT_HOST" \
  --machine-guid "$MACHINE_GUID" \
  --function "$SNMP_TRAPS_FUNCTION" \
  --body '{"info":true}')"
Show full SKILL.md (329 more words)Show less

Row Decoding Helper

Use Row Decoding for column-indexed log arrays and private decoded rows.

Source Selection

Start with {"info":true} for snmp:traps and inspect the __logs_sources required parameter. By default, the SDK selects all direct-journal sources. To target one listener job, add:

json
{
  "selections": {
    "__logs_sources": ["local"]
  }
}

If a job is missing from __logs_sources, verify it exists and journal.enabled is not false. Check the running Function response and availability: with no direct-journal trap sources, it can return no sources or an unavailable response. A visible Function name alone does not prove sources exist. The collector handler src/go/plugin/go.d/collector/snmp_traps/internal/snmptrapsfunc/func_logs.go owns that availability check.

Knowledge Capture

  • For answer-only questions, deliver the requested answer. If the work reveals a reusable, evidence-backed recipe not already documented, you MUST preserve a sanitized note with the finding, supporting evidence, and proposed owning guide. In a repository checkout, use <repo-root>/.local/audits/<subject>/followups.md, reusing this skill's audit directory when available. Outside a checkout, use an appropriate local workspace. If no writable workspace is available, include the sanitized follow-up in the response instead.
  • Briefly report reusable documentation discoveries and proposed updates in the answer-only final response, even when recorded locally. Obtain authorization before those guide edits; do not delay the answer while awaiting it.
  • During authorized implementation, you MUST update this skill or its guides for reusable, evidence-backed discoveries made while doing the work, even when the documentation is not required for the code change. This needs no separate authorization. Keep how-tos/INDEX.md consistent and report the updates.
  • Guide edits arising from answer-only questions require separate authorization. Documentation capture records observed behavior; it does not authorize additional implementation or new product contracts. Commit and publication require authorization too.
  • Prefer updating an existing guide over duplicating it. Keep recipes operator-facing: querying and interpreting SNMP traps. Developer validation, schema work, collector implementation, fixtures, and project handoff notes belong in project developer documentation, not in this public skill.

See Also

© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files in docs/netdata-ai/skills/query-snmp-traps of netdata/netdata.

  • SKILL.md
  • fields.md
  • how-tos/INDEX.md
  • how-tos/convert-custom-mibs-to-trap-profiles.md
  • how-tos/filter-by-severity-across-fleet.md
  • how-tos/inspect-dedup-summary-entries.md
  • how-tos/recent-security-traps-from-device.md
  • how-tos/search-varbind-value-in-trap-json.md
  • how-tos/top-trap-senders-last-hour.md

Open the folder on GitHubat commit 9fe30d9

Compare with similar skills

Query Snmp Traps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Query Snmp Traps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Query Snmp Traps this skillnetdata/netdata81k—~2.1kAutomated safety check: PassGPL-3.0
Monitor CInrwl/nx29k5 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 5 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Terraform Skill

    antonbabenko/terraform-skill

    A skill your agent uses when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops - diagnoses failure mode (identity churn, secrets, blast radius, CI drift…

    2.4k GitHub starsUsed in 1 repo~5.1k tokens
    DevOps & CloudAuto-check passed

More from netdata/netdata

All 27 skills in this repo
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Triage Agent Events

    netdata/netdata

    Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.

    81k GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Triage Codacy

    netdata/netdata

    Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

    81k GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Triage Coverity

    netdata/netdata

    Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

    81k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes

Categories

Questions about Query Snmp Traps

What does Query Snmp Traps do?

Query, explain or review SNMP trap logs and recipes through Cloud or an Agent, including severity, senders, dedup, decode errors and TRAP fields. Query Snmp Traps is an agent skill from netdata/netdata. Query, explain or review SNMP trap logs and recipes through Cloud or an Agent, including severity, senders, dedup, decode errors and TRAP fields.

When should I use Query Snmp Traps?

Query Snmp Traps fits situations like: devOps & Cloud work in your project.

How do I install Query Snmp Traps in Claude Code?

Run `npx skills add netdata/netdata --skill query-snmp-traps -a claude-code`. Or copy the skill folder (docs/netdata-ai/skills/query-snmp-traps in netdata/netdata) into .claude/skills/query-snmp-traps in your project. Claude Code loads it when a task matches its description.

How do I install Query Snmp Traps in Codex?

Run `npx skills add netdata/netdata --skill query-snmp-traps -a codex`. Or copy the skill folder (docs/netdata-ai/skills/query-snmp-traps in netdata/netdata) into .agents/skills/query-snmp-traps in your project. Codex loads it when a task matches its description.

Can I use Query Snmp Traps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill query-snmp-traps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/query-snmp-traps, .gemini/skills/query-snmp-traps, .github/skills/query-snmp-traps and .opencode/skills/query-snmp-traps in your project.

What does Query Snmp Traps need to run?

Going by SKILL.md and its folder, Query Snmp Traps needs the command-line tools its instructions call (git).

Does Query Snmp Traps access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Query Snmp Traps safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Query Snmp Traps use?

Query Snmp Traps is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Query Snmp Traps use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Query Snmp Traps?

Skills that share tags, products or a category with Query Snmp Traps: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Query Snmp Traps?

netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,820 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 7, 2026.

Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.