Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations.

Apache-2.0Auto-check: notesSecurity

Install Checkpoint

skills CLI
$ npx skills add automateyournetwork/netclaw --skill checkpoint -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw checkpoint --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/checkpoint .claude/skills/checkpoint && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
checkpoint
GitHub stars
676
Token cost
~2.3k tokens
SKILL.md length
887 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations.

  • Works in 3 steps: API key or username/password is correct → Management server is reachable → User has API access permissions
  • Check Point platform questions
  • SKILL.md covers Activation, MCP Servers, Query Routing and Cross-Platform Composition (US7), plus 5 more sections
  • Reaches api.us1.sase.checkpoint.com; needs CHKP_MGMT_API_KEY and CHKP_MGMT_PASSWORD

What it does

Checkpoint is an agent skill from automateyournetwork/netclaw. Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations. Use for Check Point platform questions or workflows.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering MCP servers and OSINT. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Check Point platform questions
  • Tasks that involve MCP servers
  • Tasks that involve OSINT

Example prompts

  • “/checkpoint”

Requirements

  • A credential in CHKP_MGMT_API_KEY
  • A credential in CHKP_S1C_API_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. API key or username/password is correct
  2. Management server is reachable
  3. User has API access permissions

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.us1.sase.checkpoint.com

    Also links to:

    • mcp.checkpoint.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CHKP_MGMT_API_KEY
    • CHKP_MGMT_PASSWORD
    • CHKP_S1C_API_KEY
    • CHKP_SASE_API_KEY
    • CHKP_REPUTATION_API_KEY
    • CHKP_TE_API_KEY
    • CHKP_SPARK_API_KEY
    • CHKP_ARGOS_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Checkpoint loads about 2.3k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 887 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:230
    l credentials are stored in `~/.openclaw/.env` with the `CHKP_` prefix:
  • NoteMentions a .env fileSKILL.md:275
    gure minimum credentials in `~/.openclaw/.env`:

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 887 words, ~2,268 tokens.

Download SKILL.mdSave it as .claude/skills/checkpoint/SKILL.md (or your agent's skills folder).
name
checkpoint
description
Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations. Use for Check Point platform questions or workflows.

Check Point Security Platform

A comprehensive skill for interacting with Check Point enterprise security infrastructure through 15 MCP servers.

Activation

This skill activates when user queries involve:

  • Check Point firewall policies, rules, or objects
  • Security policy auditing or compliance
  • Threat intelligence (IP/URL/file reputation)
  • Gateway diagnostics and troubleshooting
  • SASE management and cloud security
  • Threat prevention profiles and IPS
  • Malware analysis and file sandboxing
  • Check Point documentation queries

Explicit activation: /checkpoint prefix

MCP Servers

This skill composes across 15 Check Point MCP servers:

ServerPurposeCredentials
chkp-managementPolicies, rules, objects, topologyMGMT server
chkp-management-logsConnection and audit logsMGMT server
chkp-threat-preventionTP profiles, IPS, IOC feedsMGMT server
chkp-https-inspectionHTTPS inspection policiesMGMT server
chkp-harmony-saseSASE regions, applicationsSASE API
chkp-reputation-serviceIP/URL/file reputationReputation API
chkp-quantum-gw-cliGateway diagnosticsMGMT server
chkp-gw-connection-analysisConnection debuggingMGMT server
chkp-threat-emulationMalware analysisTE API
chkp-quantum-gaiaGAIA OS managementMGMT server
chkp-documentationCheck Point docs searchNone
chkp-spark-managementSpark firewall (MSP)Spark API
chkp-cpinfo-analysisCPInfo diagnosticsNone
chkp-argos-ermExposure/risk managementArgos API
chkp-policy-insightsPolicy optimizationMGMT server

Query Routing

Policy & Object Queries (US1)

Keywords: policy, rule, firewall, access, NAT, object, host, network, group, audit, permissive, compliance MCP: chkp-management, chkp-policy-insights

Examples:

  • "show me all firewall policies"
  • "audit my policies for overly permissive rules"
  • "show all rules allowing any-any"
  • "list host objects matching 10.1.*"
  • "show NAT rules for the DMZ policy"
  • "suggest policy optimizations"
  • "show gateways and servers"
Log Queries

Keywords: logs, audit, connection, history, traffic MCP: chkp-management-logs

Examples:

  • "show recent connection logs"
  • "query audit logs for the last hour"
  • "show log statistics"
Threat Intelligence (US2)

Keywords: reputation, malicious, suspicious, threat, IP, URL, hash, file, indicator MCP: chkp-reputation-service

Examples:

  • "check reputation of IP 185.220.101.1"
  • "is this URL malicious: http://example.com/suspicious"
  • "check file reputation for SHA256 abc123..."
  • "what's the risk score for IP 8.8.8.8"
Gateway Diagnostics (US3)

Keywords: gateway, health, CPU, memory, interface, performance, status, cluster, HA MCP: chkp-quantum-gw-cli

Gateway Selection: When multiple gateways are configured, the skill uses the first configured gateway by default. Users can specify a different gateway in their query (e.g., "show health for gateway fw-london").

