forward-skills
v0.5.36Evidence-returning network skills over Forward Networks. Needs the fwdctl binary on PATH.
By Forward NetworksLicense: Proprietary0 GitHub starsUpdated 1 hour ago
Directory evidence
- Runtimes
- Codex and Claude Code
- Parsed components
- 41 skill or MCP entries
- Source updated
- Oct 1, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install forward-skills for Codex and Claude Code
codex plugin marketplace add forwardnetworks/forward-skills
codex plugin marketplace upgrade forward-skills
codex plugin add forward-skills@forward-skillsPaste and run these commands in a terminal with Codex. They add and refresh the forward-skills catalog, then install this plugin.
Compatibility: the page URL and API slug “forward-skills” remain stable.
- Codex:
forward-skills@agent-plugin-marketplace→forward-skills@forward-skills
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/forwardnetworks/forward-skillsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The repository root is the plugin root.
Plugin files
├── .codex-plugin/plugin.json├── .claude-plugin/plugin.json├── skills/check-network-compliance/SKILL.md├── skills/compare-device-config/SKILL.md├── skills/compare-nqe-results/SKILL.md├── skills/edit-advanced-reachability/SKILL.md├── skills/edit-change-set/SKILL.md├── skills/edit-checks/SKILL.md├── skills/edit-collection/SKILL.md├── skills/edit-device-tags/SKILL.md├── skills/edit-endpoint-profile/SKILL.md├── skills/edit-internet-exclusions/SKILL.md├── skills/edit-link-overrides/SKILL.md├── skills/edit-nqe-query/SKILL.md├── skills/edit-snapshot-note/SKILL.md├── skills/edit-snapshot-reprocess/SKILL.md├── skills/edit-synthetic-query/SKILL.md├── skills/edit-wan-circuit/SKILL.md├── skills/edit-workspace/SKILL.md├── skills/find-nqe-query/SKILL.md├── skills/inspect-bgp-neighbors/SKILL.md├── skills/inspect-device-files/SKILL.md├── skills/inspect-edge/SKILL.md├── skills/inspect-environment/SKILL.md├── skills/inspect-history/SKILL.md├── skills/inspect-networks/SKILL.md├── skills/inspect-snapshots/SKILL.md├── skills/inspect-vulnerabilities/SKILL.md├── skills/investigate-collection-failure/SKILL.md├── skills/investigate-reachability/SKILL.md├── skills/plan-change-review/SKILL.md├── skills/plan-health-check/SKILL.md├── skills/plan-incident-triage/SKILL.md├── skills/plan-investigation/SKILL.md├── skills/plan-link-overrides/SKILL.md├── skills/plan-maintenance-window/SKILL.md├── skills/plan-report-skill-gap/SKILL.md├── skills/plan-segmentation-check/SKILL.md├── skills/plan-snapshot-recovery/SKILL.md├── skills/plan-synthetic-device/SKILL.md├── skills/plan-troubleshoot-connectivity/SKILL.md├── skills/plan-what-changed/SKILL.md└── skills/validate-nqe-query/SKILL.md
Included Skills41
Decides whether the network satisfies a policy using Forward's checks and NQE violation queries; view read lists existing checks. Use when asked if the network is compliant or breaks a rule.
Shows which devices' config files changed between two snapshots and the lines added or removed on one device. Use when asked what changed in a device's config or which were reconfigured.
Shows which rows a saved NQE query gains, loses or changes between two snapshots. Use when asked what changed between two snapshots for one kind of data, or to diff a query before and after.
Starts advanced reachability for a processed snapshot that never had it, showing cost first. Dry run unless apply is true. Use when internet exposure is PENDING_ADVANCED_REACHABILITY.
Builds a Predict change set from CLI commands or BGP advertisements and optionally predicts it, touching no device. Dry run unless apply is true. Use when staging or testing a change.
Creates one check on a snapshot from a definition, or deactivates one. Dry run unless apply is true. Use when asked to add a policy check, turn a query into a check, or switch one off.
Starts a collection, or stops a running one, after checking none runs and the collector is up. Dry run unless apply is true. Use when asked to collect now or cancel a collection.
Puts existing tags on devices or takes them off, after showing the pairs that change. Dry run unless apply is true. Use when asked to tag, label or group devices, or remove a tag.
Copies an SNMP endpoint profile with extra OIDs, repoints endpoints or deletes one, with before and after. Dry run unless apply is true. Use when changing what endpoints collect.
Changes the public subnets excluded from the internet node, showing before and after. Dry run unless apply is true. Use when internal public prefixes count as internet.
Adds or removes a snapshot's manual and suppressed links, showing the change. Dry run unless apply is true. Use when adding an undiscovered link, ignoring a wrong one or undoing an override.
Saves an authored NQE query to the organization's library, or removes one, showing the effect. Dry run unless apply is true. Use when a checked query should be kept for the team or dropped.
Sets a snapshot's note, such as before change X, after showing what it replaces. Dry run unless apply is true. Use when asked to label or annotate a snapshot, or record why it was taken.
