Workspace
Workspace from gabrielmoreira/agent-skills-mirror.
Skills in this plugin
224- ▌ Pyats Dynamic Test · gabrielmoreiraGenerate and execute deterministic pyATS aetest validation scripts - interface state, OSPF neighbors, BGP paths, ping matrices, and custom compliance tests. Use when writing a network test, validating post-change state, running pass/fail checks, or building automated regression tests.
- ▌ Pyats Health Check · gabrielmoreiraComprehensive network device health monitoring - CPU, memory, interfaces, hardware, NTP, logging, environment, and uptime analysis. Use when running a device health check, monitoring CPU or memory usage, checking interface errors, or validating NTP sync.
- ▌ Pyats Junos System · gabrielmoreiraJunOS system operations via pyATS — chassis health, hardware inventory, system info, NTP, SNMP, files/logs, firewall counters, DDoS protection, services accounting. Use when checking Juniper chassis alarms, auditing hardware inventory, reviewing system uptime, or inspecting JunOS firewall counters.
- ▌ Pyats Linux System · gabrielmoreiraLinux host system operations via pyATS — process monitoring, filesystem inspection, Docker container stats, package/tool verification across fleet hosts. Use when checking running processes, monitoring Docker containers, inspecting log files, or verifying system tools on Linux hosts.
- ▌ Pyats Linux Vmware · gabrielmoreiraVMware ESXi host operations via pyATS — VM inventory, snapshot management, hypervisor inspection across ESXi hosts in the testbed. Use when listing VMs on ESXi, checking snapshot age, auditing VMware inventory, or verifying pre-change snapshots exist.
- ▌ Pyats Parallel Ops · gabrielmoreiraFleet-wide parallel device operations - concurrent health checks, config audits, routing snapshots, severity-sorted reporting, and failure-isolated multi-device automation. Use when checking all devices at once, running bulk health checks, collecting configs from the entire fleet, or comparing state across multiple routers and switches.
- ▌ Pyats Troubleshoot · gabrielmoreiraSystematic network troubleshooting - connectivity, routing, interface, protocol, and performance issues using structured OSI-layer and divide-and-conquer methodology. Use when something is broken, a device is unreachable, a link is flapping, users report slow performance, or an OSPF/BGP adjacency is down.
- ▌ Slack User Context · gabrielmoreiraLeverage Slack user profiles, presence, DND status, and workspace context to personalize responses, route escalations, and coordinate team operations. Use when checking who is on-call, routing an escalation, personalizing responses based on user role, or respecting Do Not Disturb before paging someone.
- ▌
- ▌ Webex User Context · gabrielmoreiraLeverage WebEx user profiles, presence status, and workspace context to personalize responses, route escalations, and coordinate team operations. Use when checking who is available, routing an escalation, personalizing responses based on user role, or determining engineer availability before paging someone.
- ▌ Wikipedia Research · gabrielmoreiraResearch networking protocols, standards history, and technology context via Wikipedia - OSPF, BGP, MPLS, 802.1X, VXLAN, and more. Use when looking up protocol background, researching how a technology works, building reference material for the team, or understanding standards history.
- ▌ Aruba Cx Interfaces · gabrielmoreiraMonitor Aruba CX switch interface status, LLDP neighbors, and optical transceiver health
- ▌ Browser Gui Inspect · gabrielmoreiraController-agnostic browser automation and inspection — navigate, read, click, fill, and capture network traffic on any web GUI using a persistent, manually-authenticated Chrome profile. Use to (1) pull a GUI-only report a vendor's REST API doesn't expose, (2) discover the undocumented API behind a dashboard feature, (3) automate a one-off interaction with a web tool that has no NetClaw API integration, or (4) run any of the above in Watch Mode — a real, visible Chrome window an operator can watch work live. Never used to submit, apply, or commit a configuration change — that remains the job of the relevant API-based skill.
- ▌ Clab Lab Management · gabrielmoreiraContainerLab network lab lifecycle management — authenticate, list, deploy, inspect, execute commands on, and destroy containerized network labs via the ContainerLab API. Use when deploying containerized network labs, spinning up SR Linux or cEOS topologies, running commands on lab nodes, or tearing down test environments.
