Protocol Reverse Engineering
wshobson/agents
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation.
嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from majiayu000/claude-skill-registry.
$ npx skills add majiayu000/claude-skill-registry --skill net -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install majiayu000/claude-skill-registry net --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bash/net .claude/skills/net && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "net" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/net into .claude/skills/net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "net", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/netType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add majiayu000/claude-skill-registry --skill net -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install majiayu000/claude-skill-registry net --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/bash/net .agents/skills/net && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "net" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/net into .agents/skills/net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "net", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add majiayu000/claude-skill-registry --skill net -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install majiayu000/claude-skill-registry net --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/bash/net .cursor/skills/net && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "net" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/net into .cursor/skills/net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "net", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/majiayu000/claude-skill-registry.git --path skills/bash/net--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add majiayu000/claude-skill-registry --skill net -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install majiayu000/claude-skill-registry net --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/bash/net .gemini/skills/net && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "net" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/net into .gemini/skills/net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "net", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install majiayu000/claude-skill-registry netInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add majiayu000/claude-skill-registry --skill net -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/bash/net .github/skills/net && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "net" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/net into .github/skills/net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "net", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add majiayu000/claude-skill-registry --skill net -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install majiayu000/claude-skill-registry net --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/bash/net .opencode/skills/net && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "net" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/net into .opencode/skills/net/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "net", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
net嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from majiayu000/claude-skill-registry.
Net is an agent skill from majiayu000/claude-skill-registry. 嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计。 当用户提到 Wireshark、tshark、Npcap、抓包、网络联调、端口扫描、连通性排查、pcap 分析、 网络接口、ping 测试、traceroute、流量统计、Modbus TCP、EtherNet/IP 等网络协议调试时自动触发, 也兼容 /net 显式调用。即使用户只是说"抓个包看看"、"扫一下端口"、"网络通不通"或"分析一下这个 pcap", 只要上下文中出现具体工具名(tshark、Wireshark、Npcap)、协议名(Modbus TCP、EtherNet/IP、ICMP 等)、 调试动作(抓包、端口扫描、连通性测试、ping、traceroute、流量统计、pcap 分析)或网络接口操作,就应触发此 skill。
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `metadata.json`).
It sits in Security, covering Network security. It works with Wireshark and Bash. The repository describes itself as: Searchable Claude Code skills catalog with source-linked guides and generated registry artifacts. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2d14a69. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Net loads about 1.1k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 217 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from majiayu000/claude-skill-registry at commit 2d14a69, republished under its MIT licence (© majiayu000). 217 words, ~1,150 tokens.
.claude/skills/net/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.嵌入式网络通信调试工具,统一封装接口发现、抓包、离线分析、连通性测试、端口扫描和流量统计能力。
<skill-dir>/scripts/<skill-dir>/config.json(仅工具路径)<workspace>/.embeddedskills/config.json(网络参数)<skill-dir>/references/common_protocols.jsontshark (随 Wireshark 安装,需加入 PATH)dumpcap (随 Wireshark 安装)capinfosipconfig、ping、tracert、netstat、arp、nslookupskill/config.json)仅保留工具路径相关的环境级配置:
{
"tshark_exe": "tshark",
"capinfos_exe": "capinfos"
}.embeddedskills/config.json)工作区下的 .embeddedskills/config.json 存放工程级网络配置:
{
"net": {
"interface": "",
"target": "",
"capture_filter": "",
"display_filter": "",
"duration": 30,
"timeout_ms": 1000,
"scan_ports": "",
"capture_format": "pcapng",
"log_dir": ".embeddedskills/logs/net"
}
}--interface, --target 等) - 最高优先级.embeddedskills/config.json 中的 net 部分).embeddedskills/state.json 中的历史记录)连接和采集参数按优先级解析,脚本通过 CLI 参数接收覆盖值。若配置缺少必要项或连接失败,询问用户并引导修改配置。
