Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MCP_AGENTICNoSet to 1 to enable CodeMode agentic discovery (equivalent to the --agentic flag).
GOOGLE_API_KEYNoStandard API key detected by the Google cloud provider.
OPENAI_API_KEYNoStandard API key detected by the OpenAI cloud provider.
ANTHROPIC_API_KEYNoStandard API key detected by the Anthropic cloud provider.
PACKETSNIFFER_MCP_LLM_MODELNoOverride the model name.
PACKETSNIFFER_MCP_LLM_API_KEYNoAPI key for cloud LLM providers.
PACKETSNIFFER_MCP_LLM_PROVIDERNoLLM provider to use: ollama | lmstudio | openai | anthropic | google. Local providers (Ollama on :11434, LM Studio on :1234) are auto-detected.
PACKETSNIFFER_MCP_MAX_SNIFF_COUNTNoRaise the maximum capture count ceiling (default max 1000).
PACKETSNIFFER_MCP_MAX_SNIFF_SECONDSNoRaise the maximum capture timeout ceiling (default max 300s).

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
logging
{}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
extensions
{
  "io.modelcontextprotocol/ui": {}
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
agentic_packetsniffer_mcp_workflowC

Run a multi-step workflow using FastMCP sampling when the client supports it.

helpB

List capabilities and fleet surface for PacketsnifferMcp.

statusB

Server health and version.

chatA

Chat with the configured LLM provider (local or cloud).

Uses the unified LLM client which auto-detects local providers (Ollama, LM Studio) and supports cloud providers (OpenAI, Anthropic, Google Gemini) via API keys.

The provider and model can be overridden per-request.

Return Format

{"success": bool, "content": str, "model": str, "provider": str}

Examples

await chat(prompt="What is the capital of Austria?") await chat(prompt="Explain quantum computing in 3 sentences", system="Be concise.") await chat(prompt="Hello", provider="openai", model="gpt-4o") await chat(prompt="Describe Vienna", temperature=0.3)

packetsniffer_opsA

Network interface discovery, live packet capture, and PCAP analysis.

[RATIONALE] Consolidates local packet sniffing, background captures, and offline PCAP analysis tools to stay under tool limits while providing full companion hacking capability.

Operations:

  • list_interfaces: List active network interfaces with details.

  • sniff: Blocking capture for the given count/timeout (requires admin privileges). Pass save_path to persist the capture to a PCAP file for later analysis or evidence.

  • start_capture: Start a capture in the background (non-blocking). Returns a capture_id immediately; the capture runs in a server thread until count/timeout is reached or stop_capture is called. In HTTP daemon mode the capture survives across agent sessions. Poll with capture_status.

  • capture_status: Status of one capture (capture_id) or all active captures.

  • stop_capture: Request a stop (takes effect on the next packet, or at timeout). Returns packets captured so far; pass save_path to persist them.

  • decode_pcap: Deep protocol decode of a PCAP/PCAPNG file via tshark (optional dependency - install Wireshark). Extracts decoded fields Scapy's thin dissectors miss: DNS query/answer names, HTTP requests, TLS SNI hostnames (catches encrypted phone-home domains). Use limit to bound output.

  • analyze_pcap: Parse a PCAP/PCAPNG capture file and summarize network flows.

Hardware-protocol reverse engineering (pure Python, no tshark needed; for working out what bytes a host sends a device such as a label printer):

  • usb_list_hubs: List USB root hubs USBPcap can capture on (needs USBPcap installed; UNVERIFIED live).

  • usb_capture: Capture USB traffic with USBPcapCMD for 'timeout' seconds into save_path (needs USBPcap and administrator rights; UNVERIFIED live). Print/operate the device during the window.

  • usb_payloads: From a USBPcap capture, the data of each transfer (default host-to-device bulk/interrupt), per-endpoint totals, and any device/interface descriptors in the capture (answers "printer class, HID, or vendor-specific?"). export_path writes the concatenated stream to a .bin file.

  • btsnoop_payloads: From a Bluetooth HCI capture (btsnoop, or pcap/pcapng link type 187/201), the RFCOMM serial-port-profile data. Best effort: capture from before the connection is made.

  • diff_captures: Compare two captures' host-to-device streams (file_path vs file_path_b): shared prefix and suffix, changed byte ranges, per-transfer differences. For controlled experiments (blank label vs one dot).

Return Format

{"success": bool, "operation": str, "data": dict | list}

Examples

await packetsniffer_ops(operation="list_interfaces") await packetsniffer_ops(operation="sniff", interface="WiFi", count=10) await packetsniffer_ops(operation="sniff", filter_expr="udp port 53", count=200, timeout=120, save_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="start_capture", filter_expr="udp port 53", count=1000, timeout=300) await packetsniffer_ops(operation="capture_status", capture_id="a1b2c3d4") await packetsniffer_ops(operation="stop_capture", capture_id="a1b2c3d4", save_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="decode_pcap", file_path="C:/captures/dns.pcap", limit=100) await packetsniffer_ops(operation="analyze_pcap", file_path="C:/captures/dns.pcap") await packetsniffer_ops(operation="usb_list_hubs") await packetsniffer_ops(operation="usb_capture", usb_hub="\.\USBPcap1", timeout=30, save_path="C:/captures/02-dot.pcap") await packetsniffer_ops(operation="usb_payloads", file_path="C:/captures/02-dot.pcap", export_path="C:/captures/02-dot.bin") await packetsniffer_ops(operation="btsnoop_payloads", file_path="C:/captures/btsnoop_hci.log", direction="tx") await packetsniffer_ops(operation="diff_captures", file_path="C:/captures/01-blank.pcap", file_path_b="C:/captures/02-dot.pcap")

packetsniffer_mcp_status_cardB

Server health as a Prefab card.

Prompts

Interactive templates invoked by user choice

NameDescription
packetsniffer_mcp_session

Resources

Contextual data attached and managed by the client

NameDescription
packetsniffer_mcp_skills
packetsniffer_mcp_capabilities

TDQS

B3.1/5.0

Scored across 6 tools

Disambiguation3/5

Most tools target distinct concerns, but 'status' and 'packetsniffer_mcp_status_card' both expose server health (differing only in output format), and 'agentic_packetsniffer_mcp_workflow' has a vague, undefined purpose that overlaps conceptually with both chat and ops orchestration. An agent can mostly tell them apart, but the redundancy and the fuzzy workflow tool create real selection risk.

Naming Consistency3/5

All names are snake_case, but prefixing is inconsistent: three tools carry a 'packetsniffer'/'agentic_packetsniffer_mcp' namespace prefix while 'help', 'status', and 'chat' are bare, and the naming mixes workflow-style, health-style, and action-style conventions. Readable but not a predictable pattern.

Tool Count4/5

Six top-level tools is a reasonable, well-scoped surface for this server. However, 'packetsniffer_ops' is an over-consolidated mega-tool packing roughly 14 distinct operations, which pushes complexity into a single tool rather than the count itself.

Completeness4/5

The ops tool covers the sniffing lifecycle well: interface discovery, blocking/background capture, capture status, stop, PCAP decode and analysis, plus USB and Bluetooth payload extraction and diffing. Minor gaps remain (no live stream display, packet injection, or filter validation), but core workflows are covered.

Maintenance

ActivityMaintained
ResponsivenessNo issues