network-diagnostics

v2026.09.24

Network connectivity and latency diagnostics. Use when tracing routes, comparing ping latency across endpoints, or inspecting local socket/port usage.

GitHub
Install command
npx skhub add laurigates/network-diagnostics
Markdown
SKILL.md

Network Diagnostics

When to Use This Skill

ScenarioUse this skillAlternative
Trace the route to a remote hostYes (trippy)
Diagnose packet loss or high latency on a pathYes (trippy)
Compare ping latency across multiple endpointsYes (gping)
Find what process is listening on a portYes (ss)
Count established connections to a serviceYes (ss)
Inspect local socket states (TIME_WAIT, etc.)Yes (ss)
Scan all open ports on a remote hostnetwork-discovery (RustScan, nmap)
Look up DNS records or check propagationdns-tools (dog, dig)
Enumerate hosts on the local L2 segmentlayer2-discovery (ARP/LLDP)
Inspect or configure the host's own IPs, links, or routesinterface-state (ip)
Benchmark HTTP endpoint throughputhttp-load-testing (oha)
See real-time per-process bandwidth consumptionnetwork-monitoring (bandwhich)

Expert knowledge for network connectivity troubleshooting using modern diagnostic tools that provide richer output than legacy alternatives.

Core Expertise

Tool Selection

Use CaseToolWhy
Path analysis with latencytrippyCombines traceroute + ping with TUI
Multi-host latency comparisongpingVisual graphs, parallel pings
Local socket inspectionssModern netstat replacement
Quick single-hop latencygpingFaster feedback than trippy
Network path + ASN infotrippyBuilt-in ASN/geo lookups

Advantages Over Legacy Tools

ModernLegacyImprovements
trippytraceroute, mtrTUI, jitter stats, ASN/geo, world map
gpingpingVisual graphs, multi-host parallel
ssnetstatFaster, more info, better filtering

Trippy - Modern Traceroute/MTR

Rust-based network path analyzer combining traceroute and ping with a rich TUI.

Essential Commands

# Basic traceroute with TUI
trip example.com

# Specify protocol mode
trip -m icmp example.com    # ICMP (default, needs root/caps)
trip -m udp example.com     # UDP (no root needed)
trip -m tcp example.com     # TCP

# TCP to specific port
trip -m tcp -p 443 example.com
trip -m tcp -p 80 example.com

# Specify source interface
trip -i en0 example.com
trip -i eth0 example.com

# Enable ASN lookups in TUI
trip --tui-as-mode asn example.com
trip --tui-as-mode prefix example.com

# Geo-location in TUI
trip --tui-geoip-mode short example.com
trip --tui-geoip-mode long example.com

Non-Interactive Output

# JSON output for parsing
trip example.com --mode json -c 10

# Dot format (Graphviz)
trip example.com --mode dot -c 10

# CSV format
trip example.com --mode csv -c 10

# Flows (path changes)
trip example.com --mode flows -c 10

# Silent mode (summary only)
trip example.com --mode silent -c 10

# Pretty print (no TUI)
trip example.com --mode pretty -c 10

Advanced Options

# Set packet count
trip example.com -c 100

# Set max TTL (hops)
trip example.com -t 30

# Set packet size
trip example.com -S 64

# First TTL to start from
trip example.com -f 5

# Parallel probes per hop
trip example.com -N 16

# Grace period after target reached
trip example.com -g 100ms

gping - Graphical Ping

Visual latency graphs with multi-host parallel ping support.

Essential Commands

# Basic ping with graph
gping example.com

# Multiple hosts (parallel comparison)
gping google.com cloudflare.com amazon.com

# Force IPv4/IPv6
gping -4 example.com
gping -6 example.com

# Specify interface
gping -i en0 example.com

# Simple graphics (ASCII, for terminals without unicode)
gping -s example.com

# Set buffer size (number of pings to display)
gping -b 100 example.com

Command Execution Mode

# Ping a command's execution time instead of host
gping --cmd "curl -s https://api.example.com/health"
gping --cmd "dig example.com"
gping --cmd "http https://api.example.com/status"

# Compare multiple commands
gping --cmd "curl -s localhost:3000" --cmd "curl -s localhost:8080"

Customization

# Set ping interval (seconds)
gping -n 0.5 example.com

# Watch specific timeout
gping -w 2 example.com

# Clear screen before starting
gping --clear example.com

ss - Socket Statistics

Modern replacement for netstat, faster and more informative.