- ▌ Claroty Ot Topology · gabrielmoreiraRender Claroty xDome OT / IoT communication maps and zone segmentation as inline Canvas/A2UI topology, draw.io diagrams, and timeline summaries.
- ▌ Claroty Risk Triage · gabrielmoreiraTriage Claroty xDome alerts and vulnerabilities, compute blast radius, correlate with NVD CVE data, and drive ITSM-gated workflow actions (acknowledge, label, assign, set relevance).
- ▌ Cloudflare Security · gabrielmoreiraMonitor Cloudflare WAF, firewall events, audit logs, and threat intelligence.
- ▌ Cml Node Operations · gabrielmoreiraCML node operations — start, stop, console access, CLI execution, config management, node details. Use when starting or stopping a CML node, running show commands on a lab router, setting startup configs, or reading console logs.
- ▌ Desktop Gui Inspect · gabrielmoreiraFull-desktop automation for targets that have no browser and no API at all — a legacy Java-based NMS client, a vendor's Windows-only configuration utility, a terminal emulator with no scriptable interface. Drives OpenClaw's ClawHub computer-use skill (Xvfb+XFCE virtual desktop, xdotool input automation) to read, confirm, or search state in a desktop-only application. Includes a VNC/noVNC Watch Mode so an operator can watch or take over live, the direct desktop analogue of the Chrome DevTools Watch Mode. Never used to submit, apply, or commit a configuration change — that remains the job of the relevant API-based skill.
- ▌ Document Generation · gabrielmoreiraGenerate Word (.docx), Excel (.xlsx) and PowerPoint (.pptx) documents and fill existing PDF forms, from real NetClaw data, with per-element provenance and no fabrication. Use when someone needs a deliverable rather than an answer — a change record to attach to a CR, an audit workbook for a compliance reviewer, a summary deck for a director, or a required PDF form filled from real device and ticket data.
- ▌ Gns3 Packet Capture · gabrielmoreiraCapture network traffic on GNS3 links - start/stop captures, retrieve PCAP data
- ▌ Halo Change Request · gabrielmoreiraOpen a change request in HaloPSA / HaloITSM through a discover-preview-confirm-submit workflow, with the confirmed change ticket type cached in Memory. Use when raising a Halo change, opening a CR in Halo, submitting a change ticket, or asking NetClaw to file a change in HaloPSA.
- ▌ Halo Ticket Context · gabrielmoreiraReview a HaloPSA / HaloITSM ticket for resolution context — its detail, action/note history, linked assets, and related KB runbooks — read-only. Use when investigating a Halo ticket, gathering resolution context, reading a ticket's note history, or finding runbooks for an open issue.
- ▌ Itential Automation · gabrielmoreiraItential Automation Platform (IAP) — network automation orchestration, device configuration management, compliance enforcement, workflow execution, golden config, lifecycle management, and gateway services via 65+ MCP tools. Use when automating network changes through Itential, running compliance plans, deploying golden configs, or orchestrating IAP workflows
- ▌ Meraki Wireless Ops · gabrielmoreiraCisco Meraki wireless (read-only) — SSID configuration, RF profiles, Air Marshal, channel utilization, signal quality, client connectivity events via Cisco's official Meraki MCP. Use when inspecting Meraki SSIDs, auditing RF configuration, or investigating WiFi connectivity
- ▌
- ▌ Prisma Sdwan Config · gabrielmoreiraInspect Prisma SD-WAN interfaces, routing (BGP, static), policies, and security zones
- ▌ Prisma Sdwan Status · gabrielmoreiraMonitor Prisma SD-WAN element health, software versions, events, and alarms
- ▌ Pyats Junos Routing · gabrielmoreiraJunOS routing operations via pyATS — OSPF/OSPFv3, BGP, route table, MPLS/LDP/RSVP, TED, PFE, ping, traceroute across Juniper devices. Use when checking Juniper OSPF neighbors, viewing BGP summary, inspecting MPLS LSPs, tracing routes, or auditing the JunOS route table.
- ▌ Pyats Linux Network · gabrielmoreiraLinux host network operations via pyATS — interface configuration, routing tables, network connections, and multi-table route inspection across fleet hosts. Use when checking Linux interface status, viewing routing tables, auditing host network config, or comparing routes across hosts.
