Unifi
enuno/unifi-mcp-server
Manage UniFi network infrastructure via the UniFi MCP Server.
Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management.
$ npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw fmc-firewall-ops --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/fmc-firewall-ops .claude/skills/fmc-firewall-ops && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fmc-firewall-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fmc-firewall-ops into .claude/skills/fmc-firewall-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fmc-firewall-ops", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fmc-firewall-opsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw fmc-firewall-ops --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/fmc-firewall-ops .agents/skills/fmc-firewall-ops && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fmc-firewall-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fmc-firewall-ops into .agents/skills/fmc-firewall-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fmc-firewall-ops", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw fmc-firewall-ops --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/fmc-firewall-ops .cursor/skills/fmc-firewall-ops && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fmc-firewall-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fmc-firewall-ops into .cursor/skills/fmc-firewall-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fmc-firewall-ops", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/fmc-firewall-ops--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw fmc-firewall-ops --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/fmc-firewall-ops .gemini/skills/fmc-firewall-ops && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fmc-firewall-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fmc-firewall-ops into .gemini/skills/fmc-firewall-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fmc-firewall-ops", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw fmc-firewall-opsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/fmc-firewall-ops .github/skills/fmc-firewall-ops && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fmc-firewall-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fmc-firewall-ops into .github/skills/fmc-firewall-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fmc-firewall-ops", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw fmc-firewall-ops --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/fmc-firewall-ops .opencode/skills/fmc-firewall-ops && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fmc-firewall-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fmc-firewall-ops into .opencode/skills/fmc-firewall-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fmc-firewall-ops", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fmc-firewall-opsCisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management.
Fmc Firewall Ops is an agent skill from automateyournetwork/netclaw. Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management. Use when searching firewall rules by IP or FQDN, checking if host A can reach host B through the firewall, auditing FMC access policies, or reviewing SGT-based segmentation rules.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Cloud networking. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitpippythonFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
FMC_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fmc Firewall Ops loads about 1.8k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 771 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Single FMC mode (set in `.env`):Each profile `.env` contains:Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 771 words, ~1,813 tokens.
.claude/skills/fmc-firewall-ops/SKILL.md (or your agent's skills folder).http://<host>:8000/mcp) — requires HTTPS reverse proxy for productiongit clone + pip install -r requirements.txt + python -m sfw_mcp_fmc.server (or Docker)FMC_BASE_URL, FMC_USERNAME, FMC_PASSWORD| Tool | What It Does |
|---|---|
list_fmc_profiles | Discover all configured FMC instances (single or multi-FMC mode). Returns profile IDs, display names, and aliases. Use this first to select which FMC to query. |
find_rules_by_ip_or_fqdn | Search rules within a specific access policy by IP address or FQDN. Matches source/destination network objects against the given indicator. |
find_rules_for_target | Resolve FTD devices or HA clusters to their assigned access policies, then search those policies. Use when you know the firewall device name but not the policy name. |
search_access_rules | FMC-wide rule search with multiple filter types: network indicators (IP, FQDN), identity indicators (SGT tags, realm users/groups), and policy name filters. The most powerful search tool. |
| Concept | What It Means |
|---|---|
| FMC | Firepower Management Center — centralized management for Cisco Secure Firewalls (FTD) |
| FTD | Firepower Threat Defense — the firewall appliance/virtual managed by FMC |
| Access Policy | Collection of access rules (ACLs) applied to FTD devices — permit/deny by source/dest/port/app |
| Access Rule | Individual rule within a policy — source zones, dest zones, source/dest networks, ports, action (allow/block/monitor) |
| SGT | Security Group Tag — TrustSec identity-based tag for micro-segmentation |
| HA Cluster | High Availability pair of FTD devices sharing the same policy |
