SkillLow riskUnclaimed
AKS Network Capture
Collects bounded packet captures from AKS nodes and Azure network configuration for wire-level evidence. WHEN: "capture packets on an AKS node", "take a pcap", "run tcpdump on AKS", "prove where packets drop". Use for explicit packet-capture intent after read-only diagnostics, not general AKS connectivity or ingress troubleshooting.
microsoftmicrosoft/aks-network-capture
Description
Quick Reference
| Use | Requires | Safety |
|---|---|---|
| AKS pcap evidence | kubectl; az for Azure evidence |
Bounded, pinned, least privilege |
When to Use This Skill
Use for explicit packet capture after read-only checks, not generic connectivity failures.
MCP Tools
Azure MCP's AKS area provides cluster and node-pool metadata, not Kubernetes command execution or packet capture.
Host Capability Gate
Before executing the workflow, confirm that the host permits the required
Bash or PowerShell execution, kubectl access to the bound cluster, az for
Azure evidence, access to the bundled scripts, and an approved artifact
destination. A governed Azure CLI tool alone does not establish that shell,
Kubernetes commands, or artifact operations are supported.
If a required capability is unavailable or prohibited, state that capture
execution is unavailable in this host. Analyze supplied, appropriately
redacted evidence or give the operator a target-bound collection/capture plan;
do not claim to have run it. Never route kubectl through Azure MCP, add an
unapproved execution path, or bypass host policy. Host support does not replace
the mutation and sensitive-data approvals below.
Run bundled scripts from the skill root only after this gate is satisfied.
Workflow/Steps
- Check host capabilities, then complete authorization and target binding. Capture intent is not mutation consent. Stop for separate approval before any debug-container fallback.
- Install Bash / PowerShell.
- Capture nodes or pods with Bash / PowerShell.
- Generate traffic if approved with Bash / PowerShell.
- Retrieve the exact run with Bash / PowerShell.
- Gather Azure evidence with Bash / PowerShell.
The ConfigMap runs run-capture.sh inside its pinned Linux image.
Error Handling
| Error | Action |
|---|---|
| Invalid input | Correct it before retrying. |
| Missing/stale ConfigMap | Run setup again. |
| Capture/retrieval failure | Inspect Job logs; missing evidence is not success. |
Permissions
powershellshellkubernetes.iolearn.microsoft.comRUN_TOKENChecks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
4 minor marks: common commands and the like, noted but not a concern
- Rule · command_injection
scripts/collect-azure-network-info.sh:145 - Rule · command_injection
scripts/retrieve-captures.ps1:227 - Rule · command_injection
scripts/retrieve-captures.sh:243 - Rule · command_injection
scripts/run-capture.sh:88
Files13 files · 77.4 KB
- SKILL.md2.9 KB
references/1
- capture-authorization.md1.4 KB
scripts/11
- collect-azure-network-info.ps17.9 KB
- collect-azure-network-info.shx7.0 KB
- create-capture.ps111.5 KB
- create-capture.shx12.4 KB
- generate-test-traffic.ps15.4 KB
- generate-test-traffic.shx6.1 KB
- retrieve-captures.ps19.4 KB
- retrieve-captures.shx8.1 KB
- run-capture.shx2.4 KB
- setup-capture-configmap.ps11.7 KB
- setup-capture-configmap.shx1.2 KB
Versions
- #11.0.1latestOct 10, 2026