嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from majiayu000/claude-skill-registry.

MITAuto-check passedSecurity

Install Net

skills CLI
$ npx skills add majiayu000/claude-skill-registry --skill net -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install majiayu000/claude-skill-registry net --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bash/net .claude/skills/net && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
net
GitHub stars
666
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
217 words
Files
2
Skills in repo
1,273
Repo updated
First seen
Licence
MIT

At a glance

嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from majiayu000/claude-skill-registry.

  • Works in 4 steps: CLI 参数 (--interface, --target 等) - 最高优先级 → 工程级配置 (.embeddedskills/config.json 中的… → 状态文件 (.embeddedskills/state.json 中的历史记录) → …
  • Tasks that involve Network security
  • SKILL.md covers 脚本与配置路径, 依赖, 配置 and 执行流程, plus 4 more sections
  • Calls python

What it does

Net is an agent skill from majiayu000/claude-skill-registry. 嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计。 当用户提到 Wireshark、tshark、Npcap、抓包、网络联调、端口扫描、连通性排查、pcap 分析、 网络接口、ping 测试、traceroute、流量统计、Modbus TCP、EtherNet/IP 等网络协议调试时自动触发, 也兼容 /net 显式调用。即使用户只是说"抓个包看看"、"扫一下端口"、"网络通不通"或"分析一下这个 pcap", 只要上下文中出现具体工具名(tshark、Wireshark、Npcap)、协议名(Modbus TCP、EtherNet/IP、ICMP 等)、 调试动作(抓包、端口扫描、连通性测试、ping、traceroute、流量统计、pcap 分析)或网络接口操作,就应触发此 skill。

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `metadata.json`).

It sits in Security, covering Network security. It works with Wireshark and Bash. The repository describes itself as: Searchable Claude Code skills catalog with source-linked guides and generated registry artifacts. The licence is MIT.

When your agent uses it

  • Tasks that involve Network security

Example prompts

  • “分析一下这个 pcap”
  • “/net”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. CLI 参数 (--interface, --target 等) - 最高优先级
  2. 工程级配置 (.embeddedskills/config.json 中的 net 部分)
  3. 状态文件 (.embeddedskills/state.json 中的历史记录)
  4. 默认值 - 最低优先级

What it can do on your machine

Read from SKILL.md and the folder at commit 2d14a69. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Net loads about 1.1k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 217 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from majiayu000/claude-skill-registry at commit 2d14a69, republished under its MIT licence (© majiayu000). 217 words, ~1,150 tokens.

Download SKILL.mdSave it as .claude/skills/net/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
net
description
嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计。 当用户提到 Wireshark、tshark、Npcap、抓包、网络联调、端口扫描、连通性排查、pcap 分析、 网络接口、ping 测试、traceroute、流量统计、Modbus TCP、EtherNet/IP 等网络协议调试时自动触发, 也兼容 /net 显式调用。即使用户只是说"抓个包看看"、"扫一下端口"、"网络通不通"或"分析一下这个 pcap", 只要上下文中出现具体工具名(tshark、Wireshark、Npcap)、协议名(Modbus TCP、EtherNet/IP、ICMP 等)、 调试动作(抓包、端口扫描、连通性测试、ping、traceroute、流量统计、pcap 分析)或网络接口操作,就应触发此 skill。
argument-hint
[iface|capture|analyze|ping|scan|stats] ...

Net Debug Skill

嵌入式网络通信调试工具,统一封装接口发现、抓包、离线分析、连通性测试、端口扫描和流量统计能力。

脚本与配置路径

  • 脚本目录: <skill-dir>/scripts/
  • 环境级配置: <skill-dir>/config.json(仅工具路径)
  • 工程级配置: <workspace>/.embeddedskills/config.json(网络参数)
  • 协议参考: <skill-dir>/references/common_protocols.json

依赖

  • tshark (随 Wireshark 安装,需加入 PATH)
  • dumpcap (随 Wireshark 安装)
  • 可选: capinfos
  • Windows 自带: ipconfig、ping、tracert、netstat、arp、nslookup
  • Python 3.x (仅标准库)
  • 抓包需要 Npcap 驱动,部分环境需管理员权限

配置

环境级配置 (skill/config.json)

仅保留工具路径相关的环境级配置:

json
{
  "tshark_exe": "tshark",
  "capinfos_exe": "capinfos"
}
工程级配置 (.embeddedskills/config.json)

工作区下的 .embeddedskills/config.json 存放工程级网络配置:

json
{
  "net": {
    "interface": "",
    "target": "",
    "capture_filter": "",
    "display_filter": "",
    "duration": 30,
    "timeout_ms": 1000,
    "scan_ports": "",
    "capture_format": "pcapng",
    "log_dir": ".embeddedskills/logs/net"
  }
}
参数解析优先级
  1. CLI 参数 (--interface, --target 等) - 最高优先级
  2. 工程级配置 (.embeddedskills/config.json 中的 net 部分)
  3. 状态文件 (.embeddedskills/state.json 中的历史记录)
  4. 默认值 - 最低优先级

