network-aiops
Use this skill whenever the user needs to operate a network device — read device facts, interfaces (+ counters/IP), BGP/LLDP neighbors (summary and detail), ARP/MAC tables, VLANs, routes, hardware environment (fans/temp/power/CPU/mem), optics, NTP, users, SNMP info, VRFs, and an aggregated device-health summary; run read-only RCA diagnostics on interface health and BGP neighbors; back up a switch/router config, diff a candidate config (dry-run), and merge/replace/rollback config — across Cisco IOS/IOS-XE, Nexus NX-OS, IOS-XR, Arista EOS, and Juniper Junos via NAPALM. An optional NetBox block adds source-of-truth lookups. Always use this skill for "back up switch config", "show bgp neighbors", "diff network config", "push config to router", "show interfaces on the switch", or tasks mentioning "cisco", "arista", "juniper", "nexus", "ios-xr", or "napalm". Do NOT use when the target is not a NAPALM-supported network device (Kubernetes clusters, hypervisor VMs, and cloud consoles are out of scope — route those elsewhere). Common multi-vendor device operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 9, 2026
Version
0.12.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 1.9K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.12.3release · observed Sep 15, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:network-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:network-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/network-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-network-aiops/snapshot"
Documentation
CLAWHUB
148,977 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: network-aiops
slug: network-aiops
displayName: "Network AIops"
summary: "Governed network device ops (NAPALM) — 33 MCP tools with audit/undo."
license: MIT
homepage: https://github.com/AIops-tools/Network-AIops
tags: [aiops, mcp, governance, network]
description: >
Use this skill whenever the user needs to operate a network device — read device facts, interfaces (+ counters/IP), BGP/LLDP neighbors (summary and detail), ARP/MAC tables, VLANs, routes, hardware environment (fans/temp/power/CPU/mem), optics, NTP, users, SNMP info, VRFs, and an aggregated device-health summary; run read-only RCA diagnostics on interface health and BGP neighbors; back up a switch/router config, diff a candidate config (dry-run), and merge/replace/rollback config — across Cisco IOS/IOS-XE, Nexus NX-OS, IOS-XR, Arista EOS, and Juniper Junos via NAPALM. An optional NetBox block adds source-of-truth lookups.
Always use this skill for "back up switch config", "show bgp neighbors", "diff network config", "push config to router", "show interfaces on the switch", or tasks mentioning "cisco", "arista", "juniper", "nexus", "ios-xr", or "napalm".
Do NOT use when the target is not a NAPALM-supported network device (Kubernetes clusters, hypervisor VMs, and cloud consoles are out of scope — route those elsewhere).
Common multi-vendor device operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).
installer:
kind: uv
package: network-aiops
argument-hint: "[device name or describe your network task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["network-aiops","uvx"]},"optional":{"env":["NETWORK_AIOPS_CONFIG","NETWORK_AIOPS_HOME","NETWORK_AIOPS_MASTER_PASSWORD","NETWORK_NETBOX_TOKEN"]},"homepage":"https://github.com/AIops-tools/Network-AIops","emoji":"🛜","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed network device operations over NAPALM. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
All write operations are audited to a local SQLite DB under ~/.network-aiops/ (relocatable via NETWORK_AIOPS_HOME).
Credentials: device login passwords AND the optional NetBox API token live in an ENCRYPTED store at ~/.network-aiops/secrets.enc (Fernet/AES + scrypt-derived key; chmod 600), never in plaintext. Device passwords are keyed by the device name; the NetBox token uses the reserved name "netbox-token". Unlock with the NETWORK_AIOPS_MASTER_PASSWORD env var (for the MCP server / non-interactive use) or an interactive prompt. Run `network-aiops init` (wizard) or `network-aiops secret set <name>` to populate it, and `network-aiops secret migrate` to import a legacy plaintext .env (NETWORK_<TARGET_UPPER>_PASSWORD / NETWORK_NETBOX_TOKEN are still honoured as a deprecated fallback). config.yaml holds only device names, drivers, hosts, usernames, and NAPALM optional_args — never secrets. The state _meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "network-aiops",
"version": "0.12.3",
"publishedAt": 1789452559228
}references/agent-guardrails.md
# Agent guardrails — running network-aiops with a smaller / local model
If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.
The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.
Network gear raises the stakes: a bad merge on a core switch takes the management
plane with it, and the model cannot SSH back in to fix what it broke.
