Shipped on all three platforms from 1.0.24 (4b273161e). JSON-RPC over stdio. The four lifecycle tools (open_file, get_file_info, get_analysis_bundle, get_packet_list) are MCP-only; the rest are get_tool_definitions() minus MCP_EXCLUDED_TOOLS — the SSH job-launch tools are never advertised, and planner_edit is excluded, so the planner is read-only over MCP. Read-only is the tool's own annotations.readOnlyHint, not an editorial judgement. ---
| Tool | Read-only | What it does |
|---|---|---|
access_point_clients | yes | Get the clients associated with a PHYSICAL access point. |
analyze_block_ack_health | yes | Analyze Block Ack (BA) session health from the capture. |
analyze_handshakes | yes | Analyze WiFi 4-way handshakes: completion, timing, failures, PMKID. |
analyze_qos_flows | yes | Analyze SCS/MSCS QoS flow health from the capture. |
analyze_twt_health | yes | Analyze TWT (Target Wake Time) session health from the capture. |
analyze_wifi_security | yes | Analyze WiFi security threats: deauth attacks, rogue APs, weak encryption, evil twins. |
api_apply_mapping | no | Apply a proposed mapping (from api_propose_mapping), writing its mapped data into the workspace as PROVISIONA… |
api_describe_sandbox | yes | List API-sandbox items: connector responses/requests the engine could NOT fit into the canonical schema (an u… |
api_get_capabilities | yes | Report one connector's capability matrix: which data types it can READ (device, interface, wlan, client, topo… |
api_get_diagnostics | yes | Export the redacted API-sandbox diagnostics bundle: every staged adaptation (raw redacted response + inferred… |
api_list_connectors | yes | List the API connectors configured in the active workspace (read-only). |
api_propose_mapping | no | Propose a field mapping for a sandbox staging item (from api_describe_sandbox). |
apply_filter | no | Apply a Wireshark display filter to narrow down packets for analysis. |
compare_values | yes | Compare field values between groups (set operations). |
correlate_fields | yes | Correlate multiple metrics grouped by a field. |
count_by_field | yes | Count packets grouped by field value (fast GROUP BY). |
detect_patterns | yes | Detect common network patterns: high_retry_clients, channel_congestion, weak_signal_clients, auth_failures. |
extract_fields | yes | Extract field values from every packet in the current scope (apply a filter first to scope it). |
field_time_series | yes | Get time series data for a field (like Wireshark IO Graph). |
fleet_get_device | yes | Read one fleet device by id, host/IP, or name — full enrichment, tags, notes, prompt override, and its effect… |
fleet_get_run_results | yes | Read fleet run results: run summary with per-status counts plus paged per-device rows, or — when 'device' is… |
fleet_list_devices | yes | Read-only paged search of the fleet device inventory (the devices imported into PCAPAI's Fleet window — IPs/h… |
fleet_list_runbooks | yes | List saved fleet runbooks (name, description, last updated). |
fleet_validate_runbook | yes | Validate fleet runbook YAML WITHOUT running it: structural rules, Rhai expression compilation, variable refer… |
geolocate_ip | yes | Resolve up to 25 IP addresses to an approximate geographic location and ASN/owner. |
get_airtime_breakdown | yes | Per-radio Wi-Fi airtime attribution: WHO (which stations) and WHAT (which frame types / traffic) is burning t… |
get_analysis_bundle | yes | Get the full stable analysis bundle for the loaded capture as one JSON object: aggregate Wi-Fi health report… |
get_burst_periods | yes | Get detected traffic burst periods. Returns periods of unusually high traffic with start/end times, peak/aver… |
get_capture_quality | yes | Get capture quality assessment: FCS error rate, truncation rate, and malformed packet classification (capture… |
get_client_detail | yes | Get detailed analysis of a specific Wi-Fi client including authentication timeline, join sessions (auth/assoc… |
