← OGENIC GOD TOOLKITCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to OGENIC GOD TOOLKIT
Snapshot Sep 30, 2026 · 23:15 UTC · version 1.2.4
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Run a complete read-only network survey end to end: get access, crawl the topology, diagnose every device, draw the diagram and produce a deliverable report. Loops netwalk-login, netwalk-scan and netwalk-diag until the crawl runs dry or the engineer is satisfied, then finishes once with netwalk-map and netwalk-fullreport. Use when the user wants a whole network surveyed, audited or documented rather than one specific step - 'survey this site', 'audit my customer's network', 'document what is on this LAN'.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 184
}
],
"name": "netwalk",
"skill_md_contents": "---\nname: netwalk\ndescription: 'Run a complete read-only network survey end to end: get access, crawl the topology, diagnose every device, draw the diagram and produce a deliverable report. Loops netwalk-login, netwalk-scan and netwalk-diag until the crawl runs dry or the engineer is satisfied, then finishes once with netwalk-map and netwalk-fullreport. Use when the user wants a whole network surveyed, audited or documented rather than one specific step - ''survey this site'', ''audit my customer''s network'', ''document what is on this LAN''.'\n---\n\n# netwalk\n\nThe umbrella workflow for the **netwalk** read-only network survey toolkit.\nToolkit lives at `{{TOOLKIT}}`.\n\nEach stage is also a skill in its own right. Use this one when the user wants the whole job;\ninvoke a single stage directly when they want just that step.\n\n```\n ┌─────────────────── repeat until the frontier is empty ───────────────────┐\n │ │\n ▼ │\n netwalk-login ──► netwalk-scan ──► netwalk-diag ───────────────────────────┘\n get access crawl a hop read its health\n (form stays open) find neighbours export config, find faults\n ▲ │\n └── new devices ─────┘ each round's discoveries go back on the same form\n\n when the crawl runs dry, or the engineer says enough\n │\n ▼\n netwalk-map ──► netwalk-fullreport\n draw it hand it over\n```\n\n`netwalk-login`, `netwalk-scan` and `netwalk-diag` are **one loop, not three phases**. Every hop turns up devices nobody\nmentioned; those go straight back onto the credential form that is already open, the engineer answers\nthem at their own pace, and the crawl carries on. It ends when a round finds nothing the engineer has\nnot already ruled on — or when they decide the coverage is good enough. `map` and `fullreport` run\nonce at the end, over whatever the loop actually reached.\n\n## The three promises\n\n1. **Read-only.** Every command is checked against a per-vendor allowlist in\n `scripts/netwalk_policy.py` before it is sent. Config writes, counter clears, service restarts\n and reboots are refused by the tool, not by good intentions. Config is exported, never imported.\n2. **Credentials never enter the conversation.** They are typed into a page served on the user's own\n `127.0.0.1`, stored in a private file, and read by the exec wrapper — never by you. The same page\n carries the *access* questions: which URL, which port, which jump host, which controller site. When\n you are blocked on how to reach something, put the question on the form with `--ask` and let the\n user answer it there, rather than asking across several conversational turns.\n3. **No unauthorised sweeping.** `netwalk_sweep.py` refuses any address range that is not in\n the site's `scope.json` with the name of whoever authorised it. There is no override flag.\n Crawling from a device you were given a credential for is not the same as probing addresses\n nobody named.\n\nAll three are enforced in code. Do not route around any of them. If a read-only command is wrongly blocked,\nadd it to the allowlist, run `python3 {{TOOLKIT}}/tests/test_policy.py`, and say you did.\n\n## Stage 0 — scope it\n\nBefore running anything:\n\n- **What is the target?** netwalk needs one device it can log into and crawls out from there. It can\n also sweep an address range, but only after the owner has authorised that range by name\n (`netwalk_sweep.py authorize`) — the gate is enforced in code and has no override.\n- **Whose network is it?** For a customer site, confirm the user is authorised to log into this\n equipment today, and write what they say into `site.scope_note`. It appears in the report.\n- **What is off limits?** Fragile boxes, maintenance windows, devices to leave alone. Record them\n under `coverage.not_covered` so the report does not imply they were checked.\n- **What are we actually answering?** \"Document the network\" and \"find why the Wi-Fi drops at 2pm\"\n produce different scans. Ask.\n\nPick a site slug (`acme-hq`). Everything for the engagement lands in `~/.netwalk/sites/<slug>/` — outside the installed toolkit, so an upgrade cannot delete it.\n\n## The loop, and how it ends\n\nStages 1 to 3 repeat. Do not run them once each and call the survey done: a crawl discovers devices\nover minutes, each round turns up neighbours nobody mentioned, and those go back on the credential\nform that is already open rather than into the conversation.