wireshark-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_interfacesA | List capture interfaces, with whether live capture is currently permitted. |
| start_captureB | Capture live packets on an interface. Always bounded by BOTH duration_s and max_packets. |
| list_capturesA | List capture files this server has stored. |
| packet_summaryB | One line per packet, optionally narrowed by a Wireshark display filter. |
| packet_detailB | Full decoded protocol tree for a single frame. |
| capture_infoC | capinfos summary: packet count, duration, byte totals, encapsulation. |
| protocol_hierarchyC | Protocol hierarchy statistics for the whole capture. |
| conversationsC | Conversation statistics. type is one of tcp, udp, ip, eth. |
| endpointsC | Endpoint statistics. type is one of tcp, udp, ip, eth. |
| io_statsC | Traffic volume over time, bucketed by interval_s seconds. |
| expert_infoC | Wireshark expert info: retransmissions, resets, malformed packets, warnings. |
| follow_streamC | Reassemble one stream as ASCII. protocol is one of tcp, udp, http. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| triage_capture | |
| tls_failures | |
| find_slow_requests |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 12 tools
Each tool targets a distinct task: capture management, packet inspection, and separate statistical views. packet_summary and packet_detail are clearly differentiated by granularity, and capture_info, protocol_hierarchy, conversations, endpoints, io_stats, and expert_info all answer different questions.
Names are readable lower_snake, but the pattern is mixed: list_captures, list_interfaces, start_capture, and follow_stream are verb_noun while packet_summary, packet_detail, capture_info, protocol_hierarchy, conversations, endpoints, io_stats, and expert_info are noun-style result names. The split between command-style and result-style names is noticeable but not chaotic.
Twelve tools is a well-scoped set for a Wireshark-oriented server: capture control, packet inspection, and a range of statistical analyses each earn their place. It stays within the ideal range and avoids unnecessary overlap.
The surface covers the core workflow: discover interfaces, start bounded captures, list stored captures, inspect frames, and compute standard Wireshark statistics. It includes both packet-level detail and protocol/expert diagnostics, so there are no obvious dead ends.