get_device_specs | yes | Look up VERIFIED specifications for a RUCKUS access point or switch from the bundled device database (datashe… |
get_dns_health | yes | DNS health report: capture visibility, graded checks (latency, errors, timeouts, retries, slow-resolver QoE,… |
get_dns_security | yes | DNS security findings sorted by severity: rogue servers, tunneling, cache poisoning, LLMNR/NBNS/WPAD poisonin… |
get_dns_servers | yes | Per-DNS-server stats: query/response/timeout counts, latency percentiles, and classification (expected/public… |
get_dns_sites | yes | DNS site/domain inventory rolled up to registrable domain (eTLD+1): per-site query/answered/NXDOMAIN counts a… |
get_dns_summary | yes | Use FIRST for any DNS question. Capture-wide DNS totals (queries/responses/matched/timeouts/orphans/retransmi… |
get_file_info | yes | Get summary information about the currently loaded capture file: packet count, file path, link type, and whet… |
get_mdns_services | yes | Get mDNS/Bonjour services discovered in the capture. |
get_packet_list | yes | Get a summary list of packets showing columns: No, Time, Source, Destination, Protocol, Length, Info. |
get_packet_notes | yes | Read the Wireshark-style notes and capture provenance persisted in the open capture: the capture-level commen… |
get_passpoint_providers | yes | 🚨 CRITICAL: Use this tool FIRST for ANY Passpoint/Hotspot 2.0 question! |
get_ping_monitor_data | yes | Read THIS machine's desktop Ping Monitor history — the continuous reachability/latency/jitter/loss monitoring… |
get_protocol_hierarchy | yes | Get the protocol hierarchy breakdown from pre-computed analysis. |
get_protocol_tree | yes | Get the detailed protocol tree for a specific packet. |
get_statistics | yes | Get packet statistics: protocol breakdown, timeline, or conversation analysis. |
get_timeline_data | yes | Get traffic timeline data showing packet rates over time. |
get_unique_packets | yes | Get unique values for a field with counts. |
get_wlan_context | yes | Get relationship-aware WLAN context for troubleshooting. |
list_access_points | yes | List all Wi-Fi Access Points visible in the capture. |
list_clients | yes | List all Wi-Fi Clients visible in the capture. |
netinsights_area_aps | yes | Read-only. Resolve a free-text AREA NAME ("the media tribune", "north concourse", "suite 12") to the set of a… |
netinsights_area_vocabulary | yes | Read-only. List every name this workspace's OWN data uses for a place — controller policy/site/RF tags, uplin… |
netinsights_diff_configs | yes | Read-only comparison of two NetInsights config snapshots. |
netinsights_get_config_drift | yes | Read-only NetInsights config drift report for one device. |
netinsights_get_config_history | yes | Read-only paged list of NetInsights redacted config snapshots. |
netinsights_get_data_quality | yes | Read-only NetInsights data-quality report — WHY the inventory is incomplete. |
netinsights_get_device_detail | yes | Read-only NetInsights device detail lookup. |
netinsights_get_device_evidence | yes | Read-only NetInsights evidence bundle for one device. |
netinsights_get_evidence_snippet | yes | Read-only bounded redacted source snippet around one NetInsights parser observation. |
netinsights_get_health_checks | yes | Read-only paged NetInsights health-check report — the findings themselves. |
netinsights_get_topology_neighborhood | yes | Read-only bounded topology neighborhood query around one NetInsights device. |
netinsights_get_topology_path | yes | Read-only resolved topology path query between two NetInsights devices. |
netinsights_get_troubleshooting_brief | yes | Read-only evidence-backed NetInsights troubleshooting brief for one device. |
netinsights_get_vlan_subnet_catalog | yes | Read-only paged NetInsights VLAN and subnet catalog query with canonical network derivation. |
netinsights_import_assist | yes | Help import TRICKY config/backup files into NetInsights. |
netinsights_prepare_ai_extraction | yes | Read-only NetInsights AI extraction preparation. |