\n\nTwo things end the loop, and only two:\n\n- **the frontier is empty** — a round finds no device the engineer has not already ruled on, whether\n by giving a credential, saying \"I don't know what this is\", marking it out of scope, or deferring it\n- **the engineer says the coverage is good enough** — a legitimate answer on a large site, and one you\n should offer explicitly rather than crawling on\n\nEither way, write what was reached and what was not into `coverage.not_covered` before moving on.\nStages 4 and 5 run **once**, at the end, over whatever the loop actually reached.\n\n## Stage 1 — access (`netwalk-login`)\n\nServe the credential form for the entry device. Never take a secret in the chat, not even offered, and\nput any \"how do I reach this\" question on the same form with `--ask` instead of in the conversation.\nHand the `netwalk_cred.py request` command to the user to run in their own terminal (`!` prefix in\nClaude Code) rather than running it as a background task — it waits on a human, and a reaped task\ntakes the one-time URL with it. Verify with `netwalk_exec.py probe` before moving on; an unverified\ncredential wastes the whole next stage.\n\n## Stage 2 — crawl (`netwalk-scan`)\n\nRun the vendor discovery pack, map the output into the scan record, then hop to every neighbour that\nhas not been visited and repeat until the frontier is empty. Each round, put **all** the newly\ndiscovered devices on the login form at once (`--round N`) rather than asking about them one by one;\nthe user can answer \"I don't know what this is\" or \"not ours\" per device, and both are real results\nthat go in the report. Stop when a round produces nothing the user has not already ruled on. Re-run the map and report after each\nbatch so the user can correct a wrong assumption early. Devices you cannot reach stay in the record\nas `reachable: false` with a reason.\n\n**Sweep the subnets the crawl walked through**, once the owner has authorised them by name. The\ncrawl only finds what announces itself; a sweep finds the static-address server and the forgotten\nprinter, and it is usually where the surprises are:\n\n```bash\npython3 {{TOOLKIT}}/scripts/netwalk_sweep.py authorize --site <slug> --range 10.2.30.0/24 \\\n --authorized-by \"who said yes, and when\"\npython3 {{TOOLKIT}}/scripts/netwalk_sweep.py hosts --site <slug> --range 10.2.30.0/24\npython3 {{TOOLKIT}}/scripts/netwalk_sweep.py ports --site <slug> --target 10.2.30.99\npython3 {{TOOLKIT}}/scripts/netwalk_sweep.py record --site <slug> --record <record>.json\n```\n\nEverything that answers and is not already a device goes back onto the login form — it is another\nround of the same loop, not a separate exercise. The sweep is TCP-only and therefore blind to UDP\nand to hosts that drop rather than reject; `record` writes that into `coverage.not_covered`.\n\n## Stage 3 — diagnose (`netwalk-diag`)\n\nExport config read-only and collect CPU, memory, storage, temperature, PoE, interface errors and\nflap counts, throughput, sessions, services and logs. Turn observations into findings with evidence\nand a recommendation a technician can act on. Divide counters by uptime before calling anything a\nfault.\n\n## Stage 4 — draw (`netwalk-map`)\n\nDeterministic SVG from the record. One box per internet uplink, port labels on every link, dashed\nfor anything inferred. Fix the record, never the SVG.\n\n## Stage 5 — deliver (`netwalk-fullreport`)\n\nOne self-contained HTML file. Produce the full copy for the user; produce `--public` as well when\nthe report is going to someone who should see the shape of the network but not a list of ways into\nit. The renderer refuses to build a report from a record containing credential material.\n\n## Stage 6 — close out\n\n- Tell the user every file path you produced and which mode each report is.\n- Say plainly what was **not** covered. A polished document should never imply a completeness the\n scan did not have.\n- Offer to clear the credential store:\n `python3 {{TOOLKIT}}/scripts/netwalk_cred.py forget --site <slug> --with-configs`\n — **on every machine the survey ran from.** Nothing expires on its own, and `--with-configs`\n is what removes the configuration exports, which hold PSKs and password hashes and are the\n more dangerous of the two. Without the flag the command tells you how many are still there.\n If the credentials were sensitive, recommend rotating them — overwrite-then-delete is not a\n forensic wipe on modern storage.\n\n## Layout on disk\n\n```\n~/.netwalk/sites/<slug>/\n scan-YYYY-MM-DD.json the record - single source of truth, never overwritten\n evidence.jsonl every command run, appended as it happens\n configs/<host>.conf read-only config exports (contain secrets - never into the report)\n map.svg\n report.html full\n report-public.html for the site owner\n```\n\nRecords accumulate one per scan date, so two surveys of one site diff cleanly.\n\n## Never\n\n- Change anything on a surveyed device. Report the fix; the owner applies it.\n- Accept a credential in the conversation, or open the credential store yourself.\n- Scan or sweep outside the agreed scope. A range the owner has not authorised by name is refused\n by `netwalk_sweep.py`, and that refusal is the correct answer, not an obstacle.\n- Present an incomplete crawl as complete.\n"
}SHA-256 of public snapshot: bb454d457afcfa6ea004f7faf764004e43c127602587436d29ab8e8a7c5b560e