Design fail-closed MCP tool access to network devices for Claude Code and other agents. Use when adding a NAPALM/Netmiko tool, reviewing allow-lists, or connecting an LLM to a lab or production fabric.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add gesh75/claude-skill-lint --skill mcp-netops-safety --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Mcp Netops Safety?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gesh75-mcp-netops-safety)More formats (shields.io, HTML) on the badges page.
---
name: mcp-netops-safety
description: Design fail-closed MCP tool access to network devices for Claude Code and other agents. Use when adding a NAPALM/Netmiko tool, reviewing allow-lists, or connecting an LLM to a lab or production fabric.
argument-hint: "[tool] [env]"
allowed-tools: Read Grep
license: MIT
---
# MCP NetOps safety
Do not use for skill authoring style (use this repo's linter). Not for general MCP server scaffolding.
## Procedure
1. Default read-only. Write tools are a separate server with a second allow-list.
2. Every tool names device, command class, and whether it mutates. `show` is not `commit`.
3. Sanitize before the model: strip secrets, TACACS, SNMP, and user PII from command output.
4. Production requires a human approval token. Labs may auto-apply under a risk gate.
5. Verify: a denied write, a sanitized syslog line, and an audit HMAC or equivalent.
```text
tool: napalm_get_facts mutate: no env: any
tool: napalm_commit mutate: yes env: lab|prod+token
tool: netmiko_send_config mutate: yes env: lab-only
```
## Anti-patterns
- Never give an agent raw Bash on a jump host that can SSH to production.
- Do not log full command output to a cloud LLM without sanitizing.
## Safety
This skill is itself fail-closed. If the policy is unclear, the tool does not fire.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.
Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...
Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.
**Complete production-ready guide for Google Gemini embeddings API** This skill provides comprehensive coverage of the `gemini-embedding-001` model for generating text embeddings, including SDK usage, REST API patterns, batch processing, RAG integration with Cloudflare Vectorize, and advanced use cases like semantic search and document clustering. ---
Recovers prior coding-agent session context by running `catchup <agent> --since-compact`, which extracts a clean summary of a previous Codex, Claude Code, Antigravity, OpenCode, or Pi Agent session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", or asks to recover/summarize a previous session before continuing. Do NOT use for the current conversation, git history, or any non-agent log.