tshark 是否可用;若不可用,提示用户安装 Wireshark(含 tshark)并确认已加入 PATH;若需要抓包,还需提示安装 Npcap 驱动;依赖缺失时终止执行并输出 status: error 及安装指引iface(列出网络接口)python <skill-dir>/scripts/net_iface.py [--filter <关键词>] [--tshark] [--json]--tshark: 同时显示 tshark 抓包接口索引映射--filter: 按关键词筛选接口python <skill-dir>/scripts/net_capture.py [--interface <接口>] [--duration <秒>] [--capture-filter <过滤器>] [--display-filter <过滤器>] [--output <文件路径>] [--format <pcapng|pcap>] [--decode-as <规则>] [--json]--interface: 抓包接口(覆盖配置)--duration: 抓包时长(覆盖配置)--capture-filter: BPF 抓包过滤器(覆盖配置)--display-filter: Wireshark 显示过滤器(覆盖配置)--output: 保存抓包文件路径--json: 输出 JSON Lines 格式(基于 tshark -T ek)--decode-as: 自定义解码规则python <skill-dir>/scripts/net_analyze.py <pcap_file> [--mode <summary|protocols|conversations|endpoints|io|anomalies|all>] [--filter <显示过滤器>] [--top <数量>] [--decode-as <规则>] [--export-fields <字段列表>] [--output <CSV路径>] [--json]--mode all 输出全部分析维度python <skill-dir>/scripts/net_ping.py [--target <目标>] [--tcp <端口>] [--count <次数>] [--traceroute] [--concurrent <线程数>] [--timeout <毫秒>] [--json]--target: 目标地址(覆盖配置)--tcp: TCP 连通性测试(指定端口)--traceroute: 执行路由追踪--timeout: 超时毫秒数(覆盖配置)python <skill-dir>/scripts/net_scan.py [--target <目标>] [--ports <端口范围>] [--timeout <毫秒>] [--banner] [--concurrent <线程数>] [--json]--target: 目标地址(覆盖配置)--ports: 端口范围,如 '80,443,8000-8100'(覆盖配置)--banner: 尝试获取服务 Bannerpython <skill-dir>/scripts/net_stats.py [--interface <接口>] [--duration <秒>] [--display-filter <过滤器>] [--interval <秒>] [--mode <overview|protocol|endpoint|port>] [--json]--interface: 抓包接口(覆盖配置)--duration: 统计时长(覆盖配置)--display-filter: Wireshark 显示过滤器(覆盖配置)所有脚本输出统一的 JSON 结构:
{
"status": "ok",
"action": "<子命令名>",
"summary": "<简要描述>",
"details": { ... }
}错误时:
{
"status": "error",
"action": "<子命令名>",
"error": {
"code": "<错误码>",
"message": "<错误描述>"
}
}capture --json 输出 JSON Lines,进度信息写入 stderr。
.embeddedskills/config.json需要查询嵌入式常用端口和协议映射时,读取 references/common_protocols.json。
© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/bash/net of majiayu000/claude-skill-registry.
Open the folder on GitHubat commit 2d14a69
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in majiayu000/claude-skill-registry, which our catalogue first saw on October 8, 2026.
Net next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Net this skillmajiayu000/claude-skill-registry | 666 | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Protocol Reverse Engineeringwshobson/agents | 40k | 8 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Performing Network Packet Capture Analysismukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Detecting Arp Poisoning In Network Trafficmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | |
| Analyzing Network Traffic For Incidentsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Traffic Analysis Pcapyaklang/hack-skills | 2.4k | — | ~2.8k | Automated safety check: Notes | MIT |
wshobson/agents
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation.
mukul975/Anthropic-Cybersecurity-Skills
Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic…
mukul975/Anthropic-Cybersecurity-Skills
Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC…
mukul975/Anthropic-Cybersecurity-Skills
Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and…
yaklang/hack-skills
Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills.
dslsdzc/rev-skills
物联网协议:MQTT/CoAP/BLE/Zigbee;BLE 链路层(广播解析/配对加密)与 NFC/智能卡(ISO14443/APDU/MIFARE)。
majiayu000/claude-skill-registry
Multi-source deep research using firecrawl and exa MCPs. An agent skill from majiayu000/claude-skill-registry.
majiayu000/claude-skill-registry
Neural search via Exa MCP for web, code, and company research.
majiayu000/claude-skill-registry
Unified media generation via fal.ai MCP — image, video, and audio.
majiayu000/claude-skill-registry
Interact with Zotero reference management libraries using the pyzotero Python client.
majiayu000/claude-skill-registry
Search scientific papers and retrieve structured experimental data extracted from full-text studies via the BGPT MCP server.
majiayu000/claude-skill-registry
Perform pairwise sequence alignment using Biopython Bio.Align.PairwiseAligner.
Categories
嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from majiayu000/claude-skill-registry. Net is an agent skill from majiayu000/claude-skill-registry.
Net fits situations like: tasks that involve Network security.
Run `npx skills add majiayu000/claude-skill-registry --skill net -a claude-code`. Or copy the skill folder (skills/bash/net in majiayu000/claude-skill-registry) into .claude/skills/net in your project. Claude Code loads it when a task matches its description.
Run `npx skills add majiayu000/claude-skill-registry --skill net -a codex`. Or copy the skill folder (skills/bash/net in majiayu000/claude-skill-registry) into .agents/skills/net in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/claude-skill-registry --skill net -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/net, .gemini/skills/net, .github/skills/net and .opencode/skills/net in your project.
Going by SKILL.md and its folder, Net needs the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Net is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Net: Protocol Reverse Engineering (wshobson/agents, 40k stars), Performing Network Packet Capture Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Arp Poisoning In Network Traffic (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Network Traffic For Incidents (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
majiayu000 (a GitHub user) maintains it in majiayu000/claude-skill-registry, which has 666 GitHub stars. The repository holds 1,273 skills in this directory. The repository was last updated on October 7, 2026.
Source: majiayu000/claude-skill-registry on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.