Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
67 commits
Select commit Hold shift + click to select a range
d772b92
Merge pull request #4 from iam0range/feat-windows-compatibility
bx33661 Mar 13, 2026
7222d30
fix ci and improve installer reliability
bx33661 Mar 14, 2026
f8ebd1f
Add bundled Wireshark traffic analysis skill
bx33661 Mar 14, 2026
96520d1
Expand skill discovery across AI clients
bx33661 Mar 14, 2026
87bbcfb
Release 0.6.4
bx33661 Mar 14, 2026
4f685d3
Add optional Wireshark suite tooling
bx33661 Mar 14, 2026
b639d5f
Merge pull request #5 from bx33661/codex/dev
bx33661 Mar 14, 2026
d147af6
Expand cross-platform test coverage
bx33661 Mar 14, 2026
e05c09c
Fix platform CI regressions
bx33661 Mar 14, 2026
46e8127
Add packaged CLI smoke tests
bx33661 Mar 14, 2026
a5542d5
Merge pull request #6 from bx33661/codex/dev
bx33661 Mar 15, 2026
f5f5509
feat: Add Cursor one-click installation instructions to READMEs
bx33661 Mar 16, 2026
998c9a6
Merge pull request #7 from bx33661/codex/dev
bx33661 Mar 16, 2026
c02c138
chore: prepare 0.6.5 release
bx33661 Mar 16, 2026
a15d155
Merge pull request #8 from bx33661/codex/dev
bx33661 Mar 16, 2026
54db7f7
feat: finalize 1.0 stabilization and docs
bx33661 Mar 16, 2026
1a8d3a1
style: apply ruff formatting
bx33661 Mar 16, 2026
37cd81d
docs: add v1.0.0 release announcement
bx33661 Mar 16, 2026
6ec5895
video
bx33661 Mar 16, 2026
a72f1cd
docs: add clickable demo video previews
bx33661 Mar 16, 2026
3ae8afe
docs: expand AGENTS.md with full tool surface, layout, and runtime notes
bx33661 Mar 27, 2026
c09b096
docs: add Fronteir AI hosted deployment option
ElishaKay Mar 30, 2026
7684089
Merge pull request #9 from ElishaKay/docs/add-fronteir-ai-host
bx33661 Mar 30, 2026
f41eeea
feat: add OpenCode support, interactive TUI installer, update command…
bx33661 Apr 17, 2026
75c44a3
chore: bump version to 1.1.0
bx33661 Apr 17, 2026
f587119
fix: resolve CI failures — lint errors and version/test sync for v1.1.0
bx33661 Apr 17, 2026
33fb5fd
chore: bump version to 1.1.5
bx33661 Apr 18, 2026
40bd36a
feat: concurrent agents, result cache, new protocol tools, token opti…
bx33661 May 10, 2026
2014097
docs: add documentation site with full tool coverage and i18n
bx33661 May 10, 2026
a89c7ed
docs: add v2.0 roadmap design spec
bx33661 May 12, 2026
1e0bb9c
docs: add Phase 1 (v1.3) implementation plan
bx33661 May 12, 2026
9cee775
feat(ics): add Modbus TCP protocol analysis tool
bx33661 May 12, 2026
0f6a87f
feat(ics): add S7comm and DNP3 protocol analysis tools
bx33661 May 12, 2026
42830f9
feat(iot): add Zigbee network analysis tool
bx33661 May 12, 2026
eccb99b
feat(forensics): add file carving via magic byte detection
bx33661 May 12, 2026
a579fc0
feat(forensics): add evidence chain generation tool
bx33661 May 12, 2026
3acf0e1
feat(forensics): add metadata enrichment tool for external IP/domain …
bx33661 May 12, 2026
0deae9e
chore: bump version to 1.3.0
bx33661 May 12, 2026
7954dbc
docs: add Phase 2 (v1.4) implementation plan
bx33661 May 12, 2026
40ac3e2
feat(anomaly): add beacon detection tool with jitter analysis
bx33661 May 12, 2026
e7924fe
feat(anomaly): add data exfiltration detection tool
bx33661 May 12, 2026
b97f347
feat(anomaly): add protocol anomaly detection tool
bx33661 May 12, 2026
2ec763a
feat(anomaly): add aggregate detector and register in catalog
bx33661 May 12, 2026
f546319
feat(nl): add natural language query engine with intent mapping
bx33661 May 12, 2026
9d86084
feat: register NL query tools in catalog
bx33661 May 12, 2026
157f3a1
feat(prompts): add hypothesis-driven and alert investigation prompts
bx33661 May 12, 2026
350d6e5
chore: bump version to 1.4.0
bx33661 May 12, 2026
5bde6d0
docs: complete Phase 3 (v2.0) implementation plan
bx33661 May 12, 2026
80965a0
feat(playbooks): add playbook engine with 4 bundled investigation pla…
bx33661 May 12, 2026
8d9bb7c
feat(investigator): add investigation engine with session management …
bx33661 May 12, 2026
f966e49
feat(reporter): add report generation with Markdown/JSON, IOC extract…
bx33661 May 12, 2026
5ad8120
feat(registry): wire Phase 3 modules (investigator, playbooks, reporter)
bx33661 May 12, 2026
fe5d4ad
chore: bump version to 2.0.0 with Phase 3 integration tests
bx33661 May 12, 2026
5c0cd51
docs: rewrite README — trim from 649 to 127 lines
bx33661 May 21, 2026
e32b27d
refactor(tshark): split client.py god object into focused mixins
bx33661 May 21, 2026
0689d38
feat: v2.0.0 — modular architecture, strict typing, CI hardening
bx33661 May 22, 2026
54f8419
fix(ci): apply ruff format + fix Windows encoding in YAML/JSON reads
bx33661 May 22, 2026
c30aa98
chore: remove Docker support and prune repo redundancies
bx33661 May 28, 2026
7330af8
update
bx33661 Jul 2, 2026
72c5516
fix
bx33661 Jul 2, 2026
37cd628
refactor: remove decorative tool surface, fix response contract + cac…
bx33661 Jul 26, 2026
4c2a660
fix: carve_files false positives + keep stderr out of structured data
bx33661 Jul 26, 2026
3ae1ae6
refactor: trim MCP surface and remove threat intel
bx33661 Jul 28, 2026
2bfde6c
refactor: consolidate protocol analysis and add tool profiles
bx33661 Jul 28, 2026
2a8c009
test: preserve platform environment in hash-seed check
bx33661 Jul 28, 2026
0ef9915
chore: add MCP server registry metadata
bx33661 Jul 30, 2026
378452b
chore(deps): bump actions/setup-python from 5 to 7
dependabot[bot] Aug 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 0 additions & 20 deletions .dockerignore

