routeros-sniffer
Debug RouterOS Packet Captures
RouterOS packet capture setup is hard to remember during network debugging. This skill guides TZSP streaming, pcap saving, and receiver setup.
This skill is part of a pack
Install the whole pack to get every skill the task needs, in one command.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "routeros-sniffer" from https://skillstore.io/skills/tikoci-routeros-sniffer.md and its manifest at https://skillstore.io/api/skills/tikoci-routeros-sniffer/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "routeros-sniffer". I need to see whether DNS queries leave a RouterOS bridge.
Expected outcome:
- A focused capture plan using a DNS filter and a clear start and stop point.
- A receiver checklist for Wireshark or tshark on the default TZSP port.
- Cleanup notes for removing temporary capture settings.
Using "routeros-sniffer". I want to mirror one client to tshark for five minutes.
Expected outcome:
- A narrow mangle-based mirroring plan for the selected client address.
- A reminder to confirm authorization before collecting packet payloads.
- A verification checklist that confirms packets arrive at the receiver.
Using "routeros-sniffer". My CHR lab is not sending TZSP packets to the host.
Expected outcome:
- A troubleshooting path for QEMU host addressing, receiver binding, and port selection.
- Likely causes such as wrong receiver IP, host firewall rules, or missing sniffer start state.
Security Audit
High RiskThe strongest confirmed issues are privileged firewall-change commands and security-sensitive packet mirroring guidance. Most static hits are false positives from Markdown code fences, placeholders, private lab IPs, temporary capture paths, or documentation links. No evidence of prompt injection was found.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (59)
๐ Network access (15)
๐ Filesystem access (5)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/tikoci-routeros-sniffer/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/tikoci-routeros-sniffer?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/tikoci-routeros-sniffer?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/tikoci-routeros-sniffer/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/tikoci-routeros-sniffer.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
tikoci. (2026). routeros-sniffer security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/tikoci-routeros-sniffer/audits/6BibTeX citation
@techreport{tikoci-tikoci-routeros-sniffer-2026,
author = {tikoci},
title = {routeros-sniffer security audit report (audit version 6)},
institution = {Skillstore},
year = {2026},
number = {6},
url = {https://skillstore.io/skills/tikoci-routeros-sniffer/audits/6},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "routeros-sniffer security audit report (audit version 6)"
version: "unspecified"
type: report
authors:
- name: "tikoci"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/tikoci-routeros-sniffer/audits/6"
identifiers:
- type: other
value: "skillstore:tikoci-routeros-sniffer:audit:6"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Diagnose a RouterOS Connectivity Issue
Capture ICMP, DNS, or TCP traffic to confirm whether packets reach the expected interface.
Build a CHR Packet Lab
Use QEMU CHR and TZSP streaming to reproduce protocol behavior without physical hardware.
Collect Evidence for Incident Triage
Mirror a narrow traffic flow to Wireshark or tshark for authorized investigation.
Try These Prompts
Help me capture ICMP traffic on a RouterOS interface and save it as a pcap file.
Guide me through streaming RouterOS sniffer output to a tshark receiver on my workstation.
Create an authorized sniff-tzsp mangle workflow for one host and explain how to remove it afterward.
Plan a RouterOS CHR packet capture lab with TZSP streaming, receiver validation, and cleanup steps.
Best Practices
- Capture only the minimum traffic needed for the investigation.
- Use authorized lab or production windows before enabling packet mirroring.
- Stop captures and remove temporary mangle rules after testing.
Avoid
- Do not capture broad production traffic without approval.
- Do not leave TZSP receivers or firewall openings enabled after debugging.
- Do not share pcap files before checking for credentials or private data.
Frequently Asked Questions
Does this skill run packet captures automatically?
Which tools can receive TZSP traffic?
Can it save captures on the RouterOS device?
Can it mirror only one flow?
Does hardware offload affect captures?
Is packet capture sensitive?
Developer Details
Author
tikociLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
26421118b848d9f1efc0aa169d8a7a9e7e0a877e
Maintenance freshness
7/18/2026
Usage
4 downloads ยท 115 views
File structure