CtrlK
BlogDocsLog inGet started
Tessl Logo

analyzing-network-traffic-for-incidents

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

71%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete, executable commands and a clear six-step workflow, but it over-explains well-known concepts and fails to route detail into the provided bundle files. Tightening the reference sections and linking the bundle files would materially improve it.

Suggestions

Remove or shrink the 'Key Concepts' and 'Tools & Systems' sections — Claude already knows what PCAP, Wireshark, Zeek, and DNS tunneling are; keep only tool specifics that affect command choice.

Link the bundle files explicitly (e.g., 'For the full tshark/Zeek/Suricata command catalog, see references/api-reference.md; for the scapy/tshark automation agent, see scripts/agent.py') and move the overlapping filter/command detail out of the body.

Add explicit validation checkpoints to the workflow (e.g., confirm a capture covers the incident timeframe before analysis, and corroborate a beaconing finding with a second technique) to lift workflow clarity.

DimensionReasoningScore

Conciseness

The bulk is lean, executable commands, but the 'Key Concepts' table and 'Tools & Systems' section explain concepts Claude already knows (PCAP, Wireshark, DNS tunneling, NetFlow); not a 4 because these padded sections are noticeable rather than minor.

3 / 5

Actionability

Provides copy-paste-ready tcpdump, zeek-cut, and Wireshark display-filter commands covering the common cases (beaconing, lateral movement, exfiltration); fully executable with specific examples.

5 / 5

Workflow Clarity

A clear six-step sequence (capture → C2 → lateral movement → exfiltration → IOCs → document) with concrete commands; not a 5 because explicit validate/verify checkpoints are largely absent, though read-only analysis softens that gap.

4 / 5

Progressive Disclosure

Section structure is good, but the body never signals the existing references/api-reference.md or scripts/agent.py, and detail that overlaps those bundle files is inlined; not a 4 because references are not clearly signaled at all.

3 / 5

Total

15

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is a strong, well-structured trigger: it concisely states concrete capabilities, names the supporting tools, and lists natural activation phrases with synonyms. It cleanly answers both what the skill does and when Claude should invoke it.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — identify C2 communications, lateral movement, data exfiltration, and exploitation attempts — and names the concrete techniques (Wireshark, Zeek, NetFlow), giving comprehensive coverage.

5 / 5

Completeness

Explicitly states what it does ('Analyzes network traffic captures and flow data to identify adversary activity...') and when to use it ('Activates for requests involving...'), matching the anchor that requires both with concrete trigger phrases.

5 / 5

Trigger Term Quality

Provides six natural trigger phrases ('network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection') with synonyms (packet capture / PCAP); not a 4 because coverage is comprehensive rather than merely good.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear network-forensics niche with distinct triggers (PCAP, C2, exfiltration) that are unlikely to fire for endpoint or host-based skills; minimal conflict risk.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.