netinsights_rf_proximity | yes | Read-only. Ask whether this workspace's RF-neighbour data can support a PHYSICAL PROXIMITY claim at all, and… |
netinsights_search_devices | yes | Read-only paged search of NetInsights current device inventory. |
netinsights_search_evidence | yes | Read-only paged search of NetInsights current fact evidence with source artifact provenance. |
netinsights_search_services | yes | Read-only paged NetInsights service inventory query. |
netinsights_search_topology_edges | yes | Read-only paged search of NetInsights current topology edges. |
netinsights_search_topology_evidence | yes | Read-only paged search of protocol evidence attached to NetInsights topology edges. |
netinsights_topology_edge_evidence | yes | Read-only paged supporting/conflicting/missing protocol evidence for NetInsights topology edges. |
netinsights_topology_graph | yes | Read-only scoped NetInsights topology graph: device nodes, placeholder nodes for unresolved neighbors, and co… |
netinsights_topology_path | yes | Read-only NetInsights shortest path between two devices over resolved topology edges, with optional excluded… |
netinsights_triage_workspace | yes | Read-only NetInsights workspace triage. Use this FIRST for broad questions like 'what is wrong', 'any problem… |
netinsights_wireless_clients | yes | Read-only Cisco C9800 client data from an imported show-tech: the aggregate client counts (total clients, 802… |
netinsights_wlan_coverage | yes | Read-only Cisco C9800 WLAN coverage: which APs broadcast a given SSID, or which SSIDs and VLANs a policy tag… |
netinsights_workspace_status | yes | Read-only NetInsights workspace identity and size. |
open_file | yes | Open a packet capture file (.pcapai, .pcap, or .pcapng). |
passive_dns_lookup | yes | Resolve an IP to its best passive-DNS name (built from this capture, no live lookups), or a hostname to the I… |
planner_get_bom | yes | Bill of materials and PoE budget analysis for the Wi-Fi Planner project: AP/switch inventory with model-match… |
planner_get_calibration | yes | Compare MEASURED survey RSSI against the propagation model's PREDICTION at the same positions, for one floor… |
planner_get_coverage | yes | Computed coverage STATISTICS for one Planner floor and band: percentage of the floor at or above -65 dBm and… |
planner_get_materials | yes | The Planner project's wall-material catalog: each material's name, flat attenuation in dB per crossing, dB pe… |
planner_get_project | yes | Summarize the open Wi-Fi Planner (RF design) project: floors (name, dimensions in meters, whether scale is se… |
planner_get_rf_inputs | yes | RF propagation INPUTS for one floor and band: floor bounds, each client-serving AP's tx power / channel / pos… |
planner_get_rf_models | yes | Per-AP report of WHICH antenna model the RF math is actually using on a band, and why. |
planner_get_survey | yes | Survey walks recorded in the Planner project. |
planner_list_aps | yes | List the access points in the Wi-Fi Planner project. |
planner_match_survey_aps | yes | Propose which DESIGN AP each SURVEYED (measured) AP in the Planner project is, on an evidence ladder: an infr… |
search_fields | yes | Search for valid Wireshark field names. Use this to verify field names before using them in filters or extrac… |
syslog_drill_template | yes | Drill into a specific syslog template. Returns full template details, all matching events, and unique variabl… |
syslog_get_sources | yes | Get all syslog source device summaries. Returns source IP, hostname, vendor, message/error/warning counts for… |
syslog_get_templates | yes | Get syslog log templates (message patterns) from the loaded syslog analysis. |
syslog_get_timeline | yes | Get syslog event timeline grouped into time buckets. |
syslog_search_events | yes | Search syslog events (deduplicated aggregations of raw messages). |
triage_capture | yes | PCAP-first capture triage. Use this FIRST for broad questions like 'what is wrong', 'any problems', 'summariz… |