This file was deleted.

12 changes: 12 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# GitHub Copilot Repository Instructions

For packet capture, protocol analysis, network security monitoring, incident response, and troubleshooting tasks, prefer the project skill in `.github/skills/wireshark-traffic-analysis/`.

Use the skill to:

- start with `wireshark_open_file` and capture-wide context
- choose the correct playbook before drilling into packets
- separate observation from interpretation
- report exact filters, stream indexes, frame numbers, and confidence

Do not treat `Expert Info` or a single heuristic as proof on their own.
22 changes: 22 additions & 0 deletions .github/prompts/wireshark-traffic-analysis.prompt.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
Use the `wireshark-traffic-analysis` project skill in this repository to investigate a packet capture with a professional, evidence-backed workflow.

Inputs:

- Capture path: `${input:capture_path:Path to the pcap or pcapng file}`
- Goal: `${input:goal:triage | security | incident-response | troubleshoot}`
- Optional scope: `${input:scope:Suspicious host, protocol, time window, domain, stream, or symptom}`

Requirements:

- Start broad, then narrow.
- Use the project skill playbook that matches the goal.
- Include exact filters, streams, frames, or extracted fields for every important finding.
- Label confidence as `confirmed`, `likely`, `possible`, or `unresolved`.
- End with concrete next steps.

