← Docs

MCP Reference

pcapai-mcp · 98 tools over JSON-RPC on stdio

Generated from the shipped binaries — not written by hand.

Shipped on all three platforms from 1.0.24 (4b273161e). JSON-RPC over stdio. The four lifecycle tools (open_file, get_file_info, get_analysis_bundle, get_packet_list) are MCP-only; the rest are get_tool_definitions() minus MCP_EXCLUDED_TOOLS — the SSH job-launch tools are never advertised, and planner_edit is excluded, so the planner is read-only over MCP. Read-only is the tool's own annotations.readOnlyHint, not an editorial judgement. ---

ToolRead-onlyWhat it does
access_point_clientsyesGet the clients associated with a PHYSICAL access point.
analyze_block_ack_healthyesAnalyze Block Ack (BA) session health from the capture.
analyze_handshakesyesAnalyze WiFi 4-way handshakes: completion, timing, failures, PMKID.
analyze_qos_flowsyesAnalyze SCS/MSCS QoS flow health from the capture.
analyze_twt_healthyesAnalyze TWT (Target Wake Time) session health from the capture.
analyze_wifi_securityyesAnalyze WiFi security threats: deauth attacks, rogue APs, weak encryption, evil twins.
api_apply_mappingnoApply a proposed mapping (from api_propose_mapping), writing its mapped data into the workspace as PROVISIONA…
api_describe_sandboxyesList API-sandbox items: connector responses/requests the engine could NOT fit into the canonical schema (an u…
api_get_capabilitiesyesReport one connector's capability matrix: which data types it can READ (device, interface, wlan, client, topo…
api_get_diagnosticsyesExport the redacted API-sandbox diagnostics bundle: every staged adaptation (raw redacted response + inferred…
api_list_connectorsyesList the API connectors configured in the active workspace (read-only).
api_propose_mappingnoPropose a field mapping for a sandbox staging item (from api_describe_sandbox).
apply_filternoApply a Wireshark display filter to narrow down packets for analysis.
compare_valuesyesCompare field values between groups (set operations).
correlate_fieldsyesCorrelate multiple metrics grouped by a field.
count_by_fieldyesCount packets grouped by field value (fast GROUP BY).
detect_patternsyesDetect common network patterns: high_retry_clients, channel_congestion, weak_signal_clients, auth_failures.
extract_fieldsyesExtract field values from every packet in the current scope (apply a filter first to scope it).
field_time_seriesyesGet time series data for a field (like Wireshark IO Graph).
fleet_get_deviceyesRead one fleet device by id, host/IP, or name — full enrichment, tags, notes, prompt override, and its effect…
fleet_get_run_resultsyesRead fleet run results: run summary with per-status counts plus paged per-device rows, or — when 'device' is…
fleet_list_devicesyesRead-only paged search of the fleet device inventory (the devices imported into PCAPAI's Fleet window — IPs/h…
fleet_list_runbooksyesList saved fleet runbooks (name, description, last updated).
fleet_validate_runbookyesValidate fleet runbook YAML WITHOUT running it: structural rules, Rhai expression compilation, variable refer…
geolocate_ipyesResolve up to 25 IP addresses to an approximate geographic location and ASN/owner.
get_airtime_breakdownyesPer-radio Wi-Fi airtime attribution: WHO (which stations) and WHAT (which frame types / traffic) is burning t…
get_analysis_bundleyesGet the full stable analysis bundle for the loaded capture as one JSON object: aggregate Wi-Fi health report…
get_burst_periodsyesGet detected traffic burst periods. Returns periods of unusually high traffic with start/end times, peak/aver…
get_capture_qualityyesGet capture quality assessment: FCS error rate, truncation rate, and malformed packet classification (capture…
get_client_detailyesGet detailed analysis of a specific Wi-Fi client including authentication timeline, join sessions (auth/assoc…
get_device_specsyesLook up VERIFIED specifications for a RUCKUS access point or switch from the bundled device database (datashe…
get_dns_healthyesDNS health report: capture visibility, graded checks (latency, errors, timeouts, retries, slow-resolver QoE,…
get_dns_securityyesDNS security findings sorted by severity: rogue servers, tunneling, cache poisoning, LLMNR/NBNS/WPAD poisonin…
get_dns_serversyesPer-DNS-server stats: query/response/timeout counts, latency percentiles, and classification (expected/public…
get_dns_sitesyesDNS site/domain inventory rolled up to registrable domain (eTLD+1): per-site query/answered/NXDOMAIN counts a…
get_dns_summaryyesUse FIRST for any DNS question. Capture-wide DNS totals (queries/responses/matched/timeouts/orphans/retransmi…
get_file_infoyesGet summary information about the currently loaded capture file: packet count, file path, link type, and whet…
get_mdns_servicesyesGet mDNS/Bonjour services discovered in the capture.
get_packet_listyesGet a summary list of packets showing columns: No, Time, Source, Destination, Protocol, Length, Info.
get_packet_notesyesRead the Wireshark-style notes and capture provenance persisted in the open capture: the capture-level commen…
get_passpoint_providersyes🚨 CRITICAL: Use this tool FIRST for ANY Passpoint/Hotspot 2.0 question!
get_ping_monitor_datayesRead THIS machine's desktop Ping Monitor history — the continuous reachability/latency/jitter/loss monitoring…
get_protocol_hierarchyyesGet the protocol hierarchy breakdown from pre-computed analysis.
get_protocol_treeyesGet the detailed protocol tree for a specific packet.
get_statisticsyesGet packet statistics: protocol breakdown, timeline, or conversation analysis.
get_timeline_datayesGet traffic timeline data showing packet rates over time.
get_unique_packetsyesGet unique values for a field with counts.
