Agent skill

Linux Networking

by RightNow-AI in RightNow-AI/openfang

Linux networking expert for iptables, nftables, routing, DNS, and network troubleshooting

Apache-2.0Auto-check passedDevOps & Cloud

Install Linux Networking

skills CLI
$ npx skills add RightNow-AI/openfang --skill linux-networking -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RightNow-AI/openfang linux-networking --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RightNow-AI/openfang.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/openfang-skills/bundled/linux-networking .claude/skills/linux-networking && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
linux-networking
GitHub stars
18k
Token cost
~882 tokens
SKILL.md length
473 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
Apache-2.0

At a glance

Linux networking expert for iptables, nftables, routing, DNS, and network troubleshooting

  • Tasks that involve Cloud networking
  • SKILL.md covers Key Principles, Techniques, Common Patterns and Pitfalls to Avoid
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Linux Networking is an agent skill from RightNow-AI/openfang. Linux networking expert for iptables, nftables, routing, DNS, and network troubleshooting

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud networking. It works with Linux. The repository describes itself as: Open-source Agent Operating System. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cloud networking

Example prompts

  • “/linux-networking”

What it can do on your machine

Read from SKILL.md and the folder at commit acf2587. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Linux Networking loads about 882 tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 473 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~882

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from RightNow-AI/openfang at commit acf2587, republished under its Apache-2.0 licence (© RightNow-AI). 473 words, ~882 tokens.

Download SKILL.mdSave it as .claude/skills/linux-networking/SKILL.md (or your agent's skills folder).
name
linux-networking
description
Linux networking expert for iptables, nftables, routing, DNS, and network troubleshooting

Linux Networking Expert

A senior systems engineer with extensive expertise in Linux networking internals, firewall configuration, routing policy, DNS resolution, and network diagnostics. This skill provides practical, production-grade guidance for configuring, securing, and troubleshooting Linux network stacks across bare-metal, virtualized, and containerized environments.

Key Principles

  • Understand the packet flow through the kernel: ingress, prerouting, input, forward, output, postrouting chains determine where filtering and NAT decisions occur
  • Use nftables as the modern replacement for iptables; it offers a unified syntax for IPv4, IPv6, ARP, and bridge filtering in a single framework
  • Apply the principle of least privilege to firewall rules: default-deny with explicit allow rules for required traffic
  • Monitor with ss (socket statistics) rather than the deprecated netstat for faster, more detailed connection information
  • Document every routing rule and firewall change; network misconfigurations are among the hardest issues to diagnose retroactively

Techniques

  • Use iptables -L -n -v --line-numbers to inspect rules with packet counters; use -t nat or -t mangle to inspect specific tables
  • Write nftables rulesets in /etc/nftables.conf with named tables and chains; use nft list ruleset to verify and nft -f to reload atomically
  • Configure policy-based routing with ip rule add and ip route add table to route traffic based on source address, mark, or interface
  • Capture traffic with tcpdump -i eth0 -nn -w capture.pcap for offline analysis; filter with host, port, and protocol expressions
  • Diagnose DNS with dig +trace for full delegation chain, and check systemd-resolved status with resolvectl status
  • Create network namespaces with ip netns add for isolated testing; connect them with veth pairs and bridges
  • Tune TCP performance with sysctl parameters: net.core.rmem_max, net.ipv4.tcp_window_scaling, net.ipv4.tcp_congestion_control
  • Configure WireGuard interfaces with wg-quick using [Interface] and [Peer] sections for encrypted point-to-point or hub-spoke VPN topologies
Show full SKILL.md (188 more words)Show less

Common Patterns

  • Port Forwarding: DNAT rule in the PREROUTING chain combined with a FORWARD ACCEPT rule to redirect external traffic to an internal service
  • Network Namespace Isolation: Create a namespace, assign a veth pair, bridge to the host network, and apply per-namespace firewall rules for container-like isolation
  • MTU Discovery: Use ping with -M do (do not fragment) and varying -s sizes to find the path MTU; set interface MTU accordingly to prevent fragmentation
  • Split DNS: Configure systemd-resolved with per-link DNS servers so that internal domains resolve via corporate DNS while public queries go to a public resolver

Pitfalls to Avoid

  • Do not flush iptables rules on a remote machine without first ensuring a scheduled rule restore or out-of-band console access
  • Do not mix iptables and nftables on the same system without understanding that iptables-nft translates rules into nftables internally, which can cause conflicts
  • Do not set overly aggressive TCP keepalive or timeout values on NAT gateways, as this causes silent connection drops for long-lived sessions
  • Do not assume DNS is working just because ping succeeds; ping may use cached results or /etc/hosts entries while application DNS resolution fails

© RightNow-AI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates/openfang-skills/bundled/linux-networking of RightNow-AI/openfang.

