Cloud Audit
CommonHuman-Lab/nyxstrike
Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images
Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.
$ npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ancoleman/ai-design-components configuring-firewalls --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/configuring-firewalls .claude/skills/configuring-firewalls && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuring-firewalls" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/configuring-firewalls into .claude/skills/configuring-firewalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-firewalls", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ancoleman/ai-design-components/tree/main/skills/configuring-firewallsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ancoleman/ai-design-components configuring-firewalls --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/configuring-firewalls .agents/skills/configuring-firewalls && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuring-firewalls" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/configuring-firewalls into .agents/skills/configuring-firewalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-firewalls", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ancoleman/ai-design-components configuring-firewalls --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/configuring-firewalls .cursor/skills/configuring-firewalls && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuring-firewalls" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/configuring-firewalls into .cursor/skills/configuring-firewalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-firewalls", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ancoleman/ai-design-components.git --path skills/configuring-firewalls--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ancoleman/ai-design-components configuring-firewalls --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/configuring-firewalls .gemini/skills/configuring-firewalls && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuring-firewalls" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/configuring-firewalls into .gemini/skills/configuring-firewalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-firewalls", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ancoleman/ai-design-components configuring-firewallsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/configuring-firewalls .github/skills/configuring-firewalls && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuring-firewalls" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/configuring-firewalls into .github/skills/configuring-firewalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-firewalls", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ancoleman/ai-design-components configuring-firewalls --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/configuring-firewalls .opencode/skills/configuring-firewalls && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuring-firewalls" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/configuring-firewalls into .opencode/skills/configuring-firewalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuring-firewalls", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuring-firewallsConfigure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.
Configuring Firewalls is an agent skill from ancoleman/ai-design-components. Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. Use when exposing services, hardening servers, or implementing network segmentation with defense-in-depth strategies.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 25 other files, including reference files (for example `examples/kubernetes/default-deny-allow-dns.yaml`, `examples/ufw/basic-web-server.sh` and `outputs.yaml`).
It sits in Security, covering Cloud security and Secure coding. It works with Amazon Web Services, Google Cloud, Microsoft Azure and Kubernetes. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Shell, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
awskubectlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws and kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Configuring Firewalls loads about 3.5k tokens when it runs, and up to ~45k if it reads all its reference files. Until then it costs about 83 tokens; SKILL.md has 1,093 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo ufw default deny incomingsudo ufw default allow outgoingsudo ufw allow sshsudo ufw limit ssh # Rate-limit to prevent brute forcesudo ufw allow http # Port 80sudo ufw allow https # Port 443sudo ufw allow from 192.168.1.100 to any port 5432sudo ufw enablesudo ufw status verboseApply: `sudo nft -f /etc/nftables.conf`Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 1,093 words, ~3,468 tokens.
.claude/skills/configuring-firewalls/SKILL.md (or your agent's skills folder). This skill also uses 19 other files; get the full folder from GitHub.Guide engineers through configuring firewalls across host-based (iptables, nftables, UFW), cloud-based (AWS Security Groups, NACLs), and container-based (Kubernetes NetworkPolicies) environments with practical rule examples and safety patterns to prevent lockouts and security misconfigurations.
