Install
$ agentstack add skill-affaan-m-ecc-network-bgp-diagnostics ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ● Dynamic code execution Used
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Network BGP Diagnostics
Use this skill when a BGP session is down, flapping, established with missing routes, or advertising unexpected prefixes. The default workflow is read-only evidence collection; policy and reset actions belong in a reviewed change window.
When to Use
- BGP neighbors are stuck in Idle, Connect, Active, OpenSent, or OpenConfirm.
- A session is Established but expected prefixes are missing.
- A route-map, prefix-list, max-prefix limit, or AS path policy may be filtering
routes.
- You need before/after evidence for a BGP change.
- You are reviewing automation that parses BGP summary output.
Read-Only Triage Flow
- Identify the exact neighbor, address family, VRF, and local/remote ASNs.
- Capture summary state and last reset reason.
- Prove reachability to the peer source address.
- Check route policy references before assuming transport failure.
- Compare advertised, received, and installed routes where the platform
supports those commands.
show bgp summary
show bgp neighbors
show ip route
show tcp brief | include |:179
show logging | include BGP|
show running-config | section router bgp
show ip prefix-list
show route-map
Use platform-specific address-family commands when the device uses VRFs, IPv6, VPNv4, or EVPN. Do not assume global IPv4 unicast.
State Interpretation
| State | First checks | | --- | --- | | Established with prefix count | Route exchange is up; inspect policy and table selection | | Established with zero prefixes | Check inbound policy, max-prefix, advertised routes, and AFI/SAFI | | Active | TCP session is not completing; check routing, source, ACLs, and peer reachability | | Connect | TCP connection is in progress; check path and remote listener | | OpenSent/OpenConfirm | TCP works; check ASN, authentication, timers, capabilities, and logs | | Idle | Neighbor may be disabled, missing config, blocked by policy, or backoff timer |
Transport Checks
ping source
traceroute source
show ip route
show bgp neighbors | include BGP state|Last reset|Local host|Foreign host
If the peer is sourced from a loopback, confirm both directions route to the loopback addresses and that the neighbor config uses the expected update source.
Avoid disabling ACLs or firewall policy as a diagnostic shortcut. Read hit counters, logs, and path state first.
Route Policy Checks
show bgp neighbors advertised-routes
show bgp neighbors routes
show ip prefix-list
show route-map
show bgp
Some platforms require additional configuration before received-routes is available. Do not add that configuration during incident triage unless the operator approves the change.
AS Path And Prefix Review
show bgp regexp _65001_
show bgp regexp ^65001$
show bgp
show bgp neighbors advertised-routes | include Network|Path|
Use AS-path regex carefully. _65001_ matches AS 65001 as a token. Plain 65001 can match longer ASNs or unrelated text.
Parser Pattern
import re
from typing import Any
BGP_SUMMARY_RE = re.compile(
r"^(?P\d{1,3}(?:\.\d{1,3}){3})\s+"
r"(?P\d+)\s+"
r"(?P\d+)\s+"
r"(?P\d+)\s+"
r"(?P\d+)\s+"
r"(?P\d+)\s+"
r"(?P\d+)\s+"
r"(?P\d+)\s+"
r"(?P\S+)\s+"
r"(?P\S+)$",
re.M,
)
def parse_bgp_summary(raw: str) -> list[dict[str, Any]]:
rows = []
for match in BGP_SUMMARY_RE.finditer(raw):
state_or_prefixes = match.group("state_or_prefixes")
if state_or_prefixes.isdigit():
state = "Established"
prefixes_received = int(state_or_prefixes)
else:
state = state_or_prefixes
prefixes_received = None
rows.append({
"neighbor": match.group("neighbor"),
"remote_as": int(match.group("remote_as")),
"state": state,
"prefixes_received": prefixes_received,
"uptime": match.group("uptime"),
})
return rows
Prefer structured parser output when available, but store raw output with the incident record because BGP summary formats vary by platform and address family.
Change-Window Only
These actions can affect routing and should not be suggested as automatic diagnostics:
- Clearing a BGP session.
- Changing neighbor authentication, timers, update source, route-maps, or
prefix-lists.
- Enabling additional received-route storage.
- Relaxing firewall, ACL, or control-plane policy.
If a reset is approved, prefer the least disruptive soft or route-refresh option supported by the platform and document exactly why it is safe.
Anti-Patterns
- Assuming
Activealways means the remote side is down. - Ignoring VRF, address family, or update-source differences.
- Using broad AS-path regex without token boundaries.
- Hard-resetting a peer before reading last reset reason and logs.
- Treating missing
received-routesoutput as proof that no routes arrived.
See Also
- Skill:
cisco-ios-patterns - Skill:
network-config-validation - Skill:
network-interface-health
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: affaan-m
- Source: affaan-m/ECC
- License: MIT
- Homepage: https://ecc.tools
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.