- ▌ Zabbix Availability · gabrielmoreiraDevice availability and monitored inventory from Zabbix — is a device reachable, since when, how often has it flapped, and what is the NMS actually watching. Use when someone asks how long a device has been down, whether it is flapping, or what is and is not being monitored.
- ▌ Auvik Network Alerts · gabrielmoreiraSurface and triage Auvik network alerts by severity, status, dismissed state, or time window across MSP tenants. Use when reviewing active alerts, investigating a specific device's alert history, filtering by severity (emergency/critical/warning), checking whether alerts are resolved or still open, or pulling alerts within a date range for incident review.
- ▌ AWS Cloud Monitoring · gabrielmoreiraAWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance. Use when checking AWS alarms, analyzing VPC flow logs, investigating network latency, or monitoring VPN and NAT Gateway metrics.
- ▌ Azure Security Audit · gabrielmoreiraAzure NSG compliance auditing and security posture assessment. CIS Azure Foundations Benchmark rules, effective security rule analysis, orphaned NSG detection. Use when auditing Azure NSGs for CIS compliance, checking for overly permissive rules, or reviewing effective security on NICs.
- ▌ Cloudflare Analytics · gabrielmoreiraAccess Cloudflare traffic analytics, logs, and Radar global Internet insights.
- ▌ Cloudflare Zerotrust · gabrielmoreiraInspect Cloudflare Zero Trust access applications, policies, tunnels, and CASB findings.
- ▌ Cml Topology Builder · gabrielmoreiraBuild CML topologies — add nodes, create interfaces, wire links, set link conditioning, add annotations. Use when building a network topology in CML, adding routers or switches to a lab, wiring links between nodes, or simulating WAN conditions.
- ▌ Comfyui Topology Viz · gabrielmoreiraTurn a network topology into one stylized, AI-generated still image via a self-hosted ComfyUI instance — reuses the same topology model as threejs-network-viz (any of 8 topology-source integrations, or a freeform description). Use when the operator asks for a stylized, flashy, or AI-generated image/picture/illustration of a network topology. Stills only — no video/animation.
- ▌ Devnet Meraki Search · gabrielmoreiraSearch Cisco Meraki API documentation and lookup specific operations
- ▌ GCP Cloud Monitoring · gabrielmoreiraGoogle Cloud Monitoring — time series metrics, alert policies, active alerts, metric discovery. Use when checking GCP network performance, investigating firing alerts, querying VM CPU or memory metrics, reviewing Cloud VPN tunnel status, or assessing load balancer latency.
- ▌ Gns3 Link Management · gabrielmoreiraManage GNS3 links - connect/disconnect node interfaces, isolate nodes
- ▌ Gns3 Node Operations · gabrielmoreiraManage GNS3 nodes - add from templates, start/stop/suspend/reload, console access
- ▌ Gtrace Ip Enrichment · gabrielmoreiraIP address enrichment — ASN ownership lookup, geolocation (city/region/country/coordinates), and reverse DNS resolution. Use when identifying who owns an IP address, locating an IP geographically, resolving reverse DNS for a traceroute hop, or enriching unknown IPs from logs or flow data.
- ▌ Gtrace Path Analysis · gabrielmoreiraNetwork path tracing and monitoring — traceroute with MPLS/ECMP/NAT detection, continuous MTR monitoring, and distributed GlobalPing probes from 500+ worldwide locations. Use when tracing the path to a destination, diagnosing slow network routes, detecting MPLS or ECMP load balancing, running MTR for intermittent packet loss, or testing reachability from global vantage points.
- ▌ Humanrail Escalation · gabrielmoreiraHuman-in-the-loop escalation via HumanRail — route low-confidence agent decisions, pre-destructive operation approvals, and ambiguous incident tickets to real human engineers. Human answers are verified and returned as structured output. Workers are paid via Lightning Network. Use when the agent is uncertain, when a destructive change needs explicit human sign-off beyond a ServiceNow CR, or when an ambiguous ticket requires human triage before automated handling.