get_wlan_contextyesGet relationship-aware WLAN context for troubleshooting.
list_access_pointsyesList all Wi-Fi Access Points visible in the capture.
list_clientsyesList all Wi-Fi Clients visible in the capture.
netinsights_area_apsyesRead-only. Resolve a free-text AREA NAME ("the media tribune", "north concourse", "suite 12") to the set of a…
netinsights_area_vocabularyyesRead-only. List every name this workspace's OWN data uses for a place — controller policy/site/RF tags, uplin…
netinsights_diff_configsyesRead-only comparison of two NetInsights config snapshots.
netinsights_get_config_driftyesRead-only NetInsights config drift report for one device.
netinsights_get_config_historyyesRead-only paged list of NetInsights redacted config snapshots.
netinsights_get_data_qualityyesRead-only NetInsights data-quality report — WHY the inventory is incomplete.
netinsights_get_device_detailyesRead-only NetInsights device detail lookup.
netinsights_get_device_evidenceyesRead-only NetInsights evidence bundle for one device.
netinsights_get_evidence_snippetyesRead-only bounded redacted source snippet around one NetInsights parser observation.
netinsights_get_health_checksyesRead-only paged NetInsights health-check report — the findings themselves.
netinsights_get_topology_neighborhoodyesRead-only bounded topology neighborhood query around one NetInsights device.
netinsights_get_topology_pathyesRead-only resolved topology path query between two NetInsights devices.
netinsights_get_troubleshooting_briefyesRead-only evidence-backed NetInsights troubleshooting brief for one device.
netinsights_get_vlan_subnet_catalogyesRead-only paged NetInsights VLAN and subnet catalog query with canonical network derivation.
netinsights_import_assistyesHelp import TRICKY config/backup files into NetInsights.
netinsights_prepare_ai_extractionyesRead-only NetInsights AI extraction preparation.
netinsights_rf_proximityyesRead-only. Ask whether this workspace's RF-neighbour data can support a PHYSICAL PROXIMITY claim at all, and…
netinsights_search_devicesyesRead-only paged search of NetInsights current device inventory.
netinsights_search_evidenceyesRead-only paged search of NetInsights current fact evidence with source artifact provenance.
netinsights_search_servicesyesRead-only paged NetInsights service inventory query.
netinsights_search_topology_edgesyesRead-only paged search of NetInsights current topology edges.
netinsights_search_topology_evidenceyesRead-only paged search of protocol evidence attached to NetInsights topology edges.
netinsights_topology_edge_evidenceyesRead-only paged supporting/conflicting/missing protocol evidence for NetInsights topology edges.
netinsights_topology_graphyesRead-only scoped NetInsights topology graph: device nodes, placeholder nodes for unresolved neighbors, and co…
netinsights_topology_pathyesRead-only NetInsights shortest path between two devices over resolved topology edges, with optional excluded…
netinsights_triage_workspaceyesRead-only NetInsights workspace triage. Use this FIRST for broad questions like 'what is wrong', 'any problem…
netinsights_wireless_clientsyesRead-only Cisco C9800 client data from an imported show-tech: the aggregate client counts (total clients, 802…
netinsights_wlan_coverageyesRead-only Cisco C9800 WLAN coverage: which APs broadcast a given SSID, or which SSIDs and VLANs a policy tag…
netinsights_workspace_statusyesRead-only NetInsights workspace identity and size.
open_fileyesOpen a packet capture file (.pcapai, .pcap, or .pcapng).
passive_dns_lookupyesResolve an IP to its best passive-DNS name (built from this capture, no live lookups), or a hostname to the I…
planner_get_bomyesBill of materials and PoE budget analysis for the Wi-Fi Planner project: AP/switch inventory with model-match…
planner_get_calibrationyesCompare MEASURED survey RSSI against the propagation model's PREDICTION at the same positions, for one floor…
planner_get_coverageyesComputed coverage STATISTICS for one Planner floor and band: percentage of the floor at or above -65 dBm and…
planner_get_materialsyesThe Planner project's wall-material catalog: each material's name, flat attenuation in dB per crossing, dB pe…
planner_get_projectyesSummarize the open Wi-Fi Planner (RF design) project: floors (name, dimensions in meters, whether scale is se…
planner_get_rf_inputsyesRF propagation INPUTS for one floor and band: floor bounds, each client-serving AP's tx power / channel / pos…
planner_get_rf_modelsyesPer-AP report of WHICH antenna model the RF math is actually using on a band, and why.
planner_get_surveyyesSurvey walks recorded in the Planner project.
planner_list_apsyesList the access points in the Wi-Fi Planner project.
planner_match_survey_apsyesPropose which DESIGN AP each SURVEYED (measured) AP in the Planner project is, on an evidence ladder: an infr…
search_fieldsyesSearch for valid Wireshark field names. Use this to verify field names before using them in filters or extrac…
syslog_drill_templateyesDrill into a specific syslog template. Returns full template details, all matching events, and unique variabl…
syslog_get_sourcesyesGet all syslog source device summaries. Returns source IP, hostname, vendor, message/error/warning counts for…
syslog_get_templatesyesGet syslog log templates (message patterns) from the loaded syslog analysis.
syslog_get_timelineyesGet syslog event timeline grouped into time buckets.
syslog_search_eventsyesSearch syslog events (deduplicated aggregations of raw messages).
triage_captureyesPCAP-first capture triage. Use this FIRST for broad questions like 'what is wrong', 'any problems', 'summariz…