Recomputes a snapshot's derived data from what it collected, showing what would start. Dry run unless apply is true. Use when a snapshot failed to process or looks stale after an upgrade.
Attaches a saved NQE query to a synthetic node so Forward generates its connections from the rows, or detaches it. Dry run unless apply is true. Use when driving a node from a query.
Manages one WAN circuit (a synthetic device for a provider's point-to-point L2 link), showing before and after. Dry run unless apply is true. Use when modelling a leased line.
Makes a temporary workspace network, adds endpoints to a workspace, or deletes one. Dry run unless apply is true. Use when trying a collection change away from the production network.
Searches the saved NQE query library for queries relevant to a question and returns ids, paths and intent. Use before writing a query from scratch, or to get a query id for a check.
Lists BGP neighbors per device and VRF with peer, remote AS, session state, prefix counts and whether the peer is modelled. Use when asked who a device peers with or who the upstream is.
Reads the raw configuration and command output collected from one device by listing files, reading a window or regex search. Use when asked what a device's actual config or show output says.
Finds where traffic leaves the network (view exits), its public interface IPs (public_addresses) and good trace sources (trace_sources). Use when asked where the internet attaches.
Reports the Forward build, organization, login, which features are on (value, default, where set) and non-default properties. Use when asked what Forward version or features are enabled.
Shows how one check's status moved across recent snapshots and where it last changed, or when a device's config last changed. Use when asked when a check started failing or a config changed.
Lists the Forward networks the login can see, with ids, names and which are workspaces. Use when the network id is not known, or to find a network's id by name before any other question.
Lists a network's snapshots, says which is the newest worth reading, which are predictions or drafts, and how complete one is. Use when choosing a before and after snapshot.
Finds which CVEs expose the network, which devices a CVE affects, or which CVEs affect a device, from Forward's detection. Use when asked about vulnerabilities, a named CVE or patching.
Finds why Forward could not collect or model devices, grouping failures by credentials, network path, device session and processing. Use when a snapshot is incomplete or devices are missing.
Explains whether traffic from a source to a destination is delivered and where it first fails, from Forward's path search. Use when asked whether A can reach B or why a flow is dropped.
Sequences read, predict, check and reach for a change. Use when asked whether a change is safe or will break anything.
Sequences the skills that answer whether the network is healthy now. Use when asked for a health check, status or morning check.
Sequences the skills that triage an outage with unknown cause. Use when asked what is wrong right now or where to start.
Maps a network question to the right skill and states what Forward cannot answer. Use at the start of any network question.
Sequences the skills that diagnose and fix missing or drifted link overrides. Use when a manual or suppressed link is missing.
Sequences before snapshot, change, after data and comparison around a window. Use when planning or closing a maintenance window or cutover.
Reports a forward-skills gap as a redacted issue. Use when a skill result was wrong or missing.
Sequences the skills that verify zone segmentation and change impact. Use when asked whether zones are isolated.
Sequences the skills that decide why a snapshot is bad and how to recover. Use when a snapshot failed or looks stale.
Sequences the skills that model an uncollected segment as a synthetic device. Use when a path dead-ends at the edge.
Sequences the skills that find why traffic does not reach a destination. Use when asked why A cannot reach B.
Sequences the skills that answer what changed and when. Use when asked what changed or when something started.
Checks that an NQE query compiles and runs against a snapshot and reports diagnostics or rows. Use after writing a query, before trusting results, or when one fails.
Plugin manifests2
{
"name": "forward-skills",
"version": "0.5.36",
"description": "Evidence-returning network skills over Forward Networks. Needs the fwdctl binary on PATH.",
"author": {
"name": "Forward Networks"
},
"homepage": "https://github.com/forwardnetworks/forward-skills",
"repository": "https://github.com/forwardnetworks/forward-skills",
"license": "Proprietary",
"keywords": [
"forward networks",
"network",
"nqe",
"reachability",
"compliance"
],
"interface": {
"displayName": "Forward Skills",
"shortDescription": "Network skills over Forward Networks",
"longDescription": "Reachability, change verification, compliance, vulnerabilities, inventory, device configs and NQE authoring over a Forward Networks digital twin. Each skill runs through the fwdctl binary and returns evidence.",
"developerName": "Forward Networks",
"category": "Engineering",
"capabilities": [
"Read",
"Write"
],
"defaultPrompt": [
"Use investigate-reachability to check whether 10.0.0.1 can reach 10.0.0.2 on tcp/443.",
"Use check-network-compliance to summarise failing checks.",
"Use author-nqe-query to write and lint an NQE query for devices with BGP neighbors that are not established."
]
},
"skills": "./skills/"
}{
"name": "forward-skills",
"description": "Evidence-returning network skills over Forward Networks. Needs the fwdctl binary on PATH.",
"version": "0.5.36",
"lspServers": "./.lsp.json"
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[forward-skills on Agent Plugins Marketplace](https://pluginsmp.com/plugins/forward-skills)