Home / tikoci / routeros-skills · routeros-hotspot/SKILL.md · GitHub

routeros-hotspot skillB

routeros-hotspot is agent-read markdown (skill) from tikoci/routeros-skills: RouterOS hotspot captive portal for wired/wireless access control. Use when: configuring hotspot on RouterOS, setting up captive portal, writing hotspot profiles or instances, configuring walled garden, setting DHCP option 114 (RFC 8910 captive portal URI), integrating RADIUS with hotspot, or when the user mentions /ip/hotspot, walled-garden, hotspot profile, or captive portal on MikroTik..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# RouterOS Hotspot

## How Hotspot Chains Work

Hotspot traffic intercept runs **before** the regular firewall input/forward chains. This is the single most important fact to internalize:

- `/ip/hotspot` binds to a bridge or interface — all traffic on that interface enters the hotspot chain first
- Firewall rules blocking TCP 80/443 from the hotspot interface do **NOT** block the captive portal login page — hotspot handles it before the firewall sees it
- RouterOS automatically injects dynamic firewall rules (`hs-unauth`, `hs-auth` chains) — do not manually create, remove, or interfere with these hotspot-managed rules

**Common mistake:** Adding a DROP rule for port 443 from bridge-hotspot to "fix a security gap" — this breaks the HTTPS login page silently.

## Hotspot Profile

```routeros
/ip/hotspot/profile/add \
  name=my-profile \
  hotspot-address=10.20.0.1 \
  login-by=https,mac,http-pap \
  mac-auth-mode=mac-as-username-and-password \
  dns-name=login.example.com \
  ssl-certificate=login.example.com.crt_0 \
  nas-port-type=ethernet \
  use-radius=yes \
  radius-accounting=yes \
  html-directory-override=hotspot-files
```

Key properties:
…

Read the whole file at its exact version.

How to install

Latest version
mdr add tikoci/routeros-skills/routeros-hotspot@git:20260626.5284858
Exact content
mdr add tikoci/routeros-skills/routeros-hotspot@sha256:9ba41f79b9189ccb

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_3fopwrnumhe2ggru.svg)](https://markdownregistry.com/a/art_3fopwrnumhe2ggru)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260626.5284858 latest2026-06-26 5284858 9,610 BB view · diff
git:20260527.cdf00112026-05-27 cdf0011 9,600 BB view · diff
git:20260507.2ea4c622026-05-07 2ea4c62 11,597 BB view · diff
git:20260507.70736932026-05-07 7073693 11,552 BB view

Audit of the latest version

B  16 of 17 checks passed. Deterministic, no model, same answer every run.
  • fail: No script tag (matched: <script)
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (9610 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address

Source

GitHub

tikoci/routeros-skills · 64 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_3fopwrnumhe2ggru
GET https://markdownregistry.com/api/v1/resolve?ref=tikoci/routeros-skills/routeros-hotspot
GET https://markdownregistry.com/api/v1/blob/9ba41f79b9189ccb50754f26125eda6309899c4a5b636a38468647d6490c7c4e

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from tikoci/routeros-skills

routeros-app-yaml skill
tikoci/routeros-skills · routeros-app-yaml/SKILL.md · RouterOS /app YAML format for container applications (7.21+ builtin app, 7.22+ custom YAML creation). Use when: writing…
git:20260626.5284858 · audit A · 64 stars
routeros-centrs skill
tikoci/routeros-skills · routeros-centrs/SKILL.md · Use whenever a task touches a real MikroTik RouterOS device or CHR: reading or changing config, running a RouterOS CLI…
git:20260921.bf6c644 · audit A · 64 stars
routeros-command-tree skill
tikoci/routeros-skills · routeros-command-tree/SKILL.md · RouterOS command tree introspection via /console/inspect API. Use when: building tools that parse RouterOS commands…
git:20260718.14fcd40 · audit A · 64 stars
routeros-container skill
tikoci/routeros-skills · routeros-container/SKILL.md · RouterOS /container subsystem for running OCI containers on MikroTik devices. Use when: enabling containers on…
git:20260626.5284858 · audit B · 64 stars
routeros-firewall skill
tikoci/routeros-skills · routeros-firewall/SKILL.md · RouterOS firewall filter, NAT, mangle, and address-list configuration. Use when: writing firewall rules in RouterOS…
git:20260626.5284858 · audit A · 64 stars
routeros-fundamentals skill
tikoci/routeros-skills · routeros-fundamentals/SKILL.md · RouterOS v7 domain knowledge for AI agents. Use when: working with MikroTik RouterOS, writing RouterOS CLI/script…
git:20260626.5284858 · audit A · 64 stars
routeros-mac-telnet skill
tikoci/routeros-skills · routeros-mac-telnet/SKILL.md · MAC-Telnet protocol (MikroTik Layer-2 terminal/exec over UDP 20561) wire format, session handshake, and MD5 + MTWEI…
git:20260626.c5a9200 · audit A · 64 stars
routeros-mndp skill
tikoci/routeros-skills · routeros-mndp/SKILL.md · MNDP (MikroTik Neighbor Discovery Protocol) wire format, behavior, and RouterOS /ip/neighbor integration. Use when…
git:20260626.5284858 · audit A · 64 stars
routeros-netinstall skill
tikoci/routeros-skills · routeros-netinstall/SKILL.md · MikroTik netinstall-cli for automated RouterOS device flashing. Use when: automating netinstall, writing scripts that…
git:20260417.77838ab · audit A · 64 stars
routeros-qemu-chr skill
tikoci/routeros-skills · routeros-qemu-chr/SKILL.md · MikroTik RouterOS CHR (Cloud Hosted Router) with QEMU. Use when: running RouterOS in QEMU, booting CHR images…
git:20260626.83bbe1f · audit B · 64 stars
routeros-quickchr-cli skill
tikoci/routeros-skills · routeros-quickchr-cli/SKILL.md · Answer a RouterOS question by asking RouterOS. quickchr boots a real, disposable MikroTik CHR router on the local…
git:20260921.bf6c644 · audit B · 64 stars
routeros-quickchr skill
tikoci/routeros-skills · routeros-quickchr/SKILL.md · Ground RouterOS config/scripts/API code against a REAL router using quickchr (@tikoci/quickchr) — a CLI + Bun/TS…
git:20260921.bf6c644 · audit A · 64 stars

Every file in tikoci/routeros-skills

Browse by kind, by grade B, or by owner.