
from agent-skills11
Analyze pcap/pcapng captures to produce protocol summaries, evidence-backed IP labeling, PNG visualizations and a structured Markdown report.
Reads pcap/pcapng files and performs rapid triage: checks capture quality, builds protocol and endpoint overviews, labels IPs using DNS/HTTP/TLS SNI/RDAP evidence, generates time-series and ranking PNGs, and assembles a concise Markdown report with findings and unresolved items. It prioritises CLI for initial aggregation and Python for secondary processing and visualization.
Use this skill when handed network captures for incident response, operational troubleshooting, or forensic summary reporting. Ideal for quickly identifying dominant protocols, major conversations, suspicious endpoints, and for producing visual artefacts and reproducible reports.
Works best with security- and ops-focused agents that can call CLI tools and Python libraries (tshark, scapy); suitable for Codex, Copilot, and other code-capable assistants.
This skill has not been reviewed by our automated audit pipeline yet.