netwalk-map

netwalk-map is a skill for Claude Code, Codex from ripmilla/netwalk. It costs 91 tokens per session (1,645 once invoked), scanned A, original, MIT.

A diagram generator that turns a Netwalk network scan record into a self-contained SVG topology map.

In plain words
What is it for?
Creating network diagrams for surveys and reports, with options such as top-down layout and public-safe captions.
Why use it?
It produces a consistent visual layout from the scan's source data, including devices, links, ports, and live system details.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/ripmilla/netwalk/netwalk-map
Any agent
npx skills add ripmilla/netwalk --skill netwalk-map
Clone the repo
git clone --depth 1 https://github.com/ripmilla/netwalk

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for netwalk-map

README.md
[![agentmods](https://agentmods.dev/badge/skills/ripmilla/netwalk/netwalk-map.svg)](https://agentmods.dev/skills/ripmilla/netwalk/netwalk-map)
Your own site
<a href="https://agentmods.dev/skills/ripmilla/netwalk/netwalk-map"><img src="https://agentmods.dev/badge/skills/ripmilla/netwalk/netwalk-map.svg" alt="Measured on agentmods" height="20"></a>
Per session 91 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,645 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00091 $0.01645
Opus 5 $0.00046 $0.00822
Sonnet 5 $0.00018 $0.00329
Haiku 4.5 $0.00009 $0.00164

Measured 6d ago against content hash e54f199184c5, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

netwalk-map scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/netwalk-map/SKILL.md · 117 lines

How it starts

The opening of the file, as written. The whole thing — 117 lines — stays where its author put it; the contents beside it link to each section on GitHub.

netwalk-map

Part of the netwalk read-only network survey toolkit. Toolkit lives at {{TOOLKIT}}.

Run it

python3 {{TOOLKIT}}/scripts/netwalk_map.py ~/.netwalk/sites/acme-hq/scan-2026-08-22.json \
  -o ~/.netwalk/sites/acme-hq/map.svg \
  [--public] [--title "Acme HQ — after the switch swap"] [--top-down] [--no-group-aps]

Output is one self-contained SVG: no external fonts, no scripts, no network requests. It opens in a browser, drops into a document, and follows the reader's light/dark setting. netwalk-fullreport embeds the same renderer, so the diagram in the report and the standalone file never drift apart.

--public drops the scan date and the unreachable-device count from the caption.

The record is the source of truth

The renderer draws only what the record says. Never hand-edit the SVG — fix the record and re-render, or the diagram and the report start telling different stories and the next scan silently reverts your edit.

Layout is deterministic and reads left to right, the way a packet travels: internet uplinks in a column on the left, then the gateway, then each layer of switching, then the edge. Devices are ranked by BFS depth from the gateway and ordered inside each rank to minimise crossings. A rank with more devices than fit in one column wraps into another column rather than running off the page. Same record in, same SVG out — so two scans of one site diff cleanly and a changed diagram means a changed network.

--top-down stacks it vertically instead, which suits a shallow network or a portrait page.

What the record needs for a good diagram

Field Effect if missing
devices[].vendor falls back to a lettered chip instead of a logo
devices[].hostname, mgmt_ip the box is hard to identify
devices[].model, os_version the version line is empty — and version is what people read a diagram for at upgrade time
devices[].role everything lands in one flat rank and the layout stops meaning anything
devices[].health no CPU/RAM/storage/temperature chips
topology_edges[].a_port / b_port links have no port labels, so nobody can trace a cable from the picture
wan_links[] no uplink boxes at all

Read the full file on GitHub · 117 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 117 lines · 91 tokens per session scan A e54f199184c5

Subscribe to this mod's changes

netwalk-map is a skill published in the GitHub repository ripmilla/netwalk (76 stars, last pushed 13d ago), licensed MIT. It adds 91 tokens to every session and 1,645 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

integrated-browser

Use this when working on the VS Code integrated browser ("browserView") to understand its architecture and mental model. Covers the embedded Chromium browser, its editor tab, navigation, overlay/layout, sessions, and agent browser tools under src/vs/platform/browserView and src/vs/workbench/contrib/browserView.

microsoft/vscode · 68 tokens

gke-compute-classes

Configures, optimizes, and troubleshoots GKE ComputeClasses. Use when configuring Spot VMs with on-demand fallback, targeting specific accelerators (GPUs/TPUs) or machine families, restricting ComputeClass access, or debugging pending pods related to node pool auto-creation. Do not use for cluster-level Node Auto…

google/skills · 83 tokens

jetson-diagnostic

Read-only Jetson health snapshot for identity, memory, GPU, thermal, power, storage, services, and top processes.

NVIDIA/skills · 30 tokens

doca-socket-relay

Use this skill when the operator is driving the DOCA Socket Relay to bridge a socket-oriented host application onto a BlueField DPU peer without rewriting it — picking the deployment shape (in-process, sidecar, or BlueField service container), configuring the host-side socket and the DPU-side forwarding endpoint…

NVIDIA/skills · 236 tokens

offensive-z-wave

Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection on unauthenticated nodes, default-key brute-force on test deployments, and home-automation hub pivots. Use when targeting…

SnailSploit/Claude-Red · 113 tokens

hsb-flash

Flash the FPGA on an HSB board connected to an NVIDIA devkit. Supports HSB Lattice boards (FPGA versions 2407, 2412, 2507, 2510) and Leopard Imaging VB1940 "all-in-one" cameras (FPGA versions 2507, 2510). Uses release-specific YAML manifests and board-type-specific program commands. Lattice and VB1940 commands must…

NVIDIA/skills · 94 tokens