Agent skill

Fortianalyzer Ops

by automateyournetwork in automateyournetwork/netclaw

FortiAnalyzer log operations — policy-filtered traffic log query within a bounded time window, offset pagination, per-policy activity checks, and logging-device inventory.

Apache-2.0Auto-check passedDevOps & Cloud

Install Fortianalyzer Ops

skills CLI
$ npx skills add automateyournetwork/netclaw --skill fortianalyzer-ops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw fortianalyzer-ops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/fortianalyzer-ops .claude/skills/fortianalyzer-ops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fortianalyzer-ops
GitHub stars
676
Token cost
~1.4k tokens
SKILL.md length
674 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

FortiAnalyzer log operations — policy-filtered traffic log query within a bounded time window, offset pagination, per-policy activity checks, and logging-device inventory.

  • Works in 5 steps: faz_list_devices — confirm the device… → faz_policy_activity with the policy id… → Read the outcome → …
  • Asking whether traffic actually matched a firewall rule
  • SKILL.md covers MCP Server, The one rule that matters most…, Where this plane sits and Tools (4, all read-only), plus 7 more sections
  • Needs FORTIANALYZER_API_TOKEN

What it does

Fortianalyzer Ops is an agent skill from automateyournetwork/netclaw. FortiAnalyzer log operations — policy-filtered traffic log query within a bounded time window, offset pagination, per-policy activity checks, and logging-device inventory. Use when asking whether traffic actually matched a firewall rule, investigating what hit a policy, or determining whether a rule is genuinely unused.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud networking. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Asking whether traffic actually matched a firewall rule
  • Investigating what hit a policy
  • Determining whether a rule is genuinely unused

Example prompts

  • “/fortianalyzer-ops”

Requirements

  • A credential in FORTIANALYZER_API_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. faz_list_devices — confirm the device that owns the rule actually forwards
  2. faz_policy_activity with the policy id and an explicit, generous window.
  3. Read the outcome
  4. Before concluding a rule is unused, verify: log forwarding on, retention covers
  5. Only then treat it as a removal candidate — and route the actual change through

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are jsonc).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FORTIANALYZER_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fortianalyzer Ops loads about 1.4k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 674 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 674 words, ~1,418 tokens.

Download SKILL.mdSave it as .claude/skills/fortianalyzer-ops/SKILL.md (or your agent's skills folder).
name
fortianalyzer-ops
description
FortiAnalyzer log operations — policy-filtered traffic log query within a bounded time window, offset pagination, per-policy activity checks, and logging-device inventory. Use when asking whether traffic actually matched a firewall rule, investigating what hit a policy, or determining whether a rule is genuinely unused.
version
1.0.0
license
Apache-2.0
tags
fortinet, fortianalyzer, logs, traffic, siem, firewall, audit, security
user-invocable
true

FortiAnalyzer Operations — the analyzer plane

MCP Server

  • Server: fortinet-mcp (NetClaw-authored, spec 080 / roadmap R3)
  • Command: $FORTINET_MCP_CMD
  • Transport: stdio · JSON-RPC over /jsonrpc (the same dialect FortiManager speaks)
  • Requires: FORTIANALYZER_HOST, FORTIANALYZER_API_TOKEN (FortiAnalyzer 7.2.2+ for token auth)
  • Mode: read-only

The one rule that matters most here

"No logs matched" is NOT "this rule is unused."

This skill exists to answer "is this rule dead?" — and that question is dangerously easy to answer wrongly. An empty result can mean:

  • nothing matched in the window you queried (retention is finite; history is not)
  • the device never forwarded logs to this analyzer at all
  • logging is disabled on the rule itself

Reporting any of those as "unused" would license someone to delete a live firewall rule. So an empty result returns the explicit outcome no_logs_in_window, never ok and never an error, with a message saying what it does and does not prove.

This is the same error class as spec 078's "no advisories ≠ not vulnerable" and spec 079's "no probes found ≠ outage", and it gets the same treatment: a separate, named outcome that cannot be silently collapsed.

Where this plane sits

QuestionPlaneSkill
"Has anything actually matched this rule?"analyzerthis skill
"What policy is intended?"managerfortimanager-ops
"What is the box running right now?"devicefortigate-ops

The manager knows a rule exists. Only the analyzer knows whether anyone ever matched it. A configured rule is not a used rule.

Tools (4, all read-only)

ToolWhat it answers
faz_query_logsTraffic logs matching a filter within a bounded window
faz_fetch_moreNext page, re-run at an offset
faz_policy_activityDid anything match policy N in this window?
faz_list_devicesWhich devices forward logs here — check this first

Time windows are mandatory and always stated

If you supply no window, the tools apply the last 24 hours and say so in scope.window_start / scope.window_end and in notes. An unbounded log query against a busy analyzer is slow, expensive, and produces a result nobody can interpret because they do not know what period it covers.

Every response echoes the window actually queried, not the one requested.

Pagination

faz_fetch_more re-runs the search at a new offset. It does not reuse FortiAnalyzer's search task id (tid), because those are single-use and expire — treating one as a durable cursor produces silent truncation, where you believe you have all the results and you have some of them.

Show full SKILL.md (283 more words)Show less

Workflow: is this firewall rule dead?