Relevant files:

- [Canonical skill](../../skills/wireshark-traffic-analysis/SKILL.md)
- [Playbooks](../../skills/wireshark-traffic-analysis/references/playbooks.md)
- [Evidence rubric](../../skills/wireshark-traffic-analysis/references/evidence-rubric.md)
- [Report template](../../skills/wireshark-traffic-analysis/references/report-template.md)
2 changes: 1 addition & 1 deletion .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,5 +37,5 @@

- [ ] Updated `README.md`
- [ ] Updated `README_zh.md`
- [ ] Updated `CHANGELOG.md` (under `[Unreleased]`)
- [ ] Updated release notes (if applicable)
- [ ] N/A
91 changes: 80 additions & 11 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,10 @@ name: CI

on:
push:
branches: [ "master", "main" ]
branches: [ "master", "main", "codex/**" ]
pull_request:
branches: [ "master", "main" ]
workflow_dispatch:

jobs:
lint:
Expand All @@ -13,7 +14,7 @@ jobs:
- uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@v7
with:
python-version: "3.12"

Expand All @@ -29,19 +30,26 @@ jobs:
run: ruff format --check src/ tests/

- name: Type check
run: mypy src/wireshark_mcp/ --ignore-missing-imports
run: mypy --package wireshark_mcp --ignore-missing-imports --no-namespace-packages

- name: Dependency audit
run: |
pip install pip-audit
pip-audit

test:
runs-on: ubuntu-latest
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]
python-version: ["3.10", "3.11", "3.12", "3.13"]

steps:
- uses: actions/checkout@v4

- name: Set up Python ${{ matrix.python-version }}
uses: actions/setup-python@v5
uses: actions/setup-python@v7
with:
python-version: ${{ matrix.python-version }}

Expand All @@ -50,15 +58,76 @@ jobs:
python -m pip install --upgrade pip
pip install .[dev]

- name: Run tests with coverage
run: |
pytest tests/ --cov=wireshark_mcp --cov-report=term-missing --cov-fail-under=50 -v

- name: Compile check
run: python -m compileall src/

integration-linux:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v7
with:
python-version: "3.12"

- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install .[dev]

- name: Install TShark
run: |
sudo apt-get update
sudo apt-get install -y tshark
sudo usermod -aG wireshark $USER
sudo env DEBIAN_FRONTEND=noninteractive apt-get install -y tshark
tshark -v

- name: Run tests with coverage
- name: Run Linux TShark integration smoke tests
run: |
pytest tests/ --cov=wireshark_mcp --cov-report=term-missing -v
pytest tests/test_client.py -k "real_tshark" -v

- name: Compile check
run: python -m compileall src/
package-smoke:
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-latest]

steps:
- uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v7
with:
python-version: "3.12"

- name: Install build tools
run: |
python -m pip install --upgrade pip
pip install build

- name: Build package
run: python -m build

- name: Validate packaged skill files
run: |
python -c "import glob, os, zipfile; wheel = max(glob.glob('dist/*.whl'), key=os.path.getmtime); names = set(zipfile.ZipFile(wheel).namelist()); assert any(name.endswith('wireshark_mcp/skills/wireshark-traffic-analysis/SKILL.md') for name in names), 'Skill package missing from wheel'"

- name: Install built wheel
run: |
python -c "import glob, os, subprocess, sys; wheel = max(glob.glob('dist/*.whl'), key=os.path.getmtime); subprocess.check_call([sys.executable, '-m', 'pip', 'install', '--force-reinstall', wheel])"

- name: Run packaged CLI smoke tests
run: |
wireshark-mcp --version
python -m wireshark_mcp.server --version
wireshark-mcp config
wireshark-mcp doctor
wireshark-mcp doctor --format json
wireshark-mcp clients
wireshark-mcp clients --format json
wireshark-mcp --config
36 changes: 35 additions & 1 deletion .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,13 +9,14 @@ jobs:
name: Build and publish to PyPI
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write # IMPORTANT: this permission is mandatory for trusted publishing

steps:
- uses: actions/checkout@v4

- name: Set up Python
uses: actions/setup-python@v5
uses: actions/setup-python@v7
with:
python-version: "3.10"

