NetClaw: AI Network Engineering Agent with 233 Skills and Multi-Channel Access
An AI agent that claws through your network
At a glance
- What is it?
- NetClaw is an AI network engineering coworker built on the OpenClaw framework, combining 233 skills and 173 MCP integrations for live network investigation, RAG-grounded documentation queries, and device changes with audit trails. It runs locally on macOS, Linux, and Windows via WSL2, and reaches operators through chat, a visual HUD, mobile, or a Zoom call.
- Who is it for?
- NetClaw is the right tool for network engineers who want an AI coworker that can query live devices, search internal documentation, and carry out approved changes through a single interface on macOS or Linux. The install is interactive and profiles let you start with a curated subset rather than every component.
- Can I use it commercially?
- Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What NetClaw Is and Who It Is For
NetClaw is a CCIE-level AI network engineering agent built on OpenClaw, a self-hosted personal-assistant gateway. The README describes its primary audience as network engineers and operations teams who need to investigate live networks, consult internal documentation, coordinate specialist agents, and carry out approved device changes. It is not a monitoring dashboard or a replacement for a network management system; it is an interactive agent that you ask questions and give tasks, in plain language.
The scope is wide. The 233 skills cover network investigation, topology diagrams, vulnerability audits, RFC-compliant configuration generation, and multi-vendor device management. The 173 MCP integrations connect the agent to external systems such as NetBox, ServiceNow, Cisco pyATS, Grafana, Prometheus, and cloud providers including AWS, Azure, and GCP. The README's example prompt for a topology diagram is a concrete illustration: ask the agent to diagram the OSPF topology, and it produces a mindmap or diagram from live device state, not a manually maintained document.
Installing NetClaw with the Interactive Installer
The install is a single clone and script run:
git clone https://github.com/automateyournetwork/netclaw.git
cd netclaw
./scripts/install.shThe README is explicit that the script must run as the normal user, not with sudo. Under sudo, OpenClaw's configuration, API keys, and skills land in `/root/.openclaw` where the user's own `openclaw` process cannot find them. The installer refuses to run under sudo and instead prompts for each specific command that needs root.
The installer opens an interactive TUI that asks for an install profile and then an optional checklist of specific MCP servers to include (Space to toggle, `a` to select all, `n` to clear). The available profiles are: Recommended (a curated starter set including pyATS, NetBox, ServiceNow, GAIT audit trail, Chrome DevTools, nmap, diagrams, and utilities), Custom, Everything, and vendor-specific profiles: Cisco, Multivendor (Cisco plus Juniper, Arista, Aruba, F5, NetBox, Nautobot), Cloud (AWS, Azure, GCP, Cloudflare, Terraform, Vault, GitHub), Security (ISE, FMC, Panorama, FortiManager, Check Point, Zscaler, Claroty, nmap, CVE), Labs (CML, ContainerLab, Batfish, SuzieQ), and Observability (Grafana, Prometheus, Datadog).
Device credentials for pyATS go in the .env file. The .env.example shows:
NETCLAW_USERNAME=admin
NETCLAW_PASSWORD=changeme
NETCLAW_ENABLE_PASSWORD=changemeAn Anthropic API key is required if you are not using Claude Code CLI authentication. The .env.example also shows a token pricing override for cost control.
RAG: Grounding Answers in Your Own Documentation
NetClaw includes a built-in RAG system for answering questions from your own vendor guides, standards documents, customer designs, and runbooks. Documents can be uploaded through Slack, the HUD Knowledge panel, ingested as local files, or previewed as a URL crawl before import. Supported formats include PDF, Markdown, HTML, text, and modern Office formats; legacy Office conversion uses optional LibreOffice.
The retrieval pipeline uses hybrid semantic and keyword search with local reranking and structure-aware chunking. Answers come back with cited passages that include document name, section, and page context. Retrieval runs locally once the models are installed, with no external search dependency.
The README gives a worked example: ask 'Using our uploaded design guide, explain the intended BGP policy and cite the relevant sections,' then follow up with a live device check to compare documented intent against current state. This two-step pattern, documented intent compared to live reality, is one of the most common tasks the tool is designed for.
Uploaded knowledge is stored separately from the agent's experiential memory. Captured network snapshots are opt-in and carry their age, so stale snapshots do not mislead the agent about current state.
GCF, Mobile, Zoom, and the HUD
NetClaw adds several interface and efficiency layers on top of the core agent.