Examples:

  • "show gateway health status"
  • "what's causing high CPU on the gateway"
  • "show interface statistics for eth0"
  • "show top connections"
  • "show ClusterXL status"
  • "show performance overview"
Connection Debugging

Keywords: debug, connection, failing, drops, blocked, troubleshoot, traffic MCP: chkp-gw-connection-analysis

Examples:

  • "debug why connection from 10.1.1.1 to 8.8.8.8 is failing"
  • "analyze dropped packets on the gateway"
  • "why is traffic being blocked to port 443"
Threat Prevention (US4)

Keywords: threat, IPS, protection, CVE, IOC, feed, profile, signature MCP: chkp-threat-prevention

Examples:

  • "show threat prevention profiles"
  • "what IPS protections are available for CVE-2024-1234"
  • "show active IOC feeds and their status"
  • "show threat indicators"
SASE Management (US5)

Keywords: SASE, harmony, cloud, region, application, distributed MCP: chkp-harmony-sase

Examples:

  • "show all SASE regions"
  • "list applications in SASE policy"
  • "show SASE network configurations"
  • "show SASE configuration status"
Malware Analysis (US6)

Keywords: analyze, file, malware, sandbox, emulation, verdict, suspicious MCP: chkp-threat-emulation

Examples:

  • "analyze file with hash abc123..."
  • "submit file for malware analysis"
  • "get verdict for SHA256 xyz789..."
  • "show analysis report for submission ID 12345"
HTTPS Inspection

Keywords: HTTPS, SSL, inspection, decryption, certificate, bypass MCP: chkp-https-inspection

Examples:

  • "show HTTPS inspection rules"
  • "show HTTPS bypass exceptions"
  • "how is SSL decryption configured"
GAIA OS

Keywords: GAIA, route, ARP, interface, OS, routing, table MCP: chkp-quantum-gaia

Examples:

  • "show GAIA interfaces"
  • "show routing table"
  • "show ARP table"
Show full SKILL.md (356 more words)Show less
Documentation

Keywords: docs, documentation, how, guide, reference, what is, configure, setup MCP: chkp-documentation

Examples:

  • "how do I configure HTTPS inspection"
  • "what is ClusterXL"
  • "show documentation for SmartConsole"
  • "how to set up VPN"
Spark Firewall (MSP)

Keywords: Spark, MSP, appliance, distributed, SMB MCP: chkp-spark-management

Examples:

  • "list Spark appliances"
  • "show Spark policy for appliance X"
  • "show Spark appliance status"
CPInfo Diagnostics

Keywords: CPInfo, diagnostic, support, health check, dump MCP: chkp-cpinfo-analysis

Examples:

  • "analyze CPInfo file from /path/to/cpinfo.tgz"
  • "extract metrics from CPInfo"
Exposure/Risk Management

Keywords: exposure, risk, vulnerability, alert, asset, ERM MCP: chkp-argos-erm

Examples:

  • "show security alerts"
  • "list monitored assets"
  • "query threats for my organization"
  • "show organizational risk score"

Cross-Platform Composition (US7)

This skill can compose with other NetClaw skills for advanced queries:

Check Point + CML
  • "cross-reference firewall rules with my CML lab topology"
  • "which Check Point rules would affect traffic in my lab"
Check Point + SuzieQ
  • "which Check Point rules affect traffic to devices in SuzieQ inventory"
  • "compare firewall policies with network paths from SuzieQ"
Check Point + Batfish
  • "validate Check Point policies against Batfish reachability analysis"
  • "check for policy conflicts using Batfish"

Logging Configuration

Query logging is controlled by the CHKP_LOG_LEVEL environment variable:

LevelBehavior
minimalLog errors only
standardLog queries and MCPs invoked (default)
verboseLog queries, MCPs, and response summaries

Error Handling

MCP Not Configured

If a required MCP is not configured, the skill reports which credentials are missing and provides setup guidance.

Authentication Failures

For auth failures, the skill suggests verifying:

  1. API key or username/password is correct
  2. Management server is reachable
  3. User has API access permissions
Partial Configuration

The skill works with partial configurations. If only Management Server credentials are set, policy and gateway queries work but SASE and Reputation queries will indicate those MCPs are unavailable.

