Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Query Cisco Catalyst Center read-only — device inventory, site hierarchy, wireless, assurance health, compliance, software images, events. All 514 read-only API operations reachable through 8 grouped dispatchers. Use when asked what Catalyst Center manages, where a device sits, what its health or compliance state is, or to reconcile controller state against the devices themselves.
.claude/skills/automateyournetwork-catalyst-center-readonly/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-15 | ✗→✓ | ▲ Improved | 55% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 8% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 21% | 0% |
| case-13 | ✗→✓ | ▲ Improved | -25% | 0% |
| case-14 | ✗→✓ | ▲ Improved | -26% | 0% |
catc-mcp — a NetClaw client over Cisco's official tool catalogue (cisco-en-programmability/catc-mcp-oss, Apache-2.0, release/2.3.7.11). Strictly read-only: all 514 GET operations, the one mutating operation excluded. Manifest 1,821 tokens, where inlining every upstream tool would cost 64,420.
Start with discovery — the catalogue is far too large to carry in the tool list:
| Tool | Use | |---|---| | catc_find(query, group, limit) | Search all 514 operations by keyword or URI. Start here | | catc_describe_operation(name) | Full parameter schema for one operation |
Then dispatch — catc_<group>(operation, params):
catc_devices · catc_sites · catc_wireless · catc_health · catc_compliance · catc_software · catc_events · catc_other
Operation names are not guessable. They are generated from Cisco's API spec — the device list is api_getSites-style naming, not getDeviceList. Always catc_find first. Guessing wastes a call and gets a refusal that names near-matches.
Zero devices means this controller manages none. It does not mean the network is empty. The causes are different and matter:
| Cause | What it means | |---|---| | Discovery has not run | devices exist, Catalyst Center has not found them | | RBAC scopes the account | the estate is larger than this account can see | | The wrong appliance | you are asking a controller that manages nothing | | A filter excluded everything | your parameters, not the network | | Genuinely nothing onboarded | the only case that is about the estate |
This is not hypothetical. The two DevNet sandboxes share credentials and are not equivalent — sandboxdnac.cisco.com has 4 devices and 25 sites; sandboxdnac2.cisco.com has 0 devices and authenticates perfectly. An inventory answer from the second looks exactly like a real empty estate.
That is why every response names the appliance it came from, and why an empty result or a zero count carries an explicit caveat. Repeat the appliance name when you report a count, especially a zero.
reachabilityStatus is the controller's last polling result, not ground truth. A device shown Unreachable may be perfectly healthy and merely unreachable from the controller — a management-VRF problem, an ACL, a dead SNMP/NETCONF agent on an otherwise forwarding switch.
Catalyst Center is a database of what it last learned. A device can be listed and long dead, or absent and carrying traffic. Say when it was observed, and if the answer matters, confirm against the device with pyats or multivendor-cli.
| outcome | Means | |---|---| | ok | records returned | | empty | this controller returned nothing — see rule 1, never report as a network fact | | unreachable | the appliance could not be reached. Not an empty result | | auth_failed | credentials rejected or token expired. State is unknown, not empty | | forbidden | RBAC denied it — and a related answer you did get may be scoped, not complete | | not_configured | no appliance is configured at all | | refused | unknown operation, or a missing path parameter |
unreachable, auth_failed and empty are three different facts. Never collapse them.
