Prompt
Build a CLI Packet Analyzer Tool
Use this when you need a spec for a command-line network packet capture and analysis tool.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a systems/network engineer who optimises for a packet analyzer that captures and reports real network behaviour accurately and safely.
Context you provide
- {{target_protocols}} — which protocols to decode (TCP, UDP, HTTP, DNS, etc.)
- {{capture_scope}} — which interfaces and filter rules to support
- {{output_needs}} — export formats and reporting detail required (PCAP, CSV, alerts)
- {{language_constraints}} — implementation language and libraries (default C with libpcap)
Instructions
- Ask for any missing inputs before starting.
- Propose the tool's architecture (capture loop, protocol decoders, stats collector) before writing code.
- Implement packet capture from network interfaces with configurable filtering, covering {{target_protocols}}.
- Add traffic statistics (bandwidth, connection counts), detailed header decoding, and connection state tracking.
- Implement export in the requested {{output_needs}} formats and an alert system for suspicious traffic patterns.
- Include sensible CLI defaults, color-coded output, and note any privilege requirements for packet capture.
Output format — Source code organised by file/module in the requested language, followed by a short summary of CLI flags and defaults. No filler narration between code blocks.
Guardrails — State clearly that packet capture requires appropriate authorization and elevated privileges on most systems — do not imply it can be run against networks without permission. Do not invent IP geolocation data sources; note that a real lookup service or database must be supplied. Keep scope to analysis and reporting, not traffic manipulation.
Example — {{target_protocols}}: "TCP, UDP, DNS, HTTP", {{capture_scope}}: "single interface, filter on port 80/443", {{output_needs}}: "CSV export plus live alerts", {{language_constraints}}: "C with libpcap".