fabric-aiops
Use this skill whenever the user needs to operate a network fabric through a controller API — Cisco Meraki Dashboard (full read+write), Cisco Catalyst Center / DNA Center (read subset), Arista CloudVision Portal / CVP (read subset), or UniFi Network (self-hosted controller / UniFi OS console; read subset + device restart) — a one-shot fabric health overview; organization/site/container reads (list/get, licensing, admins, org-wide device statuses, API usage); network reads (list/get, VLANs, health alerts, traffic); device reads (inventory by model MX/MS/MR/MV/MG, status, uplinks, switch ports / interface stats, wireless SSIDs); client reads (list, detail, usage, connectivity); three flagship analyses — uplink loss & latency RCA (rank worst MX WAN uplinks + cause/action), network health score (composite per-network), and config template drift (settings drifted from a bound template); and eight guarded writes (reboot, blink LEDs, update device, update VLAN, claim/remove devices, bind/unbind a config template — Meraki-only except device restart, which unifi also maps; other unmapped writes return a teaching "not supported yet" error). Always use this skill for "Meraki org overview", "which uplinks are worst", "uplink loss and latency", "WAN degradation RCA", "network health score", "config template drift", "list Meraki networks/devices/clients", "reboot a Meraki device", "blink device LEDs", "claim a device into a network", "bind a network to a template", "Catalyst Center site health / device health / issues", "DNA Center inventory", "CloudVision inventory / compliance / events", "UniFi site health / alarms / clients", "restart a UniFi AP or switch" when the context is a controller-managed network fabric. Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a container/cluster orchestrator, or device-level CLI/SSH network automation (negative routing hints only). Covers common controller fabric operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; no platform has yet been exercised against a live controller (see docs/VERIFICATION.md).
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
0.12.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.12.0release · observed Sep 21, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:fabric-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:fabric-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/fabric-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-fabric-aiops/snapshot"
Documentation
CLAWHUB
151,282 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: fabric-aiops
slug: fabric-aiops
displayName: "Fabric AIops"
summary: "Governed Cisco Meraki + ACI fabric ops: uplink RCA, ACI endpoint trace; 37 tools with audit/undo."
license: MIT
homepage: https://github.com/AIops-tools/Fabric-AIops
tags: [aiops, mcp, governance, fabric]
description: >
Use this skill whenever the user needs to operate a network fabric through a controller API — Cisco Meraki Dashboard (full read+write), Cisco Catalyst Center / DNA Center (read subset), Arista CloudVision Portal / CVP (read subset), or UniFi Network (self-hosted controller / UniFi OS console; read subset + device restart) — a one-shot fabric health overview; organization/site/container reads (list/get, licensing, admins, org-wide device statuses, API usage); network reads (list/get, VLANs, health alerts, traffic); device reads (inventory by model MX/MS/MR/MV/MG, status, uplinks, switch ports / interface stats, wireless SSIDs); client reads (list, detail, usage, connectivity); three flagship analyses — uplink loss & latency RCA (rank worst MX WAN uplinks + cause/action), network health score (composite per-network), and config template drift (settings drifted from a bound template); and eight guarded writes (reboot, blink LEDs, update device, update VLAN, claim/remove devices, bind/unbind a config template — Meraki-only except device restart, which unifi also maps; other unmapped writes return a teaching "not supported yet" error).
Always use this skill for "Meraki org overview", "which uplinks are worst", "uplink loss and latency", "WAN degradation RCA", "network health score", "config template drift", "list Meraki networks/devices/clients", "reboot a Meraki device", "blink device LEDs", "claim a device into a network", "bind a network to a template", "Catalyst Center site health / device health / issues", "DNA Center inventory", "CloudVision inventory / compliance / events", "UniFi site health / alarms / clients", "restart a UniFi AP or switch" when the context is a controller-managed network fabric.
Do NOT use when the target is OT / industrial equipment (Modbus, OPC-UA, PLCs — use industrial-aiops), a hypervisor, a storage appliance, a backup product, a container/cluster orchestrator, or device-level CLI/SSH network automation (negative routing hints only).
Covers common controller fabric operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers). The test suite is mock-based; no platform has yet been exercised against a live controller (see docs/VERIFICATION.md).
installer:
kind: uv
package: fabric-aiops
argument-hint: "[org/network/device id or describe your fabric task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["fabric-aiops","uvx"]},"optional":{"env":["FABRIC_AIOPS_CONFIG","FABRIC_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/Fabric-AIops","emoji":"🛰️","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed network-fabric controller o_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "fabric-aiops",
"version": "0.12.0",
"publishedAt": 1789962986404
}references/agent-guardrails.md
# Agent guardrails — running fabric-aiops with a smaller / local model
If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.