| Profile | FMC connection configuration (URL, credentials) — supports multi-FMC environments |
When a user asks "what firewall rules exist for 10.1.1.0/24?":
list_fmc_profiles — identify which FMCs manage this networksearch_access_rules with network indicator 10.1.1.0/24When investigating connectivity through the firewall:
find_rules_for_target with the FTD device namefind_rules_by_ip_or_fqdn for the source IP in the resolved policyWhen auditing TrustSec/SGT-based policies:
search_access_rules with identity indicator for a specific SGT valueise-posture-audit to verify SGT assignment policies in ISEWhen managing multiple FMC instances:
list_fmc_profiles — see all managed FMC instancessearch_access_rules with common indicators| Skill | How They Work Together |
|---|---|
pyats-security | FMC rule audit + device-level ACL verification via pyATS |
ise-posture-audit | FMC SGT rules + ISE SGT assignment and TrustSec matrix |
ise-incident-response | FMC rules for quarantine verification + ISE endpoint investigation |
aws-security-audit | Cross-platform security: FMC on-prem + AWS cloud security posture |
gcp-cloud-logging | FMC firewall logs vs GCP firewall logs for hybrid environments |
nso-device-ops | FMC policies + NSO device config for end-to-end policy view |
servicenow-change-workflow | ServiceNow CR gating before any FMC policy modifications |
github-ops | Commit FMC rule snapshots to Git for config-as-code tracking |
Single FMC mode (set in .env):
FMC_BASE_URL=https://fmc.example.com
FMC_USERNAME=api-user
FMC_PASSWORD=changeme
FMC_VERIFY_SSL=falseMulti-FMC mode (profile directory):
profiles/
dc-east.env # FMC for DC East
dc-west.env # FMC for DC West
dmz.env # FMC for DMZ firewallsEach profile .env contains:
FMC_PROFILE_ID=dc-east
FMC_PROFILE_DISPLAY_NAME=DC East FMC
FMC_PROFILE_ALIASES=10.1.1.10,fmc-east
FMC_BASE_URL=https://fmc-east.example.com
FMC_USERNAME=api-user
FMC_PASSWORD=changeme
FMC_VERIFY_SSL=falselist_fmc_profiles first to select the right FMC instanceFMC_BASE_URL — FMC URL (e.g., https://fmc.example.com)FMC_USERNAME — FMC API usernameFMC_PASSWORD — FMC API passwordFMC_VERIFY_SSL — SSL verification (true/false)FMC_PROFILES_DIR — path to multi-FMC profiles directory (optional)FMC_PROFILE_DEFAULT — default profile name (optional)© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/fmc-firewall-ops of automateyournetwork/netclaw.
Open the folder on GitHubat commit aa90e7d
Fmc Firewall Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fmc Firewall Ops this skillautomateyournetwork/netclaw | 676 | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Unifienuno/unifi-mcp-server | 282 | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| Frontmcp Deploymentagentfront/frontmcp | 146 | — | ~9.2k | Automated safety check: Notes | Apache-2.0 | |
| Openfdd Railway CLIbbartling/open-fdd | 173 | — | ~2.3k | Automated safety check: Notes | Custom licence | |
| Azure Computemicrosoft/GitHub-Copilot-for-Azure | 255 | — | ~657 | Automated safety check: Pass | MIT | |
| AWS Containersaws/agent-toolkit-for-aws | 2.8k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 |
enuno/unifi-mcp-server
Manage UniFi network infrastructure via the UniFi MCP Server.
agentfront/frontmcp
A skill your agent uses when deploying, building for production, packaging, or shipping a FrontMCP server.
bbartling/open-fdd
A skill your agent uses when installing, authenticating, linking, or re-pinning the Open-FDD Railway hub (central/mqtt/web) via the Railway CLI on bensbench.
microsoft/GitHub-Copilot-for-Azure
Azure VM/VMSS router. An agent skill from microsoft/GitHub-Copilot-for-Azure.
aws/agent-toolkit-for-aws
Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry).
kubeshark/kubeshark
Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
Works with
Categories
Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management. Fmc Firewall Ops is an agent skill from automateyournetwork/netclaw. Cisco Secure Firewall FMC — access policy search, rule inspection, FTD device targeting, multi-FMC profile management.
Fmc Firewall Ops fits situations like: searching firewall rules by IP; checking if host A can reach host B through the firewall; auditing FMC access policies; reviewing SGT-based segmentation rules.
Run `npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a claude-code`. Or copy the skill folder (workspace/skills/fmc-firewall-ops in automateyournetwork/netclaw) into .claude/skills/fmc-firewall-ops in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a codex`. Or copy the skill folder (workspace/skills/fmc-firewall-ops in automateyournetwork/netclaw) into .agents/skills/fmc-firewall-ops in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill fmc-firewall-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fmc-firewall-ops, .gemini/skills/fmc-firewall-ops, .github/skills/fmc-firewall-ops and .opencode/skills/fmc-firewall-ops in your project.
Going by SKILL.md and its folder, Fmc Firewall Ops needs the command-line tools its instructions call (git, pip and python) and credentials named FMC_PASSWORD. Our summary lists: Python 3; Docker.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Fmc Firewall Ops is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fmc Firewall Ops: Unifi (enuno/unifi-mcp-server, 282 stars), Frontmcp Deployment (agentfront/frontmcp, 146 stars), Openfdd Railway CLI (bbartling/open-fdd, 173 stars) and Azure Compute (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.