## What the tool now enforces — do not waste prompt budget on these
| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Don't invent a value when a field is missing" | A field the driver did not return comes back as `null`, never as `""`. This is the norm, not the exception, on a multi-vendor fleet: `serial_number`, `model`, an interface `description`, an LLDP neighbour's `hostname` are all optional and driver-dependent. Absent and empty are distinguishable in the payload. |
| "Tell me if the output was cut off" | The NetBox listings return `{"devices": [...], "returned": N, "limit": L, "truncated": true/false}` (and `{"interfaces": ...}` likewise). Truncation is measured — one extra record is fetched — not guessed from a length coincidence. |
| "Preserve the ordering / tell me what's most urgent" | `interface_health_rca` and `bgp_neighbor_rca` findings carry an explicit 1-based `rank`, worst-first, and each cites the measured number that tripped it (`rx_errors+tx_errors = 412 >= 100`). Priority is in the payload, not implied by list position. |
| "Show me the diff before you commit anything" | `config_diff` is a real dry run: it stages a candidate, returns `compare_config()` output, then always discards. Nothing is committed, and the response carries `"committed": false`. |
| "Confirm before anything destructive" | The CLI write paths (`config merge`/`replace`/`rollback`) require a double confirmation, and every write supports `--dry-run` / `dry_run=True` to preview first. `config_replace` is `high` risk, carried into the audit row as a `review` tier so it stands out in the trail. |
| "Keep a copy of the old config so we can go back" | `config_merge` and `config_replace` read the running config **before** touching the device and return it as `backup`, and the harness records an undo descriptor that restores it via `config_replace`. The before-state is captured, not reconstructed. |
| "Log what you did" | Every governed call is audited to `~/.network-aiops/audit.db` regardless of what the model says it did. |
| "Never show me passwords or SNMP communities" | `get_users` returns `has_password` (a boolean) instead of the hash; `get_snmp_information` returns `community_count` instead of the commureferences/capabilities.md
# network-aiops Capabilities
33 MCP tools (28 read / 5 write). Every tool is wrapped with `@governed_tool`
(audit + policy + budget + risk-tier; undo where a clean inverse exists). Returns
are high-signal summaries — config blobs are sanitized and size-bounded. Secrets
are never returned (user password hashes and SNMP community strings are redacted).
## Read tools
| Tool | Returns | Risk | Typical response tokens |
|------|---------|:----:|:-----------------------:|
| `device_facts` | hostname, vendor, model, os_version, serial, uptime, interface list | low | ~80–300 |
| `get_interfaces` | per-interface up/enabled/speed/description/mac | low | ~60–800 |
| `get_interfaces_counters` | per-interface octets/packets/errors/discards | low | ~60–800 |
| `get_interfaces_ip` | per-interface IPv4/IPv6 + prefix length | low | ~40–400 |
| `get_bgp_neighbors` | per-VRF peer, remote AS, up, prefix counts | low | ~60–600 |
| `get_bgp_neighbors_detail` | + state, router id, local AS, advertised prefixes | low | ~80–900 |
| `get_lldp_neighbors` | local port, remote host, remote port | low | ~40–400 |
| `get_lldp_neighbors_detail` | + chassis id, system desc, capabilities | low | ~60–700 |
| `get_arp_table` | interface, IP, MAC, age | low | ~50–700 |
| `get_mac_address_table` | MAC, interface, VLAN, static/active | low | ~50–900 |
| `get_vlans` | id, name, member interfaces | low | ~40–500 |
| `get_route_to` | per-prefix protocol, next hop, outgoing interface | low | ~40–500 |
| `get_environment` | fans, temperature, power, CPU, memory | low | ~60–500 |
| `get_optics` | per-interface rx/tx power, laser bias | low | ~40–400 |
| `get_ntp_servers` | configured NTP servers | low | ~20–120 |
| `get_ntp_stats` | per-peer stratum, offset, jitter, reachability | low | ~40–300 |
| `get_users` | username, level, has_password (hash redacted) | low | ~30–200 |
| `get_snmp_information` | chassis id, contact, location, community_count | low | ~40 |
| `get_network_instances` | VRFs: name, type, RD, interfaces | low | ~40–400 |
| `device_health` | facts + interface up/down + environment + issues | low | ~120–400 |
| `interface_health_rca` | worst-first findings: down / error / discard / flap, each cited | low | ~80–600 |
| `bgp_neighbor_rca` | worst-first findings: down / shut / reset / route-less, each cited | low | ~60–500 |
| `config_backup` | running config, credential values masked (`include_secrets=True` for raw) | low | ~500–8000 |
