routeros-sniffer skillA
routeros-sniffer is agent-read markdown (skill) from tikoci/routeros-skills: RouterOS packet capture and TZSP streaming for protocol debugging. Use when: capturing packets on RouterOS, setting up /tool/sniffer, streaming live traffic via TZSP, using firewall mangle action=sniff-tzsp, debugging network protocols on MikroTik, receiving TZSP with Wireshark or tshark, saving pcap files from RouterOS, or when the user mentions packet sniffer, TZSP, sniff-tzsp, /tool/sniffer, or packet capture on RouterOS..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# RouterOS Packet Capture & TZSP Streaming RouterOS has a built-in packet sniffer (`/tool/sniffer`) and firewall mangle actions that can mirror traffic — either saving to a file on the router or streaming live to a remote host via TZSP (TaZmen Sniffer Protocol). This is the primary way to capture packets on RouterOS since standard tools like `tcpdump` do not exist (see `routeros-fundamentals` skill). ## Why This Matters for Agents When debugging any network protocol issue on RouterOS, agents should know they can: 1. **Stream live packets** from the router to the host machine via TZSP — no hardware needed if using a CHR VM 2. **Save pcap/pcapng files** on the router's flash and download them for analysis 3. **Use firewall mangle rules** for surgical, per-flow packet mirroring without touching the sniffer config Combined with a QEMU CHR instance (see `routeros-qemu-chr` skill), this gives agents a complete packet-level debugging workflow with zero physical hardware. ## Method 1: /tool/sniffer (Full Capture Tool) The built-in sniffer captures packets on specified interfaces with extensive filtering. It supports **three independent output modes** that can be combined: …
Read the whole file at its exact version.
How to install
mdr add tikoci/routeros-skills/routeros-sniffer@git:20260626.5284858mdr add tikoci/routeros-skills/routeros-sniffer@sha256:3e947f12ba7083ffPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_iblavt64dnyrpp7f)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260626.5284858 latest | 2026-06-26 | 5284858 | 10,504 B | A | view · diff |
| git:20260416.e882ae1 | 2026-04-16 | e882ae1 | 10,494 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (10504 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
tikoci/routeros-skills · 64 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_iblavt64dnyrpp7f GET https://markdownregistry.com/api/v1/resolve?ref=tikoci/routeros-skills/routeros-sniffer GET https://markdownregistry.com/api/v1/blob/3e947f12ba7083ff3e0a4a8962f4f5af021d8d49fb4a16a83039cf494e1d6751
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.