Trigger Phrases:
Common Scenarios:
AWS:
GCP:
Azure:
Ubuntu/Debian + Simplicity:
RHEL/CentOS/Fedora:
Modern Distro + Advanced Control:
Legacy Systems:
Stateful (recommended for most cases):
Stateless (specialized use):
# 1. Set defaults
sudo ufw default deny incoming
sudo ufw default allow outgoing
# 2. CRITICAL: Allow SSH before enabling (prevent lockout)
sudo ufw allow ssh
sudo ufw limit ssh # Rate-limit to prevent brute force
# 3. Allow web traffic
sudo ufw allow http # Port 80
sudo ufw allow https # Port 443
# 4. Allow from specific IP (e.g., database access)
sudo ufw allow from 192.168.1.100 to any port 5432
# 5. Enable firewall
sudo ufw enable
# 6. Verify rules
sudo ufw status verboseFor complete UFW patterns, see references/ufw-patterns.md
#!/usr/sbin/nft -f
# /etc/nftables.conf
flush ruleset
table inet filter {
chain input {
type filter hook input priority 0; policy drop;
# Accept loopback
iif "lo" accept
# Accept established connections (stateful)
ct state established,related accept
# Drop invalid packets
ct state invalid drop
# Allow SSH
tcp dport 22 accept
# Allow HTTP/HTTPS
tcp dport { 80, 443 } accept
# Log dropped packets
log prefix "nftables-drop: " drop
}
chain forward {
type filter hook forward priority 0; policy drop;
}
chain output {
type filter hook output priority 0; policy accept;
}
}Apply: sudo nft -f /etc/nftables.conf
Enable on boot: sudo systemctl enable nftables
For advanced patterns (sets, maps), see references/nftables-patterns.md
# Web server security group
resource "aws_security_group" "web" {
name = "web-server-sg"
description = "Security group for web servers"
vpc_id = aws_vpc.main.id
# Allow HTTP/HTTPS from anywhere
ingress {
description = "HTTPS from anywhere"
from_port = 443
to_port = 443
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
# Allow SSH from bastion only
ingress {
description = "SSH from bastion"
from_port = 22
to_port = 22
protocol = "tcp"
security_groups = [aws_security_group.bastion.id]
}
# Allow all outbound
egress {
from_port = 0
to_port = 0
protocol = "-1"
cidr_blocks = ["0.0.0.0/0"]
}
tags = {
Name = "web-server-sg"
}
}For Security Groups vs NACLs guide, see references/aws-security-groups.md
Before enabling any firewall:
nmap -Pn <server-ip>ufw limit ssh)Requirements:
UFW:
sudo ufw default deny incoming
sudo ufw allow from 203.0.113.0/24 to any port 22 # Office IP
sudo ufw allow http
sudo ufw allow https
sudo ufw enablenftables: See references/nftables-patterns.md for complete example
AWS Security Group: See references/aws-security-groups.md for Terraform module
Requirements:
See references/database-patterns.md for implementation
Purpose: Single hardened entry point for SSH access
See references/bastion-pattern.md for complete implementation
Purpose: Control outbound traffic to prevent data exfiltration
See references/egress-filtering.md for implementation
Track connection state (established, related, new):
No connection tracking:
Layer multiple firewall controls:
Security Groups (AWS): All rules evaluated, most permissive wins Network ACLs (AWS): Sequential evaluation, first match wins nftables/iptables: Sequential, first match wins UFW: Sequential by rule number
Bastion Host Architecture: See references/bastion-pattern.md for single entry point patterns
DMZ (Demilitarized Zone): See references/dmz-pattern.md for network segmentation
Egress Filtering: See references/egress-filtering.md for outbound traffic control
Kubernetes NetworkPolicies: See references/k8s-networkpolicies.md for pod-to-pod isolation
Migrating iptables to nftables: See references/migration-guide.md for conversion process
Cloud Firewall Comparisons:
"I locked myself out via SSH":
Connection timeouts:
sudo ufw status or sudo nft list rulesetss -tuln | grep <port>nmap -Pn <ip> -p <port>/var/log/ufw.log or journalctl -u nftablesAWS: Ephemeral port issues:
Kubernetes pods can't communicate:
kubectl get networkpolicies -n <namespace>For complete troubleshooting guide, see references/troubleshooting.md
❌ Allowing 0.0.0.0/0 on SSH/RDP → Use bastion or VPN ❌ Forgetting to enable firewall → Rules configured but not active ❌ Not testing before enabling → Risk of lockout ❌ Missing ephemeral ports in NACLs → Return traffic blocked ❌ Running iptables + nftables → Conflicts and unpredictable behavior ❌ No logging → Can't debug or audit ❌ Large port ranges → Unnecessary attack surface ❌ Not documenting rules → Future confusion
# Status
sudo ufw status verbose
sudo ufw status numbered
# Add rules
sudo ufw allow <port>/<protocol>
sudo ufw allow from <ip> to any port <port>
sudo ufw limit ssh # Rate limiting
# Delete rules
sudo ufw delete <rule-number>
sudo ufw delete allow 80/tcp
# Logging
sudo ufw logging on
tail -f /var/log/ufw.log
# Reset (disable and remove all rules)
sudo ufw reset# List ruleset
sudo nft list ruleset
# Load config
sudo nft -f /etc/nftables.conf
# Flush all rules
sudo nft flush ruleset
# Add rule dynamically
sudo nft add rule inet filter input tcp dport 8080 accept
# Enable on boot
sudo systemctl enable nftables# List rules
sudo iptables -L -v -n
sudo iptables -L INPUT --line-numbers
# Add rule
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
