workspace/skills/protocol-participation/SKILL.md
Live BGP and OSPF control-plane participation — peer with real routers, inject/withdraw routes, query RIB/LSDB, adjust metrics, GRE tunnel status. Use when injecting or withdrawing BGP routes, checking BGP peer state, querying the OSPF LSDB, or testing route advertisement in a lab.
npx skillsauth add automateyournetwork/netclaw protocol-participationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
| Property | Value |
|----------|-------|
| Source | WontYouBeMyNeighbour BGP/OSPFv3/GRE modules |
| Transport | stdio |
| Tools | 10 |
| Protocol modules | BGP (20 files), OSPFv3 (8 files), GRE (4 files), Connectors (2 files) |
| Dependencies | scapy, networkx, mcp, fastmcp |
bgp_get_peersList BGP peer sessions with state, AS, IP, uptime, and prefix counts.
| Parameter | Type | Default | Description | |-----------|------|---------|-------------| | (none) | — | — | No parameters |
Returns: { peers: [{peer, peer_as, state, local_addr, is_ibgp, uptime, prefixes_received, prefixes_sent}], count }
bgp_get_ribQuery the Loc-RIB (best routes). Optionally filter by prefix.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| prefix | string | null | Optional CIDR filter (e.g. 10.0.0.0/24) |
Returns: { routes: [{network, next_hop, as_path, local_pref, med, origin, communities}], count }
bgp_inject_routeInject a route into the BGP RIB and advertise to peers.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| network | string | required | CIDR prefix (e.g. 192.168.1.0/24) |
| next_hop | string | null | Next-hop IP (defaults to self) |
| as_path | string | null | Comma-separated AS path (e.g. 65001,65002) |
| local_pref | int | 100 | LOCAL_PREF value |
Returns: { success, network, route_info }
bgp_withdraw_routeWithdraw a route from the BGP RIB and send withdrawal to peers.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| network | string | required | CIDR prefix to withdraw |
Returns: { success, network }
bgp_adjust_local_prefChange the LOCAL_PREF for a route in the RIB.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| network | string | required | CIDR prefix |
| local_pref | int | required | New LOCAL_PREF (higher = more preferred) |
Returns: { success, network, old_local_pref, new_local_pref }
ospf_get_neighborsList OSPF neighbors with state, address, priority, and router ID.
| Parameter | Type | Default | Description | |-----------|------|---------|-------------| | (none) | — | — | No parameters |
Returns: { neighbors: [{neighbor_id, state, address, priority}], count }
ospf_get_lsdbQuery the OSPF Link State Database.
| Parameter | Type | Default | Description | |-----------|------|---------|-------------| | (none) | — | — | No parameters |
Returns: { lsdb: [{type, advertising_router, ls_id, sequence, age}], count }
ospf_adjust_costChange the OSPF cost on an interface.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| interface | string | required | Interface name (e.g. gre-netclaw) |
| cost | int | required | New OSPF cost (1-65535) |
Returns: { success, interface, old_cost, new_cost }
gre_tunnel_statusCheck GRE tunnel status via system commands (ip tunnel show, ip addr show).
| Parameter | Type | Default | Description | |-----------|------|---------|-------------| | (none) | — | — | No parameters |
Returns: { tunnels: [...], addresses: [...], count }
protocol_summaryConsolidated BGP + OSPF + GRE state summary in a single call.