The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.
## Authorization is not this tool's job — decide it where it belongs
Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:
- **The account you connect with.** Give it a Meraki API key whose admin has
read-only organization access (or the read-only equivalent on your
controller). A write then fails at the controller, which is the only place the
permission actually lives — no skill-side flag can be argued around by a model,
but a revoked permission cannot be.
- **Your agent's system prompt.** If you want an observe-only session, tell the
model not to call the write tools (they are clearly tagged `[WRITE]`).
What the tool *does* guarantee is that you can always see what happened:
## What the tool enforces — do not waste prompt budget on these
| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Log everything you do, over both MCP and the CLI" | Every call is audited to `~/.fabric-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |
| "Don't invent a value when a field is missing" | A field the controller did not return comes back as `null`, never as `""`. Absent and empty are distinguishable in the payload. |
| "Tell me if the output was cut off" | Anything with a `limit` returns `{"<items>": [...], "returned": N, "limit": L, "truncated": true/false}`, where `<items>` names what was listed — `devices`, `alerts`, `topApplications`, `worst`, `driftedNetworks` or `undos`; on ACI, `endpoints`, `faults`, `contracts` or `entries`. Read the key the tool documents rather than assuming `devices`. Truncation is measured against the full result, not guessed from a length coincidence. |
| "Preserve the ordering / tell me what's most urgent" | The ranked analyses return worst-first and carry the numbers that produced each ranking (`avgLossPct`, `score`, `alertPenalty`), so priority is in the payload rather than implied by list position. The ACI reads carry an explicit `rank` on findings and on `aci_faults_list` rows; related-fault candidates are sorted active-first but unranked. |
| "Confirm before anything destructive" | Destrucreferences/capabilities.md
# fabric-aiops capabilities
> 37 MCP tools (28 read, 9 write) over five platforms —
> Cisco Meraki Dashboard (reference, full read+write), Cisco Catalyst Center
> (read subset), Arista CloudVision Portal (read subset), UniFi Network (read
> subset + device restart), Cisco ACI APIC (three ACI-native reads). The first
> four platforms' API paths are modelled from the public API shapes and need live
> verification; the ACI reads are built against real, anonymized APIC responses.
> Community-maintained; not affiliated with Cisco/Meraki/Arista/Ubiquiti.
Meraki hierarchy: **organizations → networks → devices**. Device models carry a
product-type prefix: **MX** appliance, **MS** switch, **MR** wireless AP, **MV**
camera, **MG** cellular gateway.
**Multi-platform**: the tables below show the reference (Meraki) API per tool.
On `catalyst`, canonical organizations/networks are **sites**
(`/dna/intent/api/v1/site`, `site-health`), device statuses come from
`device-health`, alerts from `issues` (P1→critical, P2→warning), inventory from
`network-device`, switch ports from per-device `interface` stats (pass the
device uuid), and clients from `client-health` (aggregate) / `client-detail`
(by MAC). On `cvp`, organizations/networks are **containers**
(`/cvpservice/inventory/containers`), devices come from
`/cvpservice/inventory/devices` (rows carry the `complianceCode` config-drift
signal), alerts from `getAllEvents.do`, and admins from `getUsers.do`.
On `unifi`, organizations/networks are **sites** (`/api/self/sites`; the
canonical id is the site's short name — the `/api/s/{site}/` path segment),
device inventory/statuses come from `stat/device` (state 1 → online; uptime,
firmware), switch ports from the device detail's `port_table` (pass the device
**MAC** where Meraki takes a serial), clients from `stat/sta` / `stat/user`,
alerts from `stat/alarm` (`*_Lost_Contact` → critical), `network_get` from
`stat/health` (per-subsystem rollup), and `reboot_device` maps to
`POST /api/s/{site}/cmd/devmgr {"cmd": "restart-device", "mac": ...}` — the
only non-Meraki write. Device-scoped calls fill the site from the target's
default `org_id`. Auth is a UniFi API key (`X-API-KEY`); a UniFi OS console's
`base_url` carries the `/proxy/network` prefix.
Any tool a platform does not map — and **every write on catalyst/cvp (on
unifi, every write except reboot)** — returns a teaching "not supported on
<platform> yet — open an issue or PR" error instead of a silent no-op. The
full per-op matrix is in the repo README.
