Install the "traffic-analysis-pcap" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/traffic-analysis-pcap into .claude/skills/traffic-analysis-pcap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "traffic-analysis-pcap", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add yaklang/hack-skills --skill traffic-analysis-pcap -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "traffic-analysis-pcap" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/traffic-analysis-pcap into .agents/skills/traffic-analysis-pcap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "traffic-analysis-pcap", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add yaklang/hack-skills --skill traffic-analysis-pcap -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "traffic-analysis-pcap" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/traffic-analysis-pcap into .cursor/skills/traffic-analysis-pcap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "traffic-analysis-pcap", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add yaklang/hack-skills --skill traffic-analysis-pcap -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "traffic-analysis-pcap" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/traffic-analysis-pcap into .gemini/skills/traffic-analysis-pcap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "traffic-analysis-pcap", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add yaklang/hack-skills --skill traffic-analysis-pcap -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "traffic-analysis-pcap" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/traffic-analysis-pcap into .github/skills/traffic-analysis-pcap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "traffic-analysis-pcap", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add yaklang/hack-skills --skill traffic-analysis-pcap -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "traffic-analysis-pcap" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/traffic-analysis-pcap into .opencode/skills/traffic-analysis-pcap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "traffic-analysis-pcap", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
traffic-analysis-pcap
GitHub stars
2.4k
Token cost
~2.8k tokens
SKILL.md length
200 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
MIT
At a glance
Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills.
Works in 8 steps: RELATED ROUTING → PCAP REPAIR → WIRESHARK ESSENTIAL FILTERS → …
Analyzing network captures including Wireshark filters
SKILL.md covers 0. RELATED ROUTING, 1. PCAP REPAIR, 2. WIRESHARK ESSENTIAL FILTERS and 3. PROTOCOL ANALYSIS, plus 4 more sections
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Traffic Analysis Pcap is an agent skill from yaklang/hack-skills. Traffic analysis and PCAP forensics playbook. Use when analyzing network captures including Wireshark filters, protocol analysis (HTTP/DNS/FTP/SMTP/USB/WiFi), data extraction, covert channel detection, PCAP repair, TLS decryption, and tshark command-line analysis.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Transactional email and Network security. It works with Wireshark. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.
When your agent uses it
Analyzing network captures including Wireshark filters
Protocol analysis (HTTP/DNS/FTP/SMTP/USB/WiFi)
Data extraction
Covert channel detection
Example prompts
“/traffic-analysis-pcap”
Workflow steps
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Traffic Analysis Pcap loads about 2.8k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 200 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~72
When it runs· the whole SKILL.md, loaded when a task matches
~2.8k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: notes
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/traffic-analysis-pcap/SKILL.md (or your agent's skills folder).
name
traffic-analysis-pcap
description
Traffic analysis and PCAP forensics playbook. Use when analyzing network captures including Wireshark filters, protocol analysis (HTTP/DNS/FTP/SMTP/USB/WiFi), data extraction, covert channel detection, PCAP repair, TLS decryption, and tshark command-line analysis.
ip.addr == 10.0.0.1 # source or destination
ip.src == 10.0.0.1 # source only
ip.dst == 10.0.0.1 # destination only
ip.addr == 10.0.0.0/24 # subnet
!(ip.addr == 10.0.0.1) # exclude host
Protocol Filters
http # all HTTP
dns # all DNS
tcp # all TCP
ftp # all FTP
smtp # all SMTP
tls # all TLS/SSL
icmp # all ICMP
arp # all ARP
TCP / Stream
tcp.stream eq 5 # follow specific TCP stream
tcp.port == 80 # traffic on port 80
tcp.flags.syn == 1 && tcp.flags.ack == 0 # SYN packets (connection starts)
tcp.analysis.retransmission # retransmitted packets
tcp.len > 0 # packets with payload
HTTP
http.request.method == "POST" # POST requests
http.request.method == "GET" # GET requests
http.response.code == 200 # successful responses
http.response.code >= 400 # error responses
http.request.uri contains "login" # URI contains string
http.host contains "target.com" # specific host
http.content_type contains "json" # JSON responses
