Display ARP cache table with MAC vendor lookup and suspicious entry detection. Supports CSV, TSV, and TUI output. **Dependency**: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options). see x-cmd skill for installation.
Scanned 9/8/2026
Install to Claude Code
npx -y skills add thiagofernandes1987-create/APEX --skill arp --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Arp?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/thiagofernandes1987-create-arp)More formats (shields.io, HTML) on the badges page.
---
name: x-arp
description: |
Display ARP cache table with MAC vendor lookup and suspicious
entry detection. Supports CSV, TSV, and TUI output.
**Dependency**: This is an x-cmd module. Install x-cmd first (see x-cmd skill for installation options).
see x-cmd skill for installation.
license: Apache-2.0
compatibility: POSIX Shell
metadata:
author: Li Junhao
version: "1.0.0"
category: x-cmd-extension
tags: [x-cmd, network, arp, security]
---
# x arp - ARP Cache Table Viewer
> Display and inspect the local system's ARP cache table with multiple output formats.
---
## Quick Start
```bash
# Interactive ARP table viewer (default in TTY)
x arp
# TSV format output (default when piped)
x arp | cat
```
---
## Features
- **Multi-format output**: TSV, CSV, TUI application, raw
- **MAC vendor lookup**: Automatic vendor identification
- **Suspicious entry detection**: Flags potentially suspicious entries
- **Cross-platform**: Linux, macOS, Windows support
---
## Output Fields
| Field | Description | Example |
|-------|-------------|---------|
| `ip` | IP address | `192.168.1.1` |
| `mac` | MAC address | `00:11:22:33:44:55` |
| `if` | Network interface | `eth0`, `en0` |
| `suspicious` | Suspicious flag | Yes/No |
| `scope` | Address scope | `link`, `global` |
| `type` | Entry type | `static`, `dynamic` |
| `vendor` | MAC vendor (if available) | `Apple, Inc.` |
---
## Commands
| Command | Description |
|---------|-------------|
| `x arp` | Auto mode: TTY→interactive, pipe→TSV |
| `x arp --app` | Interactive TUI view |
| `x arp --csv` | CSV format output |
| `x arp --tsv` | TSV format output |
| `x arp --raw` | Raw system command output |
| `x arp --all` | Include incomplete entries |
| `x arp --no-vendor` | Skip MAC vendor lookup |
---
## Examples
### Basic Usage
```bash
# Interactive view (TTY)
x arp
# TSV format
x arp --tsv
# CSV format
x arp --csv
```
### Filtering and Processing
```bash
# Find entries for specific IP
x arp --tsv | awk -F'\t' '$1 == "192.168.1.1"'
# Check for suspicious entries
x arp --tsv | grep "Yes"
# Get all entries including incomplete
x arp --all
```
### Network Troubleshooting
```bash
# View raw ARP output
x arp --raw
# Check specific interface
x arp --tsv | grep "eth0"
```
---
## Platform Notes
### Linux
- Uses `ip neigh` or `arp -n`
- Full feature support
### macOS
- Uses `arp -an`
- Full feature support
### Windows
- Uses `arp -a`
- Full feature support
---
## Security Notes
- **Suspicious entries**: Flags entries that may indicate ARP spoofing
- **MAC vendor**: Helps identify unknown devices on network
- Use `--no-vendor` for faster output without network lookup
---
## Related
- Native `arp(8)` manual page

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!