CtrlK
BlogDocsLog inGet started
Tessl Logo

wireshark-analysis

This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network anomalies", "investigate suspicious traffic", or "perform protocol analysis". It provides comprehensive techniques for network packet capture, filtering, and analysis using Wireshark.

61

Quality

71%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Medium

Suggest reviewing before use

Fix and improve this skill with Tessl

tessl review fix ./skills/wireshark-analysis/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers a well-sequenced, genuinely actionable Wireshark workflow with copy-paste display filters and exact menu paths. Its weaknesses are token efficiency — roughly 490 lines largely restate protocol and Wireshark knowledge Claude already has, with duplicated sections — and a monolithic single-file structure that inlines filter-reference and shortcut material that belongs in separate reference files.

Suggestions

Cut the 'Technical Requirements' prerequisites list, the GUI launch walkthrough, the 'Shows:'/'Tabs:'/'Features:' bullet lists under each Statistics menu, and the generic 'Best Practices' section — Claude already knows Wireshark's menus and what TCP/UDP/HTTP/DNS are; keep only the exact menu paths.

Deduplicate content: DNS filters appear in both Phase 5 and the Quick Reference, and Ctrl+E/Ctrl+O/Ctrl+S appear in both the Capture Controls table and the Keyboard Shortcuts table — keep a single Quick Reference section.

Move the 'Common Filter Reference' table, keyboard shortcuts, and per-protocol filter recipes into a references/ file (e.g., references/filters.md) linked from a concise overview, so SKILL.md stays a navigable summary rather than a ~500-line monolith.

DimensionReasoningScore

Conciseness

At ~490 lines the body re-teaches material Claude already knows: a 'Technical Requirements' section listing 'Understanding of network protocols (TCP, UDP, HTTP, DNS)', a GUI launch walkthrough ('1. Launch Wireshark 2. Select network interface...'), 'Shows:' bullet lists under each Statistics menu, generic 'Best Practices', and duplicated content (DNS filters appear in Phase 5 and the Quick Reference; Ctrl+E/Ctrl+O/Ctrl+S appear in two tables). This matches 'noticeably verbose; several unnecessary explanations or padded sections'. Not 1, because no paragraph-style concept tutorials are present — most of the padding is reference material, not prose explanations.

2 / 5

Actionability

Display filters are copy-paste ready ("ip.addr == 192.168.1.1", "tcp.flags.syn == 1 && tcp.flags.ack == 0", "dns.flags.rcode != 0"), menu paths are exact ('Statistics > Protocol Hierarchy', 'File > Export Objects > HTTP'), and the examples give concrete filter sequences. Not 5, because several steps rely on placeholders (SUSPECT_IP, WEB_SERVER, 'suspicious-domain') and GUI descriptions rather than exact commands, and no tshark/CLI equivalents are given; not 3, because the guidance is genuinely executable rather than pseudocode.

4 / 5

Workflow Clarity

The six phases (capture → display filters → follow streams → statistics → security → expert info) are clearly sequenced and ordered by dependency, the Troubleshooting section gives error-recovery guidance ('Verify filter syntax (red = error)... Clear filter and rebuild incrementally'), and the examples walk concrete scenarios end-to-end. Not 5, because there are no explicit validation checkpoints (e.g., confirm the filter bar turns green before interpreting results); not 3, because the sequence is coherent and recovery guidance exists for the failure modes that matter in this read-only analysis domain, where the destructive/batch validation cap does not apply.

4 / 5

Progressive Disclosure

No bundle files exist (references/, scripts/, assets/ are all absent) and the entire skill is a single ~490-line file. Section headers are consistent and navigation within the file is reasonable, but clearly separable material — the full filter reference, keyboard shortcuts, and security-analysis recipes — is inlined rather than split into one-level-deep reference files. This matches 'some structure but could be better organized; content that should be separate is inline'. Not 2, because the file is not an unstructured wall of text; not 4, because nothing is offloaded to separate files.

3 / 5

Total

13

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description with explicit, natural trigger phrases, a distinct Wireshark/PCAP niche, and both what-and-when answered. The 'what' clause leans on mild buzzword padding ('comprehensive techniques') and a few natural terms/file extensions are absent, keeping specificity and trigger quality at 4.

DimensionReasoningScore

Specificity

The what-clause names the tool and several concrete capability areas ("network packet capture, filtering, and analysis using Wireshark"), matching the 'several specific actions; minor gaps in coverage' anchor — stream reconstruction, statistics, and decryption are only implied. Not 3, because more than 1-2 concrete actions are named; not 5, because 'comprehensive techniques' is slightly generic padding and coverage of the body's actual capabilities is incomplete.

4 / 5

Completeness

Both questions are answered explicitly and concretely: the when is a list of literal trigger phrases ("This skill should be used when the user asks to..."), and the what names the tool and capability areas. This matches the anchor 'clearly and explicitly answers both what AND when with concrete trigger phrases'; the boilerplate opening phrasing does not obscure either answer.

5 / 5

Trigger Term Quality

Seven natural quoted phrases users would actually say ("analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams") give good keyword coverage including PCAP, Wireshark, and stream language. Not 5, because common variations and file extensions are missing (no '.pcap'/'.pcapng', 'network forensics', 'packet analysis'); not 3, because coverage clearly exceeds the 'some relevant keywords, missing common variations' anchor.

4 / 5

Distinctiveness Conflict Risk

The description is anchored to a specific niche — Wireshark, PCAP files, TCP/UDP streams, packet capture — with triggers that would not plausibly fire a document-editing or general-analysis skill. Minimal overlap risk (only an adjacent tcpdump-style skill), matching the 'clear niche with distinct triggers' anchor.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.