packetsniffer-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| MCP_AGENTIC | No | Set to 1 to enable CodeMode agentic discovery (equivalent to the --agentic flag). | |
| GOOGLE_API_KEY | No | Standard API key detected by the Google cloud provider. | |
| OPENAI_API_KEY | No | Standard API key detected by the OpenAI cloud provider. | |
| ANTHROPIC_API_KEY | No | Standard API key detected by the Anthropic cloud provider. | |
| PACKETSNIFFER_MCP_LLM_MODEL | No | Override the model name. | |
| PACKETSNIFFER_MCP_LLM_API_KEY | No | API key for cloud LLM providers. | |
| PACKETSNIFFER_MCP_LLM_PROVIDER | No | LLM provider to use: ollama | lmstudio | openai | anthropic | google. Local providers (Ollama on :11434, LM Studio on :1234) are auto-detected. | |
| PACKETSNIFFER_MCP_MAX_SNIFF_COUNT | No | Raise the maximum capture count ceiling (default max 1000). | |
| PACKETSNIFFER_MCP_MAX_SNIFF_SECONDS | No | Raise the maximum capture timeout ceiling (default max 300s). |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| agentic_packetsniffer_mcp_workflowC | Run a multi-step workflow using FastMCP sampling when the client supports it. |
| helpB | List capabilities and fleet surface for PacketsnifferMcp. |
| statusB | Server health and version. |
| chatA | Chat with the configured LLM provider (local or cloud). Uses the unified LLM client which auto-detects local providers (Ollama, LM Studio) and supports cloud providers (OpenAI, Anthropic, Google Gemini) via API keys. The provider and model can be overridden per-request. Return Format{"success": bool, "content": str, "model": str, "provider": str} Examplesawait chat(prompt="What is the capital of Austria?") await chat(prompt="Explain quantum computing in 3 sentences", system="Be concise.") await chat(prompt="Hello", provider="openai", model="gpt-4o") await chat(prompt="Describe Vienna", temperature=0.3) |
| packetsniffer_opsA | Network interface discovery, live packet capture, and PCAP analysis. [RATIONALE] Consolidates local packet sniffing, background captures, and offline PCAP analysis tools to stay under tool limits while providing full companion hacking capability. Operations:
Hardware-protocol reverse engineering (pure Python, no tshark needed; for working out what bytes a host sends a device such as a label printer):
Return Format{"success": bool, "operation": str, "data": dict | list} Examplesawait packetsniffer_ops(operation="list_interfaces") await packetsniffer_ops(operation="sniff", interface="WiFi", count=10) await packetsniffer_ops(operation="sniff", filter_expr="udp port 53", count=200, timeout=120, save_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="start_capture", filter_expr="udp port 53", count=1000, timeout=300) await packetsniffer_ops(operation="capture_status", capture_id="a1b2c3d4") await packetsniffer_ops(operation="stop_capture", capture_id="a1b2c3d4", save_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="decode_pcap", file_path="C:/captures/dns.pcap", limit=100) await packetsniffer_ops(operation="analyze_pcap", file_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="usb_list_hubs") await packetsniffer_ops(operation="usb_capture", usb_hub="\.\USBPcap1", timeout=30, save_path="C:/captures/02-dot.pcap") await packetsniffer_ops(operation="usb_payloads", file_path="C:/captures/02-dot.pcap", export_path="C:/captures/02-dot.bin") await packetsniffer_ops(operation="btsnoop_payloads", file_path="C:/captures/btsnoop_hci.log", direction="tx") await packetsniffer_ops(operation="diff_captures", file_path="C:/captures/01-blank.pcap", file_path_b="C:/captures/02-dot.pcap") |
| packetsniffer_mcp_status_cardB | Server health as a Prefab card. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| packetsniffer_mcp_session |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| packetsniffer_mcp_skills | |
| packetsniffer_mcp_capabilities |
TDQS
Scored across 6 tools
Most tools target distinct concerns, but 'status' and 'packetsniffer_mcp_status_card' both expose server health (differing only in output format), and 'agentic_packetsniffer_mcp_workflow' has a vague, undefined purpose that overlaps conceptually with both chat and ops orchestration. An agent can mostly tell them apart, but the redundancy and the fuzzy workflow tool create real selection risk.
All names are snake_case, but prefixing is inconsistent: three tools carry a 'packetsniffer'/'agentic_packetsniffer_mcp' namespace prefix while 'help', 'status', and 'chat' are bare, and the naming mixes workflow-style, health-style, and action-style conventions. Readable but not a predictable pattern.
Six top-level tools is a reasonable, well-scoped surface for this server. However, 'packetsniffer_ops' is an over-consolidated mega-tool packing roughly 14 distinct operations, which pushes complexity into a single tool rather than the count itself.
The ops tool covers the sniffing lifecycle well: interface discovery, blocking/background capture, capture status, stop, PCAP decode and analysis, plus USB and Bluetooth payload extraction and diffing. Minor gaps remain (no live stream display, packet injection, or filter validation), but core workflows are covered.