| `config_diff` | candidate diff, credential values masked (dry-run, never committed) | low | ~30–1500 |
| `netbox_list_devices` | `{devices, returned, limit, truncated}` — name, role, site, status, primary IP | low | ~40–500 |
| `netbox_get_device` | + device_type, serial | low | ~80 |
| `netbox_device_interfaces` | `{interfaces, returned, limit, truncated}` — name, type, enabled, description | low | ~40–600 |
| `undo_list` | recorded, not-yet-applied reversible writes (undoId, original/inverse tool, note) | low | ~40–400 |
> **Optional fiereferences/cli-reference.md
# network-aiops CLI Reference All commands accept `-t/--target <name>` to select a configured device. When omitted, the first device in `~/.network-aiops/config.yaml` is used. ## Onboarding & secrets ```bash network-aiops init # interactive wizard: devices + encrypted passwords (+ NetBox) network-aiops secret set <name> # store/replace a device password, or 'netbox-token' (hidden prompt) network-aiops secret list # names only — values are never printed network-aiops secret rm <name> # delete a stored secret network-aiops secret migrate # import a legacy plaintext .env into the encrypted store network-aiops secret rotate-password # re-encrypt the store under a new master password ``` Secrets are stored encrypted in `~/.network-aiops/secrets.enc`. Unlock non-interactively with `NETWORK_AIOPS_MASTER_PASSWORD`. ## Device facts & state (read-only) ```bash network-aiops device facts [-t <device>] # hostname, vendor, model, OS, serial, uptime network-aiops device interfaces [-t <device>] # up/down, enabled, speed, description network-aiops device counters [-t <device>] # per-interface traffic + error counters network-aiops device bgp [-t <device>] # BGP neighbors per VRF network-aiops device lldp [-t <device>] # LLDP neighbors network-aiops device arp [-t <device>] # ARP table network-aiops device mac [-t <device>] # MAC address table network-aiops device vlans [-t <device>] # VLANs (id, name, member count) network-aiops device route <prefix> [-t <device>] [--protocol bgp] # routing-table lookup network-aiops device environment [-t <device>] # fans, temperature, power, CPU, memory network-aiops device health [-t <device>] # aggregated health summary ``` Additional read getters are exposed as MCP tools (no dedicated CLI subcommand): `get_bgp_neighbors_detail`, `get_lldp_neighbors_detail`, `get_optics`, `get_ntp_servers`, `get_ntp_stats`, `get_users`, `get_snmp_information`, `get_network_instances`. A getter a driver does not implement returns a teaching "not supported by the `<driver>` driver" error. ## Configuration ```bash network-aiops config backup [-t <device>] [-o <file>] # running config (save with -o) network-aiops config diff <file> [-t <device>] [--replace] # DRY-RUN: show the diff only network-aiops config merge <file> [-t <device>] [--dry-run] [--revert-in N] # commit; double confirm network-aiops config replace <file> [-t <device>] [--dry-run] [--revert-in N] # HIGH RISK; double confirm network-aiops config confirm [-t <device>] [--dry-run] # confirm a pending commit network-aiops config rollback [-t <device>] [--dry-run] # revert last commit; double confirm ``` - `config diff` stages a candidate, runs `compare_config()`, and discards it — nothing is committed. `--replace` diffs as a full-config replacement. - `--dry-run` on `merge` /
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/network-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/network-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:33:08.442Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-network-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-network-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T23:33:08.442Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.9K downloads",
"href": "https://clawhub.ai/zw008/network-aiops",
"sourceUrl": "https://clawhub.ai/zw008/network-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T23:33:08.442Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.12.3",
"href": "https://clawhub.ai/zw008/network-aiops",
"sourceUrl": "https://clawhub.ai/zw008/network-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T06:09:19.228Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-network-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-network-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.12.3",
"description": "- Removed the file: skill-card.md - No functional or code changes; this update is limited to file cleanup.",
"href": "https://clawhub.ai/zw008/network-aiops",
"sourceUrl": "https://clawhub.ai/zw008/network-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T06:09:19.228Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