连接和采集参数按优先级解析,脚本通过 CLI 参数接收覆盖值。若配置缺少必要项或连接失败,询问用户并引导修改配置。

执行流程

  1. 检查 tshark 是否可用;若不可用,提示用户安装 Wireshark(含 tshark)并确认已加入 PATH;若需要抓包,还需提示安装 Npcap 驱动;依赖缺失时终止执行并输出 status: error 及安装指引
  2. 按优先级解析参数:CLI > 工程级配置 > 状态文件 > 默认值;若多个来源对同一参数均有值,以更高优先级来源为准,并在输出 summary 中注明被覆盖的来源
  3. 若无子命令,默认执行 iface(列出网络接口)
  4. 成功执行后,将确认的参数写回工程配置
  5. 运行对应脚本并输出结构化 JSON 结果
  6. 失败时优先提示权限、Npcap、过滤器、接口选择等问题

子命令

iface — 列出网络接口
bash
python <skill-dir>/scripts/net_iface.py [--filter <关键词>] [--tshark] [--json]
  • --tshark: 同时显示 tshark 抓包接口索引映射
  • --filter: 按关键词筛选接口
  • 无副作用,可直接执行
capture — 抓包
bash
python <skill-dir>/scripts/net_capture.py [--interface <接口>] [--duration <秒>] [--capture-filter <过滤器>] [--display-filter <过滤器>] [--output <文件路径>] [--format <pcapng|pcap>] [--decode-as <规则>] [--json]
  • 接口、过滤器、时长按优先级解析
  • --interface: 抓包接口(覆盖配置)
  • --duration: 抓包时长(覆盖配置)
  • --capture-filter: BPF 抓包过滤器(覆盖配置)
  • --display-filter: Wireshark 显示过滤器(覆盖配置)
  • --output: 保存抓包文件路径
  • --json: 输出 JSON Lines 格式(基于 tshark -T ek)
  • --decode-as: 自定义解码规则
  • 默认格式 pcapng,参数完整后直接执行
analyze — 分析 pcap 文件
bash
python <skill-dir>/scripts/net_analyze.py <pcap_file> [--mode <summary|protocols|conversations|endpoints|io|anomalies|all>] [--filter <显示过滤器>] [--top <数量>] [--decode-as <规则>] [--export-fields <字段列表>] [--output <CSV路径>] [--json]
  • 基于 tshark 和 capinfos 进行离线分析
  • --mode all 输出全部分析维度
  • 无副作用,可直接执行
ping — 连通性测试
bash
python <skill-dir>/scripts/net_ping.py [--target <目标>] [--tcp <端口>] [--count <次数>] [--traceroute] [--concurrent <线程数>] [--timeout <毫秒>] [--json]
  • 目标按优先级解析
  • --target: 目标地址(覆盖配置)
  • --tcp: TCP 连通性测试(指定端口)
  • --traceroute: 执行路由追踪
  • --timeout: 超时毫秒数(覆盖配置)
  • 参数完整后直接执行
scan — 端口扫描
bash
python <skill-dir>/scripts/net_scan.py [--target <目标>] [--ports <端口范围>] [--timeout <毫秒>] [--banner] [--concurrent <线程数>] [--json]
  • 目标和端口范围按优先级解析
  • --target: 目标地址(覆盖配置)
  • --ports: 端口范围,如 '80,443,8000-8100'(覆盖配置)
  • --banner: 尝试获取服务 Banner
  • 默认收敛到嵌入式常用端口集
  • 参数完整后直接执行
stats — 流量统计
bash
python <skill-dir>/scripts/net_stats.py [--interface <接口>] [--duration <秒>] [--display-filter <过滤器>] [--interval <秒>] [--mode <overview|protocol|endpoint|port>] [--json]
  • 接口和时长按优先级解析
  • --interface: 抓包接口(覆盖配置)
  • --duration: 统计时长(覆盖配置)
  • --display-filter: Wireshark 显示过滤器(覆盖配置)
  • 默认输出按时段汇总的 JSON
  • 无副作用,可直接执行

输出格式

所有脚本输出统一的 JSON 结构:

json
{
  "status": "ok",
  "action": "<子命令名>",
  "summary": "<简要描述>",
  "details": { ... }
}

错误时:

json
{
  "status": "error",
  "action": "<子命令名>",
  "error": {
    "code": "<错误码>",
    "message": "<错误描述>"
  }
}

capture --json 输出 JSON Lines,进度信息写入 stderr。

交互策略

  • 按优先级解析参数:CLI > 工程级配置 > 状态文件 > 默认值
  • 优先用解析后的参数直接执行,不额外询问
  • 连接失败时再询问用户并引导修改配置
  • 成功执行后,确认的参数自动写回 .embeddedskills/config.json
  • 未给扫描范围时默认收敛到单主机、小范围端口
  • 结果中明确回显目标范围、过滤器和持续时间
  • 抓包结果优先总结异常协议、重传、RST 等
  • 抓包失败优先提示权限和 Npcap 问题

协议参考

需要查询嵌入式常用端口和协议映射时,读取 references/common_protocols.json。

© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/bash/net of majiayu000/claude-skill-registry.