GCF (compact network evidence) is a serialization format for structured tool results. It uses tabular encoding for repeated records and graph encoding for topology, reducing the token count of network evidence payloads. The README cites a recorded benchmark: a 1,000-node fixture produced 98,859 characters with graph encoding versus 139,881 characters with compact JSON. The mode is set with NETCLAW_GCF_MODE in the environment (full, graph, generic, or off). The README notes that the characters-per-4 token estimate is not a guaranteed billing reduction.
The mobile client (Flutter, iOS and Android) connects to the Border gateway over a single-use QR enrollment token. From the phone, operators can ask questions by text or voice, receive answers with the responding claw identified, and resolve approval requests using device biometrics. Camera and microphone captures can be attached to an investigation.
Zoom integration uses Realtime Media Streams: with listening enabled, transcript and chat context from a live incident call can trigger network investigations through the existing Border and specialist routing. The Zoom App side panel shows status and evidence during the meeting.
The HUD now runs on loopback only. The README notes that remote users should use the SSH-tunnel migration helper and access guide documented in docs/HUD-ACCESS.md. Full NetClaw hosts are macOS, Linux, and Windows through WSL2.
Safety, Audit Trail, and Change Approval
Device writes in NetClaw go through an approval gate rather than executing immediately. The README describes baselines, verification, and an immutable audit trail as standard parts of the change workflow. The mobile client's approval view and biometric confirmation extend that gate to the phone.
The GAIT audit trail component is listed in the Recommended install profile, suggesting it is considered part of the baseline setup rather than an optional extra. The DefenseClawMCPScan.md and DefenseClawSkillScan.md files in the repository root suggest a security scanning skill also exists.
The HUD loopback restriction added in this version closes a previous exposure where the credential, configuration, and chat endpoints were reachable from the network. The README instructs existing remote users to migrate to the SSH tunnel before upgrading.
Limitations and What NetClaw Is Not
NetClaw requires a Claude-compatible LLM: either an Anthropic API key or Claude Code CLI authentication. It is not model-agnostic in the way that some lighter automation frameworks are. The .env.example shows an ANTHROPIC_API_KEY slot and a token pricing override, confirming that inference costs accumulate with use.
The pyATS testbed YAML must describe your actual devices before live queries will work. The README does not document how to build or validate a testbed YAML. A network team new to pyATS faces that learning curve before NetClaw can reach production devices.
The 233 skills and 173 MCP integrations make NetClaw a large installation. The Everything profile installs all components, but the Recommended profile exists precisely because not every team needs Juniper, F5, Panorama, FortiManager, and ContainerLab on day one. Teams with a narrower vendor scope should use the appropriate vendor profile or Custom mode to avoid installing components that will never be used.
The alternative is a lighter combination of standalone tools: pyATS or Netmiko for device interaction, Ansible for change execution, and a separate vector search system for documentation. That path trades the unified AI interface for lower complexity and a broader selection of models.
Maintenance and License
The last push to the repository was on 2026-09-06. The Apache-2.0 license permits commercial use, modification, and redistribution. The repository includes example files for six standard workflows (health check, vulnerability audit, topology diagram, OSPF mindmap, RFC-compliant configuration, and full audit), giving a team concrete starting points for the most common network engineering tasks.
Editorial conclusion
NetClaw is the right tool for network engineers who want an AI coworker that can query live devices, search internal documentation, and carry out approved changes through a single interface on macOS or Linux. The install is interactive and profiles let you start with a curated subset rather than every component. The project requires an Anthropic API key or Claude Code CLI auth, and the pyATS testbed YAML must match your actual device inventory before any live queries will work. Teams that want only basic network automation scripts without an AI agent layer are better served by standalone pyATS or Ansible.
Frequently asked questions
What is NetClaw?
NetClaw is an AI network engineering agent built on the OpenClaw framework. It ships with 233 skills and 173 MCP integrations for querying live networks, searching internal documentation, and carrying out approved device changes with an audit trail. It runs locally on macOS, Linux, and Windows via WSL2.
What is the difference between NetClaw and OpenClaw?
OpenClaw is the underlying self-hosted personal-assistant gateway framework that NetClaw is built on. NetClaw is a specialized deployment of OpenClaw focused on network engineering, adding 233 network-specific skills and 173 MCP integrations for vendors such as Cisco, Juniper, Arista, and cloud providers.
Which AI tool is best for networking?
The README positions NetClaw as a CCIE-level coworker for network investigation and change management, built specifically for network operations teams. It integrates with pyATS, NetBox, ServiceNow, and multi-vendor device APIs. Teams that want a narrower automation scope without an AI agent layer may find standalone pyATS or Ansible a simpler fit.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/automateyournetwork-netclaw)