# WireMCP (Wireshark)

> Use this tool when you need to monitor and analyze network traffic in real-time, capture and inspect raw packets, or detect potential threats. WireMCP solves problems related to network diagnostics, threat hunting, and anomaly detection by providing specialized tools and integrating with URLhaus blacklist. It takes network data as input and outputs structured results, making it ideal for security analysts using AI assistants to identify and mitigate security risks.

Canonical page: https://skillsregistry.net/skills/wiremcp-network-traffic-analysis  
JSON: https://api.skillsregistry.net/v1/skills/wiremcp-network-traffic-analysis

## Description

WireMCP is a network analysis server that empowers LLMs with real-time traffic monitoring capabilities by leveraging Wireshark's tshark utility. Developed by 0xKoda, it provides five specialized tools for capturing and analyzing network data: raw packet capture, protocol statistics, conversation tracking, and threat detection through URLhaus blacklist integration. The implementation automatically locates tshark across different operating systems, handles large packet captures by intelligently trimming output, and presents results in structured formats optimized for LLM comprehension. Ideal for security analysts using AI assistants for threat hunting, network diagnostics, and anomaly detection without requiring direct access to network monitoring tools.

## Trust

- **Trust score (0–1):** 0.63
- **Verification tier:** scanned
- **Last scanned:** 2026-09-01

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** ai-ml
- **Updated:** 2026-09-01

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/wiremcp-network-traffic-analysis)
- **Repository:** <https://github.com/0xkoda/wiremcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "wiremcp-network-traffic-analysis"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/wiremcp-network-traffic-analysis` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/wiremcp-network-traffic-analysis/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
