Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add bx33661/Wireshark-MCP --skill wireshark-traffic-analysisgit clone --depth 1 https://github.com/bx33661/Wireshark-MCPWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bx33661/wireshark-mcp/wireshark-traffic-analysis)<a href="https://agentmods.dev/skills/bx33661/wireshark-mcp/wireshark-traffic-analysis"><img src="https://agentmods.dev/badge/skills/bx33661/wireshark-mcp/wireshark-traffic-analysis/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/bx33661/wireshark-mcp/wireshark-traffic-analysis"><img src="https://agentmods.dev/badge/skills/bx33661/wireshark-mcp/wireshark-traffic-analysis.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.00998 |
| Opus 5 | $0.00032 | $0.00499 |
| Sonnet 5 | $0.00013 | $0.00200 |
| Haiku 4.5 | $0.00006 | $0.00100 |
Grade A, and why
wireshark-traffic-analysis scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 48 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent Traffic Investigation — Wireshark MCP
Answer the user's question with reproducible traffic evidence. A narrow question needs a narrow investigation; an unknown capture needs triage. Do not run a security audit or a fixed tool checklist for every capture.
Establish the task
Identify the capture, question, and any host, time window, protocol, or symptom already supplied. Reuse context and previous results. Ask for the capture only when no accessible input is identified; treat an unspecified goal as triage. Unknown capture vantage point is a limitation, not a reason to stop all analysis.
Use the advertised tool schemas and available resources as the execution contract. Profiles differ; a tool named here may be unavailable. Select an available equivalent or explain the missing capability. Do not invent tool arguments or silently switch to shell to bypass an execution restriction.
For an unfamiliar capture, wireshark_open_file obtains metadata and protocol recommendations. It does not activate tools, establish an implicit current file, or certify capture completeness. Continue passing pcap_file explicitly. Skip repeated opening when this context is already known.
Choose the next useful query
| User need | First useful operation | Follow-up only if needed |
|---|---|---|
| Unknown capture | wireshark_quick_analysis |
Fill gaps with endpoints, conversations, or aggregation; do not repeat every overview component |
| Count, distribution, top hosts, timeline | wireshark_aggregate with the relevant filter |
Verify completeness, then inspect a representative frame/stream for important groups |
| A specific host, frame, stream, or failure | Filtered extraction or packet/stream inspection | Broaden only if the local evidence cannot explain it |
| Suspected compromise or root cause | A query distinguishing plausible explanations | Confirm with packet evidence and inspect the strongest counter-explanation |
Read playbooks.md only for the relevant investigation branch. Check uncertain field names and filter syntax through available protocol-field/display-filter resources or the installed engine; reference examples are not an exhaustive field catalog.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago Changed · -67 lines · +7 tokens per session 5e5f6abcc686
- 12d ago First seen · 115 lines · 56 tokens per session scan A 89c9916486e5
wireshark-traffic-analysis is a skill published in the GitHub repository bx33661/Wireshark-MCP (240 stars, last pushed 7d ago), licensed MIT. It adds 63 tokens to every session and 998 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
analyzing-network-traffic-with-wireshark
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
analyzing-network-traffic-with-wireshark
A guide for using Wireshark and tshark to capture and inspect network packets. Packets are the small pieces of data sent across a network; the guide focuses on authorized troubleshooting and security investigations.
analyzing-network-traffic-with-wireshark
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
analyzing-network-traffic-with-wireshark
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
analyzing-network-traffic-with-wireshark
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
analyzing-network-traffic-with-wireshark
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.