http.cookie contains "session" # session cookies
http.request.full_uri # show full URIs (column)
DNS
dns.qry.name contains "evil.com" # specific domain queries
dns.qry.type == 1 # A records
dns.qry.type == 28 # AAAA records
dns.qry.type == 16 # TXT records
dns.flags.response == 1 # DNS responses only
dns.resp.len > 100 # large DNS responses
# Indicators of DNS tunneling:
# 1. Unusually long subdomain names (>30 chars)
# 2. High volume of TXT record queries/responses
# 3. Consistent query patterns to same domain
# 4. Base32/Base64-like subdomain strings
# 5. High query frequency from single host
# Wireshark filter for suspicious DNS:
dns.qry.name.len > 50 # long query names
dns.qry.type == 16 # TXT records (common for tunneling)
dns.resp.len > 512 # large DNS responses
# tshark extraction:
tshark -r capture.pcap -Y "dns.qry.type==16" -T fields -e dns.qry.name
FTP — Credential & File Extraction
bash
# FTP credentials (plaintext)
# Filter: ftp.request.command == "USER" || ftp.request.command == "PASS"
# FTP file transfer reconstruction:
# FTP uses separate data channel (usually port 20 or dynamic)
# Follow TCP stream of data connection to extract file
# tshark:
tshark -r capture.pcap -Y "ftp.request.command==USER || ftp.request.command==PASS" -T fields -e ftp.request.arg
# ICMP payload analysis
# Normal ping: 32 or 64 bytes of pattern data
# Exfiltration: meaningful data in ICMP payload
# Filter:
icmp && data.len > 48 # unusual ICMP payload size
icmp.type == 8 # echo requests
# Extract ICMP payloads:
tshark -r capture.pcap -Y "icmp.type==8" -T fields -e data.data
4. DATA EXTRACTION
File Carving
bash
# Wireshark: File → Export Objects
# Supported: HTTP, SMB, TFTP, IMF (email), DICOM
# Manual from reassembled stream:
# Follow TCP Stream → Show as Raw → Save As
# binwalk on exported stream data
binwalk -e exported_stream.bin
foremost -i exported_stream.bin -o carved/
Indicators: DNS with long subdomains, ICMP with large payloads, HTTP with encoded headers, regular beacon intervals (C2). Use tshark -q -z io,stat,1 and -z conv,tcp for statistical anomaly detection.
5. NETWORKMINER
bash
# Automated PCAP analysis: sudo apt install networkminer
# Open PCAP → auto-extracts: Files, Images, Credentials, Sessions, DNS
# Files tab: carved from HTTP/SMB/FTP | Credentials tab: plaintext creds
Traffic Analysis Pcap next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Traffic Analysis Pcap compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Traffic Analysis Pcap this skillyaklang/hack-skills
This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…
Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills. Traffic Analysis Pcap is an agent skill from yaklang/hack-skills. Traffic analysis and PCAP forensics playbook.
When should I use Traffic Analysis Pcap?
Traffic Analysis Pcap fits situations like: analyzing network captures including Wireshark filters; protocol analysis (HTTP/DNS/FTP/SMTP/USB/WiFi); data extraction; covert channel detection.
How do I install Traffic Analysis Pcap in Claude Code?
Run `npx skills add yaklang/hack-skills --skill traffic-analysis-pcap -a claude-code`. Or copy the skill folder (skills/traffic-analysis-pcap in yaklang/hack-skills) into .claude/skills/traffic-analysis-pcap in your project. Claude Code loads it when a task matches its description.
How do I install Traffic Analysis Pcap in Codex?
Run `npx skills add yaklang/hack-skills --skill traffic-analysis-pcap -a codex`. Or copy the skill folder (skills/traffic-analysis-pcap in yaklang/hack-skills) into .agents/skills/traffic-analysis-pcap in your project. Codex loads it when a task matches its description.
Can I use Traffic Analysis Pcap in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill traffic-analysis-pcap -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/traffic-analysis-pcap, .gemini/skills/traffic-analysis-pcap, .github/skills/traffic-analysis-pcap and .opencode/skills/traffic-analysis-pcap in your project.
What does Traffic Analysis Pcap need to run?
SKILL.md names no scripts, command-line tools or credentials: Traffic Analysis Pcap is instructions for the agent only.
Does Traffic Analysis Pcap access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Traffic Analysis Pcap safe to install?
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
What licence does Traffic Analysis Pcap use?
Traffic Analysis Pcap is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Traffic Analysis Pcap use?
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Traffic Analysis Pcap?
Skills that share tags, products or a category with Traffic Analysis Pcap: Performing Network Traffic Analysis With Zeek (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Wireshark Analysis (zebbern/claude-code-guide, 4.7k stars), Iotnet (BrownFineSecurity/iothackbot, 859 stars) and Protocol Reverse Engineering (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Traffic Analysis Pcap?
yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,409 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on September 13, 2026.
Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.