Essential Commands

# All TCP connections
ss -t

# All UDP sockets
ss -u

# Listening sockets only
ss -l

# Show process info (requires root for other users' processes)
ss -p

# Numeric output (no DNS resolution)
ss -n

# Combined: listening TCP with process info, numeric
ss -tlnp

# Combined: all TCP/UDP listening sockets with processes
ss -tulnp

Filtering

# Filter by state
ss -t state established
ss -t state listening
ss -t state time-wait
ss -t state close-wait

# Filter by port
ss -t sport = :22
ss -t dport = :443
ss -t 'sport = :80 or dport = :80'

# Filter by address
ss -t src 192.168.1.0/24
ss -t dst 10.0.0.1

# Combined filters
ss -t 'sport = :443 and dst 10.0.0.0/8'

Statistics and Summary

# Socket summary statistics
ss -s

# Extended info (memory, congestion)
ss -e

# Timer info (retransmits, keepalives)
ss -o

# Memory usage
ss -m

# Full detail
ss -i

Common Investigations

# Find what's using a port
ss -tlnp | grep :8080
ss -tlnp 'sport = :8080'

# Count connections by state
ss -t state established | wc -l

# Find connections to specific host
ss -tn dst 192.168.1.100

# Monitor established connections to a service
watch -n 1 'ss -tn state established dport = :443 | wc -l'

Common Patterns

Connectivity Troubleshooting Workflow

# Step 1: Check if host responds
gping target.example.com

# Step 2: Analyze network path
trip target.example.com

# Step 3: Check local listening services
ss -tlnp

# Step 4: Verify outbound connectivity
ss -tn state established | grep target.example.com

Latency Comparison

# Compare multiple endpoints
gping primary.example.com secondary.example.com backup.example.com

# Compare DNS providers
gping 8.8.8.8 1.1.1.1 9.9.9.9

# Compare API endpoints
gping --cmd "curl -s api1.example.com" --cmd "curl -s api2.example.com"

Port Availability Check

# What's listening on common ports
ss -tlnp 'sport = :80 or sport = :443 or sport = :8080 or sport = :3000'

# Find all listening ports in a range
ss -tlnp 'sport >= :8000 and sport <= :9000'

Network Path Analysis

# Compare paths to different regions
trip us-east.example.com &
trip eu-west.example.com &
trip ap-southeast.example.com

# Analyze with ASN information
trip --tui-as-mode asn cdn.example.com

Agentic Optimizations

ContextCommand
Quick latency checkgping -b 10 HOST 2>&1 | head -20
Path analysis (JSON)trip HOST --mode json -c 5
Listening portsss -tlnp
Connection countss -tn state established | wc -l
Port in usess -tlnp 'sport = :PORT'
Multi-host comparegping HOST1 HOST2 HOST3 -b 5
TCP path checktrip -m tcp -p 443 HOST --mode pretty -c 3

Quick Reference

Trippy Flags

FlagLongDescription
-m--modeProtocol: icmp, udp, tcp
-p--portTarget port (tcp/udp mode)
-i--interfaceSource interface
-c--countNumber of probes
-t--max-ttlMaximum TTL/hops
-f--first-ttlStarting TTL
-S--packet-sizePacket size in bytes
--tui-as-modeASN display: asn, prefix
--tui-geoip-modeGeo display: short, long
--modeOutput: tui, json, csv, dot, flows, silent, pretty

gping Flags

FlagLongDescription
-4Force IPv4
-6Force IPv6
-i--interfaceSource interface
-s--simple-graphicsASCII-only output
-b--bufferNumber of pings to display
-n--intervalPing interval (seconds)
-w--watch-intervalWatch timeout
--cmdPing command execution time
--clearClear screen before starting

ss Flags

FlagDescription
-tTCP sockets
-uUDP sockets
-lListening only
-aAll sockets
-pShow process
-nNumeric (no DNS)
-eExtended info
-oTimer info
-mMemory usage
-iInternal TCP info
-sSummary statistics

ss State Filters

StateDescription
establishedActive connections
listeningListening sockets
time-waitWaiting for timeout
close-waitWaiting for local close
syn-sentConnection initiating
syn-recvConnection received

Installation

# macOS
brew install trippy gping

# ss is part of iproute2 on Linux (usually pre-installed)
# On macOS, use netstat instead (ss not available)

# Cargo (cross-platform)
cargo install trippy
cargo install gping

# Verify installations
trip --version
gping --version
ss --version  # Linux only

Platform Notes

  • trippy: ICMP mode requires root or CAP_NET_RAW capability; UDP/TCP modes work without elevation
  • gping: Works without elevation on all platforms
  • ss: Linux only; use netstat -an on macOS for similar functionality

Resources

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

networking-plugin/skills/network-diagnostics

Default branch

main

Latest commit

1668324

Tree SHA

b2d4cc3