  1. faz_list_devices — confirm the device that owns the rule actually forwards logs here. If it does not, stop: an empty result would mean nothing.
  2. faz_policy_activity with the policy id and an explicit, generous window.
  3. Read the outcome:
    • ok with sessions_matched > 0 → the rule is live. Do not remove it.
    • no_logs_in_window → nothing matched in that window. Not proof of disuse.
  4. Before concluding a rule is unused, verify: log forwarding on, retention covers the period, logging enabled on the rule itself.
  5. Only then treat it as a removal candidate — and route the actual change through fortimanager-ops, which enforces the two write gates.

Workflow: what hit this policy?

  1. faz_query_logs with filter_expr (e.g. policyid=12) and a bounded window.
  2. Page with faz_fetch_more using the returned next_offset while has_more.
  3. Correlate sources and destinations against fmg_resolve_object to check whether the traffic matches what the rule intended to permit.

Every response carries its plane and scope

jsonc
{ "plane": "analyzer",
  "scope": {"adom": "root", "window_start": "...", "window_end": "..."},
  "outcome": "no_logs_in_window", "message": "... This is NOT evidence the rule is unused." }

The window is part of the scope, not an optional detail. A log result without its window is uninterpretable, so a response that cannot state one is an error.

Integration with other skills

SkillHow they compose
fortimanager-opsFind the rule (intent), then come here for whether it was used
fortigate-opsDevice state; use together to separate "not configured" from "not used"
fwrule-analyzerShadowed rules found there + zero activity here = strong removal case
servicenow-change-workflowRule removal is a production change — CR required
gait-session-trackingEvery query here is GAIT-audited automatically

Important rules

  • Never report an empty window as "unused".
  • Always state the window you queried, including the default.
  • Check faz_list_devices before trusting silence.
  • Read-only — findings here justify a change; they never make one.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/fortianalyzer-ops of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Fortianalyzer Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fortianalyzer Ops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fortianalyzer Ops this skillautomateyournetwork/netclaw676—~1.4kAutomated safety check: PassApache-2.0
Unifienuno/unifi-mcp-server284—~1kAutomated safety check: PassApache-2.0
Frontmcp Deploymentagentfront/frontmcp146—~9.2kAutomated safety check: NotesApache-2.0
Openfdd Railway CLIbbartling/open-fdd173—~2.3kAutomated safety check: NotesCustom licence
Azure Computemicrosoft/GitHub-Copilot-for-Azure255—~657Automated safety check: PassMIT
AWS Containersaws/agent-toolkit-for-aws2.8k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Unifi

    enuno/unifi-mcp-server

    Manage UniFi network infrastructure via the UniFi MCP Server.

    284 GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Frontmcp Deployment

    agentfront/frontmcp

    A skill your agent uses when deploying, building for production, packaging, or shipping a FrontMCP server.

    146 GitHub stars~9.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Openfdd Railway CLI

    bbartling/open-fdd

    A skill your agent uses when installing, authenticating, linking, or re-pinning the Open-FDD Railway hub (central/mqtt/web) via the Railway CLI on bensbench.

    173 GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Azure Compute

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure VM/VMSS router. An agent skill from microsoft/GitHub-Copilot-for-Azure.

    255 GitHub stars~657 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Containers

    aws/agent-toolkit-for-aws

    Official

    Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry).

    2.8k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Categories

Questions about Fortianalyzer Ops

What does Fortianalyzer Ops do?

FortiAnalyzer log operations — policy-filtered traffic log query within a bounded time window, offset pagination, per-policy activity checks, and logging-device inventory. Fortianalyzer Ops is an agent skill from automateyournetwork/netclaw. FortiAnalyzer log operations — policy-filtered traffic log query within a bounded time window, offset pagination, per-policy activity checks, and logging-device inventory.

When should I use Fortianalyzer Ops?

Fortianalyzer Ops fits situations like: asking whether traffic actually matched a firewall rule; investigating what hit a policy; determining whether a rule is genuinely unused.

How do I install Fortianalyzer Ops in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill fortianalyzer-ops -a claude-code`. Or copy the skill folder (workspace/skills/fortianalyzer-ops in automateyournetwork/netclaw) into .claude/skills/fortianalyzer-ops in your project. Claude Code loads it when a task matches its description.

How do I install Fortianalyzer Ops in Codex?

Run `npx skills add automateyournetwork/netclaw --skill fortianalyzer-ops -a codex`. Or copy the skill folder (workspace/skills/fortianalyzer-ops in automateyournetwork/netclaw) into .agents/skills/fortianalyzer-ops in your project. Codex loads it when a task matches its description.

Can I use Fortianalyzer Ops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill fortianalyzer-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fortianalyzer-ops, .gemini/skills/fortianalyzer-ops, .github/skills/fortianalyzer-ops and .opencode/skills/fortianalyzer-ops in your project.

What does Fortianalyzer Ops need to run?

Going by SKILL.md and its folder, Fortianalyzer Ops needs credentials named FORTIANALYZER_API_TOKEN. Our summary lists: A credential in FORTIANALYZER_API_TOKEN.

Does Fortianalyzer Ops access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fortianalyzer Ops safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fortianalyzer Ops use?

Fortianalyzer Ops is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fortianalyzer Ops use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fortianalyzer Ops?

Skills that share tags, products or a category with Fortianalyzer Ops: Unifi (enuno/unifi-mcp-server, 284 stars), Frontmcp Deployment (agentfront/frontmcp, 146 stars), Openfdd Railway CLI (bbartling/open-fdd, 173 stars) and Azure Compute (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fortianalyzer Ops?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.