Credential Reference

All credentials are stored in ~/.openclaw/.env with the CHKP_ prefix:

bash
# Management Server (on-prem)
CHKP_MGMT_HOST=192.168.1.100
CHKP_MGMT_PORT=443
CHKP_MGMT_API_KEY=your-api-key
# OR username/password:
# CHKP_MGMT_USERNAME=admin
# CHKP_MGMT_PASSWORD=your-password
CHKP_MGMT_DOMAIN=                    # For MDS only

# Smart-1 Cloud (alternative)
# CHKP_S1C_API_KEY=your-s1c-key
# CHKP_S1C_URL=https://tenant.maas.checkpoint.com

# Harmony SASE
CHKP_SASE_API_KEY=your-sase-key
CHKP_SASE_MGMT_HOST=https://api.us1.sase.checkpoint.com/api
CHKP_SASE_ORIGIN=https://tenant.sase.checkpoint.com

# Reputation Service
CHKP_REPUTATION_API_KEY=your-reputation-key

# Threat Emulation
CHKP_TE_API_KEY=your-te-key

# Spark (MSP)
CHKP_SPARK_API_KEY=your-spark-key

# Argos ERM
CHKP_ARGOS_API_KEY=your-argos-key

# Global
CHKP_TELEMETRY_DISABLED=true
CHKP_LOG_LEVEL=standard

Quick Start

  1. Enable Check Point integration:

    bash
    ./scripts/checkpoint-enable.sh
  2. Configure minimum credentials in ~/.openclaw/.env:

    bash
    CHKP_MGMT_HOST=192.168.1.100
    CHKP_MGMT_API_KEY=your-api-key
    CHKP_TELEMETRY_DISABLED=true
  3. Test the skill:

    bash
    openclaw
    > /checkpoint show my firewall policies
    > /checkpoint check reputation of IP 8.8.8.8

See Also

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/checkpoint of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Checkpoint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Checkpoint compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Checkpoint this skillautomateyournetwork/netclaw676—~2.3kAutomated safety check: NotesApache-2.0
Company Contact Findergooseworks-ai/goose-skills1.2k1 repos~2.7kAutomated safety check: PassMIT
Golang Pkg Go Devcontext-labs/whip1.1k2 repos~3kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
Review Security ReportPrefectHQ/fastmcp28k—~1.2kAutomated safety check: PassApache-2.0
Burp Scansix2dez/burp-ai-agent1.5k—~6.4kAutomated safety check: WarnMIT

Similar skills

  • Company Contact Finder

    gooseworks-ai/goose-skills

    Find decision-makers at a specific company using Apollo, Crustdata, Fiber, and PDL people search via Gooseworks MCP.

    1.2k GitHub starsUsed in 1 repo~2.7k tokens
    Backend & APIsAuto-check passed
  • Golang Pkg Go Dev

    context-labs/whip

    Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.

    1.1k GitHub starsUsed in 2 repos~3k tokens
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 12 days ago
    SecurityAuto-check: notes
  • Review Security Report

    PrefectHQ/fastmcp

    Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them.

    28k GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Burp Scan

    six2dez/burp-ai-agent

    Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.

    1.5k GitHub stars~6.4k tokensUpdated today
    SecurityAuto-check: warnings
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    135 GitHub stars~3.1k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated 3 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated 3 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated 3 days ago
    Auto-check passed

Questions about Checkpoint

What does Checkpoint do?

Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations. Checkpoint is an agent skill from automateyournetwork/netclaw. Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations.

When should I use Checkpoint?

Checkpoint fits situations like: check Point platform questions; tasks that involve MCP servers; tasks that involve OSINT.

How do I install Checkpoint in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill checkpoint -a claude-code`. Or copy the skill folder (workspace/skills/checkpoint in automateyournetwork/netclaw) into .claude/skills/checkpoint in your project. Claude Code loads it when a task matches its description.

How do I install Checkpoint in Codex?

Run `npx skills add automateyournetwork/netclaw --skill checkpoint -a codex`. Or copy the skill folder (workspace/skills/checkpoint in automateyournetwork/netclaw) into .agents/skills/checkpoint in your project. Codex loads it when a task matches its description.

Can I use Checkpoint in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill checkpoint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checkpoint, .gemini/skills/checkpoint, .github/skills/checkpoint and .opencode/skills/checkpoint in your project.

What does Checkpoint need to run?

Going by SKILL.md and its folder, Checkpoint needs credentials named CHKP_MGMT_API_KEY, CHKP_MGMT_PASSWORD, CHKP_S1C_API_KEY and CHKP_SASE_API_KEY. Our summary lists: A credential in CHKP_MGMT_API_KEY; A credential in CHKP_S1C_API_KEY.

Does Checkpoint access the network?

SKILL.md names 2 domains. In commands or code: api.us1.sase.checkpoint.com; the agent is likely to contact it when it follows the instructions. As links in the text: mcp.checkpoint.com. This is read from the text; nothing was executed.

Is Checkpoint safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Checkpoint use?

Checkpoint is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Checkpoint use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Checkpoint?

Skills that share tags, products or a category with Checkpoint: Company Contact Finder (gooseworks-ai/goose-skills, 1.2k stars), Golang Pkg Go Dev (context-labs/whip, 1.1k stars), Forensify (alexgreensh/repo-forensics, 188 stars) and Review Security Report (PrefectHQ/fastmcp, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Checkpoint?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.