- ▌ Nmap Scan Management · gabrielmoreiraCustom nmap scans with arbitrary flags, plus scan history retrieval and management. Use when running nmap with custom flags, reviewing past scan results, comparing before/after scans, or retrieving a previous scan by ID
- ▌ Radkit Remote Access · gabrielmoreiraCisco RADKit — cloud-relayed remote device access, CLI execution, SNMP polling, device inventory discovery, attribute inspection. Use when accessing remote network devices through a cloud relay, running CLI on air-gapped devices, polling SNMP metrics remotely, or discovering device inventory via RADKit.
- ▌ Slack Network Alerts · gabrielmoreiraFormat and deliver network alerts, health warnings, and critical notifications via Slack with rich formatting, reactions, and file attachments. Use when sending alerts to Slack, posting health check results, notifying the team about a device issue, or formatting network status updates for a channel.
- ▌ Suzieq Observability · gabrielmoreiraSuzieQ network observability — query current and historical network state, run validation assertions, get summary statistics, trace forwarding paths, and discover unique values across 20+ network tables. Use when investigating BGP/OSPF state, checking interface health, performing time-travel queries, validating network assertions, or tracing packet paths through the network via SuzieQ.
- ▌ Terraform Operations · gabrielmoreiraExecute local Terraform operations with ServiceNow change control.
- ▌
- ▌ Webex Network Alerts · gabrielmoreiraFormat and deliver network alerts, health warnings, and critical notifications via Cisco WebEx with Adaptive Cards, markdown formatting, and file attachments. Use when sending alerts to WebEx spaces, posting health check results, notifying the team about a device issue, or formatting network status updates for a WebEx space.
- ▌ Zoom Meeting Context · gabrielmoreiraZoom meeting intelligence — correlates a live or referenced Zoom meeting discussion against NetClaw's historical meeting record (via the official Zoom Meetings MCP) and today's actual network state. Use when someone in a Zoom meeting references a past discussion or incident ('didn't we have this issue before?'), or asks to search prior meetings for a topic. Does not itself recognize live in-meeting questions — that happens automatically inside zoom-rtms-mcp's own extractor (spec 118) before this skill is ever invoked.
- ▌ Eve Ng Lab Management · gabrielmoreiraManage EVE-NG labs and platform inventory. Use when listing labs, checking lab metadata, creating or deleting labs, importing or exporting lab archives, checking EVE-NG health or auth, or verifying available node images before build work.
- ▌ Gait Session Tracking · gabrielmoreiraGAIT session lifecycle management - branch creation, turn recording, audit logging for every NetClaw operation. Use when starting a new NetClaw session, recording a health check or config change, pinning a pre-change baseline, or viewing the audit trail for a troubleshooting session.
- ▌ Grafana Observability · gabrielmoreiraGrafana observability platform — dashboards, Prometheus PromQL, Loki LogQL, alerting, incidents, OnCall schedules, annotations, datasource queries, panel rendering (75+ tools). Use when querying Grafana dashboards, running PromQL for interface metrics, searching Loki logs for syslog events, investigating firing alerts, or checking who is on call.
- ▌ Hardware Health Check · gabrielmoreiraOut-of-band hardware health via Redfish BMC (read-only) — power state, component health, thermal and power readings, firmware inventory, SEL log triage. Use when determining whether a host is powered off versus unreachable, checking hardware faults, reviewing thermal or PSU state, or triaging BMC event logs
- ▌ Ise Incident Response · gabrielmoreiraRapid ISE endpoint investigation and quarantine workflow - endpoint lookup, auth history, posture review, human-authorized quarantine, ServiceNow Security Incident. Use when a SOC alert flags a compromised endpoint, an unauthorized device is detected on the network, an endpoint is doing port scanning or lateral movement, or you need to quarantine a MAC address in ISE.
- ▌ Network Data Analysis · gabrielmoreiraAd-hoc read-only SQL analysis over exported network data (Zeek logs, Suricata eve.json, generated reports) using DuckDB. Use when aggregating across a packet capture's sessions, correlating IDS alerts with connection metadata, or answering counting and grouping questions that a per-log view cannot
- ▌ Prisma Sdwan Topology · gabrielmoreiraDiscover Prisma SD-WAN sites, ION elements, machines, and network topology