Open the folder on GitHubat commit acf2587

Compare with similar skills

Linux Networking next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Linux Networking compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Linux Networking this skillRightNow-AI/openfang18k—~882Automated safety check: PassApache-2.0
Aliyun Swas Managecinience/alicloud-skills3971 repos~1.9kAutomated safety check: PassMIT
Setup Cpu Proxy Serverdrawthingsai/draw-things-community579—~3.8kAutomated safety check: PassGPL-3.0
Nullprivate DeployNullPrivate/NullPrivate111—~2kAutomated safety check: PassGPL-3.0
Linux HardeningBagelHole/DevOps-Security-Agent-Skills1.1k—~662Automated safety check: NotesMIT
Frappe Ops DeploymentImpertio-Studio/Frappe_Claude_Skill_Package187—~2.4kAutomated safety check: NotesMIT

Similar skills

  • Aliyun Swas Manage

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud Simple Application Server (SWAS OpenAPI 2020-06-01) resources end-to-end, including querying instances, starting/stopping/rebooting, executing…

    397 GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Setup Cpu Proxy Server

    drawthingsai/draw-things-community

    Set up and verify a new Draw Things CPU proxy and Envoy server using the scripts in Scripts/ServerManagement/CPUScript.

    579 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Nullprivate Deploy

    NullPrivate/NullPrivate

    构建并发布 NullPrivate 镜像到阿里云容器镜像服务,更新 k3s 工作负载并完成 rollout、镜像 digest、Pod、Service、Gateway/Ingress、HTTPS 与 DNS/DoH 验收。Use when: 推送 dev 镜像、发布 NullPrivate、更新 public3 Pod、部署 adguardprivate、回滚 public3、检查…

    111 GitHub stars~2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Linux Hardening

    BagelHole/DevOps-Security-Agent-Skills

    Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~662 tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes
  • Frappe Ops Deployment

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when deploying Frappe/ERPNext to production, configuring Nginx or Supervisor, setting up Docker, enabling SSL, or hardening security.

    187 GitHub stars~2.4k tokensUpdated 20 days ago
    DevOps & CloudAuto-check: notes
  • Linux Service Triage

    aAAaqwq/AGI-Super-Team

    Diagnoses common Linux service issues using logs, systemd/PM2, file permissions, Nginx reverse proxy checks, and DNS sanity checks.

    105 GitHub starsUsed in 2 repos~799 tokens
    DevOps & CloudAuto-check passed

More from RightNow-AI/openfang

All 68 skills in this repo
  • Reference of CSS selectors, step-by-step web workflows and error recovery tactics for an agent that browses, fills forms and compares prices on live sites.

    18k GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction.

    18k GitHub stars~2.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Lead Generation Research Guide

    RightNow-AI/openfang

    Reference knowledge for AI lead generation: building an ideal customer profile, researching prospects on the web, enriching lead records and finding email formats.

    18k GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Video Clipping Reference

    RightNow-AI/openfang

    Command reference for cutting clips from online video: yt-dlp downloads, whisper transcription, SRT subtitle files and ffmpeg processing, with Windows, macOS and Linux differences.

    18k GitHub stars~4.1k tokensUpdated 3 mo ago
    Auto-check: warnings
  • Forecasting Expert Knowledge

    RightNow-AI/openfang

    Reference knowledge for AI forecasting: superforecasting principles, a signal taxonomy, confidence calibration rules and reasoning chains for making and tracking predictions.

    18k GitHub stars~2.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Deep Research Methodology

    RightNow-AI/openfang

    Reference knowledge for AI deep research: a five-phase process, strategies by question type, CRAAP source scoring, cross-referencing, synthesis and citation formats.

    18k GitHub stars~2.6k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Linux Networking

What does Linux Networking do?

Linux networking expert for iptables, nftables, routing, DNS, and network troubleshooting. Linux Networking is an agent skill from RightNow-AI/openfang.

When should I use Linux Networking?

Linux Networking fits situations like: tasks that involve Cloud networking.

How do I install Linux Networking in Claude Code?

Run `npx skills add RightNow-AI/openfang --skill linux-networking -a claude-code`. Or copy the skill folder (crates/openfang-skills/bundled/linux-networking in RightNow-AI/openfang) into .claude/skills/linux-networking in your project. Claude Code loads it when a task matches its description.

How do I install Linux Networking in Codex?

Run `npx skills add RightNow-AI/openfang --skill linux-networking -a codex`. Or copy the skill folder (crates/openfang-skills/bundled/linux-networking in RightNow-AI/openfang) into .agents/skills/linux-networking in your project. Codex loads it when a task matches its description.

Can I use Linux Networking in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RightNow-AI/openfang --skill linux-networking -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/linux-networking, .gemini/skills/linux-networking, .github/skills/linux-networking and .opencode/skills/linux-networking in your project.

What does Linux Networking need to run?

SKILL.md names no scripts, command-line tools or credentials: Linux Networking is instructions for the agent only.

Does Linux Networking access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Linux Networking safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Linux Networking use?

Linux Networking is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Linux Networking use?

About 882 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Linux Networking?

Skills that share tags, products or a category with Linux Networking: Aliyun Swas Manage (cinience/alicloud-skills, 397 stars), Setup Cpu Proxy Server (drawthingsai/draw-things-community, 579 stars), Nullprivate Deploy (NullPrivate/NullPrivate, 111 stars) and Linux Hardening (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Linux Networking?

RightNow-AI (a GitHub organization) maintains it in RightNow-AI/openfang, which has 18,212 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on July 2, 2026.

Source: RightNow-AI/openfang on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.