# Delete rule
sudo iptables -D INPUT <rule-number>
# Save rules
sudo netfilter-persistent save # Debian/Ubuntu
sudo service iptables save # RHEL/CentOS# List security groups
aws ec2 describe-security-groups --group-ids sg-xxxxx
# List NACLs
aws ec2 describe-network-acls --network-acl-ids acl-xxxxx
# Add rule to security group
aws ec2 authorize-security-group-ingress \
--group-id sg-xxxxx \
--protocol tcp \
--port 443 \
--cidr 0.0.0.0/0For infrastructure as code approach, use Terraform (see references/aws-security-groups.md)
Complete working examples available in:
examples/ufw/ - UFW configuration scriptsexamples/nftables/ - nftables rulesetsexamples/iptables/ - iptables rule scriptsexamples/terraform-aws/ - AWS Security Groups and NACLsexamples/terraform-gcp/ - GCP firewall rulesexamples/terraform-azure/ - Azure NSGsexamples/kubernetes/ - NetworkPolicy manifestsRelated Skills:
security-hardening - Firewalls are one component of server hardening. See security-hardening skill for SSH hardening, fail2ban, auditd, and SELinux.
building-ci-pipelines - CI runners need network access to repos and artifact stores. Configure firewall rules for self-hosted runners.
deploying-applications - Applications need firewall rules for service exposure. See deploying-applications for integration.
infrastructure-as-code - Manage firewalls as code with Terraform/CloudFormation. See infrastructure-as-code for IaC best practices.
kubernetes-operations - Advanced K8s networking beyond basic NetworkPolicies. See kubernetes-operations for Services, Ingress, and CNI configuration.
network-architecture - Broader network design patterns. See network-architecture for VPC design, subnets, and routing.
Tool-Specific Guides:
Cloud Provider Guides:
Advanced Patterns:
Support:
© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 19 other files (references) in skills/configuring-firewalls of ancoleman/ai-design-components.
Open the folder on GitHubat commit 76551b7
Configuring Firewalls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuring Firewalls this skillancoleman/ai-design-components | 526 | — | ~3.5k | Automated safety check: Notes | MIT | |
| Cloud AuditCommonHuman-Lab/nyxstrike | 157 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Agent Bom Scan InfraLeoYeAI/openclaw-master-skills | 2.2k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Cloud Auditbriiirussell/cybersecurity-skills | 413 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 |
CommonHuman-Lab/nyxstrike
Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images
LeoYeAI/openclaw-master-skills
Scan infrastructure-as-code, cloud configurations, and find secrets.
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
mukul975/Anthropic-Cybersecurity-Skills
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…
mukul975/Anthropic-Cybersecurity-Skills
Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…
trilwu/secskills
Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…
ancoleman/ai-design-components
Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.
ancoleman/ai-design-components
Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.
ancoleman/ai-design-components
Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.
ancoleman/ai-design-components
Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.
ancoleman/ai-design-components
Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.
ancoleman/ai-design-components
Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.
Categories
Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. Configuring Firewalls is an agent skill from ancoleman/ai-design-components. Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.
Configuring Firewalls fits situations like: exposing services; hardening servers; implementing network segmentation with defense-in-depth strategies.
Run `npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a claude-code`. Or copy the skill folder (skills/configuring-firewalls in ancoleman/ai-design-components) into .claude/skills/configuring-firewalls in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a codex`. Or copy the skill folder (skills/configuring-firewalls in ancoleman/ai-design-components) into .agents/skills/configuring-firewalls in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill configuring-firewalls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuring-firewalls, .gemini/skills/configuring-firewalls, .github/skills/configuring-firewalls and .opencode/skills/configuring-firewalls in your project.
Going by SKILL.md and its folder, Configuring Firewalls needs a shell for the scripts in its folder and the command-line tools its instructions call (aws and kubectl). Our summary lists: A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Configuring Firewalls is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 41k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Configuring Firewalls: Cloud Audit (CommonHuman-Lab/nyxstrike, 157 stars), Agent Bom Scan Infra (LeoYeAI/openclaw-master-skills, 2.2k stars), Cloud Audit (briiirussell/cybersecurity-skills, 413 stars) and Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.
Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.