Expand All @@ -26,10 +27,43 @@ jobs:

- name: Build package
run: python -m build

- name: Validate built wheel contents
run: |
python -c "import glob, os, zipfile; wheel = max(glob.glob('dist/*.whl'), key=os.path.getmtime); names = set(zipfile.ZipFile(wheel).namelist()); assert any(name.endswith('wireshark_mcp/skills/wireshark-traffic-analysis/SKILL.md') for name in names), 'Skill package missing from wheel'"

- name: Install built wheel
run: |
python -c "import glob, os, subprocess, sys; wheel = max(glob.glob('dist/*.whl'), key=os.path.getmtime); subprocess.check_call([sys.executable, '-m', 'pip', 'install', '--force-reinstall', wheel])"

- name: Run release smoke tests
run: |
wireshark-mcp --version
python -m wireshark_mcp.server --version
wireshark-mcp config
wireshark-mcp doctor
wireshark-mcp doctor --format json
wireshark-mcp clients
wireshark-mcp clients --format json
wireshark-mcp --config

- name: Publish to PyPI
uses: pypa/gh-action-pypi-publish@release/v1
# Note: No username/password needed if using Trusted Publishing (OIDC).
# If using legacy token, uncomment below:
# with:
# password: ${{ secrets.PYPI_API_TOKEN }}

- name: Notify Homebrew tap to bump formula
env:
TAP_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}
# Only fire when the secret is present (forks / PRs won't have it)
if: env.TAP_TOKEN != ''
run: |
VERSION="${{ github.event.release.tag_name }}"
VERSION="${VERSION#v}" # strip leading 'v' if present
curl --fail-with-body -sS -X POST \
-H "Authorization: Bearer $TAP_TOKEN" \
-H "Accept: application/vnd.github+json" \
https://api.github.com/repos/bx33661/homebrew-wireshark-mcp/dispatches \
-d "{\"event_type\":\"new-release\",\"client_payload\":{\"version\":\"$VERSION\"}}"
24 changes: 22 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,27 @@ htmlcov/
.pytest_cache/

# Runtime caches
urlhaus_cache.txt
.mcpregistry_*
.claude/worktrees/
.codex_resume_work/

# OS metadata
.DS_Store

# Documentation site

# Spec (internal)
spec/
spec/
.omx/

# Local / duplicated docs
docs/
changelog/
AGENTS.md
GEMINI.md
CODE_OF_CONDUCT.md
CHANGELOG.md

# Auto-generated skill mirrors (canonical source lives in skills/)
.github/skills/
.claude/skills/
19 changes: 19 additions & 0 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
repos:
- repo: https://github.com/astral-sh/ruff-pre-commit
rev: v0.9.9
hooks:
- id: ruff
args: [--fix]
- id: ruff-format

- repo: https://github.com/pre-commit/mirrors-mypy
rev: v1.10.0
hooks:
- id: mypy
additional_dependencies:
- "mcp>=1.0.0"
- "pyyaml>=6.0"
- "types-PyYAML>=6.0"
args: [--strict, --ignore-missing-imports, --no-namespace-packages]
pass_filenames: false
entry: mypy --package wireshark_mcp
28 changes: 28 additions & 0 deletions .well-known/mcp/server.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.bx33661/wireshark-mcp",
"title": "Wireshark MCP",
"description": "Analyze packet captures with Wireshark and tshark through the Model Context Protocol.",
"version": "2.0.0",
"repository": {
"url": "https://github.com/bx33661/Wireshark-MCP",
"source": "github"
},
"websiteUrl": "https://github.com/bx33661/Wireshark-MCP",
"icons": [
{
"src": "https://raw.githubusercontent.com/bx33661/Wireshark-MCP/main/Logo.png",
"mimeType": "image/png"
}
],
"packages": [
{
"registryType": "pypi",
"identifier": "wireshark-mcp",
"version": "2.0.0",
"transport": {
"type": "stdio"
}
}
]
}
Loading
Loading