| Want to… | Use | |---|---| | Read the device itself | pyats, multivendor-cli — when they disagree with the controller, the device is right | | Intended state | netbox, nautobot — this is discovered state. A device here and not in NetBox is a reconciliation finding, not an error | | Search Cisco documentation | devnet-catalyst-search — that reads docs; this queries an appliance | | Wireless client experience over time | thousandeyes, prometheus | | Change anything | nothing here. Read-only; no mutation is reachable |
catc_find before dispatching. Operation names are generated, not guessable.forbidden on one call means other answers may be scoped. Say so.| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-15 | fail→pass | 10,234 | 9,292 | -9% | 1 | 1 | 0% | 1,610 | 2,497 | +55% | 0 | 0 | — |
case-01 | fail→fail | 19,510 | 15,042 | -23% | 1 | 1 | 0% | 2,974 | 1,418 | -52% | 0 | 0 | — |
case-02 | fail→fail | 13,847 | 14,912 | +8% | 1 | 1 | 0% | 449 | 1,468 | +227% | 0 | 0 | — |
case-03 | fail→fail | 16,983 | 10,833 | -36% | 1 | 1 | 0% | 3,320 | 1,514 | -54% | 0 | 0 | — |
case-04 | fail→pass | 15,452 | 11,726 | -24% | 1 | 1 | 0% | 2,013 | 2,169 | +8% | 0 | 0 | — |
case-05 | pass→fail | 14,100 | 15,170 | +8% | 1 | 1 | 0% | 1,291 | 2,880 | +123% | 0 | 0 | — |
case-06 | pass→pass | 13,896 | 7,115 | -49% | 1 | 1 | 0% | 1,548 | 2,274 | +47% | 0 | 0 | — |
case-07 | fail→pass | 12,664 | 12,467 | -2% | 1 | 1 | 0% | 1,950 | 2,351 | +21% | 0 | 0 | — |
case-08 | pass→pass | 18,396 | 5,259 | -71% | 1 | 1 | 0% | 1,789 | 2,036 | +14% | 0 | 0 | — |
case-09 | fail→fail | 20,999 | 10,533 | -50% | 1 | 1 | 0% | 2,999 | 1,451 | -52% | 0 | 0 | — |
case-10 | pass→pass | 13,961 | 5,745 | -59% | 1 | 1 | 0% | 1,889 | 1,969 | +4% | 0 | 0 | — |
case-11 | pass→pass | 20,465 | 10,104 | -51% | 1 | 1 | 0% | 2,333 | 1,968 | -16% | 0 | 0 | — |
case-12 | pass→fail | 12,208 | 10,013 | -18% | 1 | 1 | 0% | 1,861 | 1,395 | -25% | 0 | 0 | — |
case-13 | fail→pass | 14,648 | 7,331 | -50% | 1 | 1 | 0% | 2,338 | 1,744 | -25% | 0 | 0 | — |
case-14 | fail→pass | 15,570 | 6,033 | -61% | 1 | 1 | 0% | 2,749 | 2,030 | -26% | 0 | 0 | — |
case-16 | pass→pass | 10,507 | 5,198 | -51% | 1 | 1 | 0% | 1,350 | 2,078 | +54% | 0 | 0 | — |
case-17 | pass→pass | 10,896 | 3,029 | -72% | 1 | 1 | 0% | 1,909 | 1,638 | -14% | 0 | 0 | — |
case-18 | fail→pass | 13,289 | 8,290 | -38% | 1 | 1 | 0% | 1,798 | 2,300 | +28% | 0 | 0 | — |
case-19 | fail→pass | 11,645 | 3,029 | -74% | 1 | 1 | 0% | 1,781 | 1,666 | -6% | 0 | 0 | — |
case-20 | pass→fail | 10,600 | 7,640 | -28% | 1 | 1 | 0% | 1,579 | 1,612 | +2% | 0 | 0 | — |
case-21 | pass→pass | 11,587 | 11,470 | -1% | 1 | 1 | 0% | 1,616 | 2,304 | +43% | 0 | 0 | — |
case-22 | pass→fail | 18,303 | 7,690 | -58% | 1 | 1 | 0% | 2,593 | 1,564 | -40% | 0 | 0 | — |
case-23 | fail→fail | 20,644 | 10,129 | -51% | 1 | 1 | 0% | 3,318 | 1,400 | -58% | 0 | 0 | — |
case-24 | pass→fail | 18,468 | 9,219 | -50% | 1 | 1 | 0% | 3,692 | 1,641 | -56% | 0 | 0 | — |
case-25 | pass→pass | 26,741 | 22,631 | -15% | 1 | 1 | 0% | 4,097 | 5,024 | +23% | 0 | 0 | — |
case-26 | pass→pass | 11,908 | 12,290 | +3% | 1 | 1 | 0% | 2,338 | 3,007 | +29% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 26 cases were attempted, and 17 counted toward the lift figure. The other 9 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +8 percentage points is the difference between those two pass rates over the 17 comparable cases. 6 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.