| Parameter | Type | Default | Description | |-----------|------|---------|-------------| | (none) | — | — | No parameters |
Returns: { router_id, local_as, lab_mode, bgp: {configured, peer_count, peers, rib_size}, ospf: {configured, neighbor_count, neighbors}, gre: {tunnels, addresses, count} }
| Variable | Example | Description |
|----------|---------|-------------|
| NETCLAW_ROUTER_ID | 4.4.4.4 | BGP/OSPF router ID |
| NETCLAW_LOCAL_AS | 65001 | BGP local autonomous system number |
| NETCLAW_BGP_PEERS | [{"ip":"172.16.0.1","as":65000}] | JSON array of BGP peers |
| NETCLAW_OSPF_AREAS | ["0.0.0.0"] | JSON array of OSPF area IDs |
| NETCLAW_GRE_TUNNELS | [{"name":"gre-netclaw","local":"...","remote":"..."}] | JSON array of GRE tunnels |
| NETCLAW_LAB_MODE | true | Relaxes CR requirement for lab testing |
A Docker-based 3-router FRR topology is provided in lab/frr-testbed/ for testing:
NetClaw (AS 65001) ──GRE── Edge1 (AS 65000) ──OSPF── Core (RR) ──OSPF── Edge2
host/WSL 1.1.1.1 2.2.2.2 3.3.3.3
172.16.0.2 172.16.0.1
eBGP iBGP→Core iBGP hub iBGP→Core
# Start lab
cd lab/frr-testbed && docker compose up -d
# Create GRE tunnel (requires sudo)
sudo bash scripts/setup-gre.sh
# Verify
bash scripts/verify.sh
servicenow-change-workflow → CR approved
→ bgp_inject_route(network, next_hop, local_pref)
→ bgp_get_rib(prefix) → verify route in table
→ pyats-routing → verify on remote devices
→ gait-session-tracking → record change
bgp_get_rib() → current routes
→ bgp_adjust_local_pref(network, local_pref)
→ bgp_get_peers() → verify advertisement
→ gait-session-tracking
ospf_get_neighbors() → verify adjacencies
→ ospf_adjust_cost(interface, cost)
→ ospf_get_lsdb() → verify LSA update
→ pyats-routing → verify SPF reconvergence
→ gait-session-tracking
protocol_summary() → full state snapshot
→ bgp_get_peers() → check all Established
→ ospf_get_neighbors() → check all Full
→ gre_tunnel_status() → check all tunnels up
→ gait-session-tracking
servicenow-change-workflow → CR approved
→ bgp_get_rib(prefix) → verify route exists
→ bgp_withdraw_route(network)
→ bgp_get_rib(prefix) → verify withdrawal
→ pyats-routing → verify removal on peers
→ gait-session-tracking
NETCLAW_LAB_MODE=true
→ bgp_inject_route / bgp_withdraw_route
→ bgp_get_rib → verify
→ ospf_adjust_cost → test convergence
→ protocol_summary → snapshot
| Skill | Integration | |-------|-------------| | servicenow-change-workflow | MUST gate all route inject/withdraw/cost changes in production | | gait-session-tracking | Record every protocol mutation in the audit trail | | pyats-routing | Cross-verify protocol state from the device CLI side | | uml-diagram | Generate BGP state machines and OSPF area diagrams | | markmap-viz | Visualise RIB hierarchy and OSPF LSDB as mind maps | | netbox-reconcile | Cross-reference peering with NetBox IPAM/circuits | | drawio-diagram | Topology diagrams showing GRE underlay + BGP/OSPF overlay | | cml-topology-builder | Provision lab topologies that NetClaw can then peer with |
NETCLAW_LAB_MODE=truebgp_get_rib) before injecting to prevent routing loopsbgp_get_peers) before advertising — only to Established peersgait-session-tracking)gre_tunnel_status do not require elevated privilegesNETCLAW_LAB_MODE=true) relaxes the CR requirement for the FRR testbed — never set this in productionbgp_get_peers, bgp_get_rib, ospf_get_neighbors, ospf_get_lsdb, gre_tunnel_status, protocol_summarytools
Federate your NetClaw with other NetClaw operators over the BGP mesh — exchange capability inventories and ask your claw what a peer can do. (US1; remote invocation and chat land in later phases.)
tools
3D network topology visualization and interactive digital twin in Unreal Engine 5.8 via the built-in UE5 MCP server.
testing
Human-in-the-loop escalation via HumanRail — route low-confidence agent decisions, pre-destructive operation approvals, and ambiguous incident tickets to real human engineers. Human answers are verified and returned as structured output. Workers are paid via Lightning Network. Use when the agent is uncertain, when a destructive change needs explicit human sign-off beyond a ServiceNow CR, or when an ambiguous ticket requires human triage before automated handling.
testing
IPv4 and IPv6 subnet calculator - CIDR breakdown, usable hosts, previous/next subnets, address classification, VLSM planning, and dual-stack analysis. Use when calculating subnets, figuring out how many hosts fit in a prefix, planning IP addressing, getting wildcard masks for ACLs, or checking if two IPs are in the same subnet.