## Read tools (28)
### Overview + organizations
| Tool | Meraki API path | Returns |
|------|----------------------|---------|
| `overview` | `/organizations/{id}/networks` + `/devices/statuses` | organizationId, networks, devicesTotal, devicesByStatus, devicesByProductType |
| `org_list` | `GET /organizations` | id, name, url, apiEnabled |
| `org_get` | `GET /organizations/{id}` | one org detail |
| `org_licensing` | `GET /organizations/{id}/licenses/overview` | stareferences/cli-reference.md
# fabric-aiops CLI reference > Controller API paths (Meraki / Catalyst Center / CVP / UniFi Network) are > modelled from the public API shapes and have not yet been exercised live > (see docs/VERIFICATION.md). Not affiliated with Cisco/Meraki/Arista/Ubiquiti. ## Setup & diagnostics ```bash fabric-aiops init # interactive onboarding wizard (platform: meraki/catalyst/cvp/unifi) fabric-aiops doctor [--skip-auth] # config + secret store + connectivity (canonical org/site/container probe) fabric-aiops mcp # start the MCP server (stdio transport) ``` ## Secrets (encrypted store ~/.fabric-aiops/secrets.enc) ```bash fabric-aiops secret set <target> [--value <key>] # store API key (hidden prompt if no --value) fabric-aiops secret list # names only — values never shown fabric-aiops secret rm <target> fabric-aiops secret migrate # import legacy plaintext .env (FABRIC_<T>_APIKEY) fabric-aiops secret rotate-password # re-encrypt under a new master password ``` ## Read commands ```bash fabric-aiops overview [--org-id <id>] [--target <t>] # networks + device status/product rollup fabric-aiops org list # organizations visible to the key fabric-aiops org get [--org-id <id>] fabric-aiops org licensing [--org-id <id>] fabric-aiops org admins [--org-id <id>] fabric-aiops org device-statuses [--org-id <id>] # online/offline/alerting rollup fabric-aiops org api-usage [--org-id <id>] # response-code counts, 429 rate-limits fabric-aiops network list [--org-id <id>] fabric-aiops network get <networkId> fabric-aiops network vlans <networkId> fabric-aiops network alerts <networkId> # health alerts by severity fabric-aiops network traffic <networkId> [--timespan 86400] fabric-aiops device inventory [--model MS] [--org-id <id>] # MX/MS/MR/MV/MG fabric-aiops device status <serial> [--org-id <id>] fabric-aiops device uplinks [--org-id <id>] fabric-aiops device switch-ports <serial> # MS ports fabric-aiops device ssids <networkId> # MR SSIDs fabric-aiops client list <networkId> [--timespan 86400] fabric-aiops client get <networkId> <clientId> fabric-aiops client usage <networkId> <clientId> fabric-aiops client connectivity <networkId> <clientId> fabric-aiops health uplink-rca [--loss-pct 5] [--latency-ms 150] [--org-id <id>] # flagship RCA fabric-aiops health score [--org-id <id>] # composite per-network health from live data # Cisco ACI targets (platform: aci) — read-only, ACI-native references fabric-aiops aci trace --mac <mac> | --ip <ip> [--limit 5] # endpoint → leaf/interface → EPG → BD → VRF → contracts fabric-aiops aci segment <tenant> <app> <epg> # an EPG's BD, VRF and contracts fabric-aiops aci faults [--severity critical] [--include-cleared] [--limit 50] # worst-first ``` ## Write commands (governed; risk ti
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/fabric-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/fabric-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T07:53:49.677Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-fabric-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-fabric-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T07:53:49.677Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/zw008/fabric-aiops",
"sourceUrl": "https://clawhub.ai/zw008/fabric-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T07:53:49.677Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.12.0",
"href": "https://clawhub.ai/zw008/fabric-aiops",
"sourceUrl": "https://clawhub.ai/zw008/fabric-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-21T03:56:26.404Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-fabric-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-fabric-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.12.0",
"description": "- Added Cisco ACI APIC platform support: read-only endpoint path trace, EPG segment, and fault queries. - Expanded from 34 to 37 MCP tools, now spanning five controller platforms. - Documentation updated to reflect ACI capabilities and tested coverage. - Removed obsolete skill-card.md file. - General improvements and clarifications in CLI reference and setup documentation.",
"href": "https://clawhub.ai/zw008/fabric-aiops",
"sourceUrl": "https://clawhub.ai/zw008/fabric-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-21T03:56:26.404Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
