Home / tikoci / routeros-skills · routeros-sniffer/SKILL.md · GitHub

routeros-sniffer skillA

routeros-sniffer is agent-read markdown (skill) from tikoci/routeros-skills: RouterOS packet capture and TZSP streaming for protocol debugging. Use when: capturing packets on RouterOS, setting up /tool/sniffer, streaming live traffic via TZSP, using firewall mangle action=sniff-tzsp, debugging network protocols on MikroTik, receiving TZSP with Wireshark or tshark, saving pcap files from RouterOS, or when the user mentions packet sniffer, TZSP, sniff-tzsp, /tool/sniffer, or packet capture on RouterOS..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# RouterOS Packet Capture & TZSP Streaming

RouterOS has a built-in packet sniffer (`/tool/sniffer`) and firewall mangle actions that can mirror traffic — either saving to a file on the router or streaming live to a remote host via TZSP (TaZmen Sniffer Protocol). This is the primary way to capture packets on RouterOS since standard tools like `tcpdump` do not exist (see `routeros-fundamentals` skill).

## Why This Matters for Agents

When debugging any network protocol issue on RouterOS, agents should know they can:

1. **Stream live packets** from the router to the host machine via TZSP — no hardware needed if using a CHR VM
2. **Save pcap/pcapng files** on the router's flash and download them for analysis
3. **Use firewall mangle rules** for surgical, per-flow packet mirroring without touching the sniffer config

Combined with a QEMU CHR instance (see `routeros-qemu-chr` skill), this gives agents a complete packet-level debugging workflow with zero physical hardware.

## Method 1: /tool/sniffer (Full Capture Tool)

The built-in sniffer captures packets on specified interfaces with extensive filtering. It supports **three independent output modes** that can be combined:
…

Read the whole file at its exact version.

How to install

Latest version
mdr add tikoci/routeros-skills/routeros-sniffer@git:20260626.5284858
Exact content
mdr add tikoci/routeros-skills/routeros-sniffer@sha256:3e947f12ba7083ff

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_iblavt64dnyrpp7f.svg)](https://markdownregistry.com/a/art_iblavt64dnyrpp7f)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260626.5284858 latest2026-06-26 5284858 10,504 BA view · diff
git:20260416.e882ae12026-04-16 e882ae1 10,494 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (10504 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

tikoci/routeros-skills · 64 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_iblavt64dnyrpp7f
GET https://markdownregistry.com/api/v1/resolve?ref=tikoci/routeros-skills/routeros-sniffer
GET https://markdownregistry.com/api/v1/blob/3e947f12ba7083ff3e0a4a8962f4f5af021d8d49fb4a16a83039cf494e1d6751

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from tikoci/routeros-skills

routeros-app-yaml skill
tikoci/routeros-skills · routeros-app-yaml/SKILL.md · RouterOS /app YAML format for container applications (7.21+ builtin app, 7.22+ custom YAML creation). Use when: writing…
git:20260626.5284858 · audit A · 64 stars
routeros-centrs skill
tikoci/routeros-skills · routeros-centrs/SKILL.md · Use whenever a task touches a real MikroTik RouterOS device or CHR: reading or changing config, running a RouterOS CLI…
git:20260921.bf6c644 · audit A · 64 stars
routeros-command-tree skill
tikoci/routeros-skills · routeros-command-tree/SKILL.md · RouterOS command tree introspection via /console/inspect API. Use when: building tools that parse RouterOS commands…
git:20260718.14fcd40 · audit A · 64 stars
routeros-container skill
tikoci/routeros-skills · routeros-container/SKILL.md · RouterOS /container subsystem for running OCI containers on MikroTik devices. Use when: enabling containers on…
git:20260626.5284858 · audit B · 64 stars
routeros-firewall skill
tikoci/routeros-skills · routeros-firewall/SKILL.md · RouterOS firewall filter, NAT, mangle, and address-list configuration. Use when: writing firewall rules in RouterOS…
git:20260626.5284858 · audit A · 64 stars
routeros-fundamentals skill
tikoci/routeros-skills · routeros-fundamentals/SKILL.md · RouterOS v7 domain knowledge for AI agents. Use when: working with MikroTik RouterOS, writing RouterOS CLI/script…
git:20260626.5284858 · audit A · 64 stars
routeros-hotspot skill
tikoci/routeros-skills · routeros-hotspot/SKILL.md · RouterOS hotspot captive portal for wired/wireless access control. Use when: configuring hotspot on RouterOS, setting…
git:20260626.5284858 · audit B · 64 stars
routeros-mac-telnet skill
tikoci/routeros-skills · routeros-mac-telnet/SKILL.md · MAC-Telnet protocol (MikroTik Layer-2 terminal/exec over UDP 20561) wire format, session handshake, and MD5 + MTWEI…
git:20260626.c5a9200 · audit A · 64 stars
routeros-mndp skill
tikoci/routeros-skills · routeros-mndp/SKILL.md · MNDP (MikroTik Neighbor Discovery Protocol) wire format, behavior, and RouterOS /ip/neighbor integration. Use when…
git:20260626.5284858 · audit A · 64 stars
routeros-netinstall skill
tikoci/routeros-skills · routeros-netinstall/SKILL.md · MikroTik netinstall-cli for automated RouterOS device flashing. Use when: automating netinstall, writing scripts that…
git:20260417.77838ab · audit A · 64 stars
routeros-qemu-chr skill
tikoci/routeros-skills · routeros-qemu-chr/SKILL.md · MikroTik RouterOS CHR (Cloud Hosted Router) with QEMU. Use when: running RouterOS in QEMU, booting CHR images…
git:20260626.83bbe1f · audit B · 64 stars
routeros-quickchr-cli skill
tikoci/routeros-skills · routeros-quickchr-cli/SKILL.md · Answer a RouterOS question by asking RouterOS. quickchr boots a real, disposable MikroTik CHR router on the local…
git:20260921.bf6c644 · audit B · 64 stars

Every file in tikoci/routeros-skills

Browse by kind, by grade A, or by owner.