  • SKILL.md
  • metadata.json

Open the folder on GitHubat commit 2d14a69

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in majiayu000/claude-skill-registry, which our catalogue first saw on October 8, 2026.

Compare with similar skills

Net next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Net compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Net this skillmajiayu000/claude-skill-registry6661 repos~1.1kAutomated safety check: PassMIT
Protocol Reverse Engineeringwshobson/agents40k8 repos~3.2kAutomated safety check: PassMIT
Performing Network Packet Capture Analysismukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Detecting Arp Poisoning In Network Trafficmukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: NotesApache-2.0
Analyzing Network Traffic For Incidentsmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.0
Traffic Analysis Pcapyaklang/hack-skills2.4k—~2.8kAutomated safety check: NotesMIT

Similar skills

  • Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation.

    40k GitHub starsUsed in 8 repos~3.2k tokens
    SecurityAuto-check passed
  • Performing Network Packet Capture Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Arp Poisoning In Network Traffic

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC…

    34k GitHub stars~3.8k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Analyzing Network Traffic For Incidents

    mukul975/Anthropic-Cybersecurity-Skills

    Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Traffic Analysis Pcap

    yaklang/hack-skills

    Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~2.8k tokensUpdated 24 days ago
    SecurityAuto-check: notes
  • Re Iot Proto

    dslsdzc/rev-skills

    物联网协议:MQTT/CoAP/BLE/Zigbee;BLE 链路层(广播解析/配对加密)与 NFC/智能卡(ISO14443/APDU/MIFARE)。

    125 GitHub stars~3.2k tokensUpdated 2 days ago
    SecurityAuto-check: notes

More from majiayu000/claude-skill-registry

All 1,273 skills in this repo
  • Deep Research

    majiayu000/claude-skill-registry

    Multi-source deep research using firecrawl and exa MCPs. An agent skill from majiayu000/claude-skill-registry.

    666 GitHub starsUsed in 6 repos~1.1k tokens
    Auto-check passed
  • Exa Search

    majiayu000/claude-skill-registry

    Neural search via Exa MCP for web, code, and company research.

    666 GitHub starsUsed in 5 repos~856 tokens
    Auto-check passed
  • Fal AI Media

    majiayu000/claude-skill-registry

    Unified media generation via fal.ai MCP — image, video, and audio.

    666 GitHub starsUsed in 5 repos~1.7k tokens
    Auto-check passed
  • Pyzotero

    majiayu000/claude-skill-registry

    Interact with Zotero reference management libraries using the pyzotero Python client.

    666 GitHub starsUsed in 5 repos~1.6k tokens
    Auto-check: notes
  • Bgpt Paper Search

    majiayu000/claude-skill-registry

    Search scientific papers and retrieve structured experimental data extracted from full-text studies via the BGPT MCP server.

    666 GitHub starsUsed in 4 repos~619 tokens
    Auto-check: notes
  • Bio Alignment Pairwise

    majiayu000/claude-skill-registry

    Perform pairwise sequence alignment using Biopython Bio.Align.PairwiseAligner.

    666 GitHub starsUsed in 4 repos~1.7k tokens
    Auto-check passed

Works with

Categories

Questions about Net

What does Net do?

嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from majiayu000/claude-skill-registry. Net is an agent skill from majiayu000/claude-skill-registry.

When should I use Net?

Net fits situations like: tasks that involve Network security.

How do I install Net in Claude Code?

Run `npx skills add majiayu000/claude-skill-registry --skill net -a claude-code`. Or copy the skill folder (skills/bash/net in majiayu000/claude-skill-registry) into .claude/skills/net in your project. Claude Code loads it when a task matches its description.

How do I install Net in Codex?

Run `npx skills add majiayu000/claude-skill-registry --skill net -a codex`. Or copy the skill folder (skills/bash/net in majiayu000/claude-skill-registry) into .agents/skills/net in your project. Codex loads it when a task matches its description.

Can I use Net in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/claude-skill-registry --skill net -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/net, .gemini/skills/net, .github/skills/net and .opencode/skills/net in your project.

What does Net need to run?

Going by SKILL.md and its folder, Net needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Net access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Net safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Net use?

Net is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Net use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Net?

Skills that share tags, products or a category with Net: Protocol Reverse Engineering (wshobson/agents, 40k stars), Performing Network Packet Capture Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Arp Poisoning In Network Traffic (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Network Traffic For Incidents (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Net?

majiayu000 (a GitHub user) maintains it in majiayu000/claude-skill-registry, which has 666 GitHub stars. The repository holds 1,273 skills in this directory. The repository was last updated on October 7, 2026.

Source: majiayu000/claude-skill-registry on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.