skywatch-scanning-the-network

Coordinate parallel subagents to scan network traffic and ClickHouse data for threats.

6|Updated Feb 21, 2026
One-click install
npx skills add https://github.com/skywatch-bsky/skywatch-agent-skills --skill skywatch-scanning-the-network
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skywatch-scanning-the-network
Source: https://github.com/skywatch-bsky/skywatch-agent-skills/tree/main/polytoken/skills/skywatch-scanning-the-network
Command: npx skills add https://github.com/skywatch-bsky/skywatch-agent-skills --skill skywatch-scanning-the-network

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the difficulty of identifying emerging threats and coordinated malicious activity across large-scale network data by automating complex, multi-faceted investigative workflows.

Core Features & Use Cases

  • Parallel Investigation: Simultaneously executes baseline traffic analysis, rule-hit monitoring, and co-sharing/entropy detection.
  • Consolidated Reporting: Synthesizes disparate data signals into a single, BLIND-style emerging-threat report with actionable recommendations.
  • Use Case: Use this when you suspect an uptick in anomalous network traffic or coordinated bot behavior and need a comprehensive, evidence-backed assessment of the threat landscape.

Quick Start

Use the skywatch-scanning-the-network skill to perform a network scan for the past 7 days with hourly granularity.

Frequently Asked Questions about skywatch-scanning-the-network

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform proactive network-wide threat scanning using ClickHouse data?

Network-wide threat scanning is performed by coordinating parallel investigative subagents to analyze traffic, rule hits, and coordinated behavior, synthesizing ClickHouse data and entropy metrics into an emerging-threat report.

What is the best way to detect coordinated bot behavior across large-scale network traffic?

Detecting coordinated bot behavior requires running parallel baseline traffic analysis, rule-hit monitoring, and co-sharing or entropy detection to synthesize disparate data signals into an actionable threat assessment.

Can I use this approach for incident response and threat hunting scenarios?

Incident response and threat hunting scenarios are fully supported, utilizing read-only access to data-analysis subagents and specific ClickHouse execution protocols to ensure safe, non-destructive querying during investigations.

Does network threat scanning require special permissions to query ClickHouse?

Querying ClickHouse requires read-only access to specific data-analysis subagents and strict execution protocols to ensure safe, non-destructive investigative workflows during threat hunting operations.

How do I generate a consolidated emerging-threat report from anomalous network traffic?

Generating a consolidated emerging-threat report involves synthesizing disparate network data signals from parallel investigations into a single, evidence-backed assessment with actionable recommendations for anomalous traffic.

When should I use parallel investigative subagents for network analysis?

Parallel investigative subagents should be used when you suspect an uptick in anomalous network traffic or coordinated bot behavior and need a comprehensive, multi-faceted assessment of the threat landscape.