Agent skill

Fortigate Ops

by automateyournetwork in automateyournetwork/netclaw

FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and…

Apache-2.0Auto-check passedDevOps & Cloud

Install Fortigate Ops

skills CLI
$ npx skills add automateyournetwork/netclaw --skill fortigate-ops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw fortigate-ops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/fortigate-ops .claude/skills/fortigate-ops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fortigate-ops
GitHub stars
676
Token cost
~1.4k tokens
SKILL.md length
673 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and…

  • Works in 4 steps: fgt_vpn_tunnels — read both phases. → Phase 1 down → IKE/peer/PSK/routing… → Phase 1 up, phase 2 down →… → …
  • Asking what a FortiGate is ACTUALLY doing right now
  • SKILL.md covers MCP Server, The distinction this skill…, Tools (6, all read-only) and Phase 1 and phase 2 are…, plus 6 more sections
  • Needs FORTIGATE_API_TOKEN

What it does

Fortigate Ops is an agent skill from automateyournetwork/netclaw. FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and manager-vs-device drift detection. Use when asking what a FortiGate is ACTUALLY doing right now, whether a tunnel is up, or whether the device matches FortiManager's intent.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering GitOps. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Asking what a FortiGate is ACTUALLY doing right now
  • Whether a tunnel is up
  • Whether the device matches FortiManagers intent

Example prompts

  • “/fortigate-ops”

Requirements

  • A credential in FORTIGATE_API_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. fgt_vpn_tunnels — read both phases.
  2. Phase 1 down → IKE/peer/PSK/routing problem. Check fgt_get_routes for a path
  3. Phase 1 up, phase 2 down → selector/proxy-ID mismatch. Inspect
  4. Both up but no traffic → not a tunnel problem. Move to policy

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are jsonc).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FORTIGATE_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fortigate Ops loads about 1.4k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 673 words, ~1,445 tokens.

Download SKILL.mdSave it as .claude/skills/fortigate-ops/SKILL.md (or your agent's skills folder).
name
fortigate-ops
description
FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and manager-vs-device drift detection. Use when asking what a FortiGate is ACTUALLY doing right now, whether a tunnel is up, or whether the device matches FortiManager's intent.
version
1.0.0
license
Apache-2.0
tags
fortinet, fortigate, fortios, firewall, vpn, ipsec, vdom, ha, security, multi-vendor
user-invocable
true

FortiGate Operations — the device plane

MCP Server

  • Server: fortinet-mcp (NetClaw-authored, spec 080 / roadmap R3)
  • Command: $FORTINET_MCP_CMD
  • Transport: stdio · FortiOS REST API, bearer token
  • Requires: FORTIGATE_HOST, FORTIGATE_API_TOKEN
  • Mode: read-only — this skill has no write path at all

The distinction this skill exists to protect

A FortiGate knows what it is doing. It does not know what it was supposed to do.

QuestionPlaneSkill
"Is the tunnel up? What's in the routing table?"devicethis skill
"What policy is intended across the estate?"managerfortimanager-ops
"Has anything ever matched this rule?"analyzerfortianalyzer-ops
"Run a raw FortiOS CLI command"CLImultivendor-raw-cli (spec 076)

If a device does not answer, this skill reports that it did not answer. It never substitutes FortiManager's intended configuration as though it were observed state — that would turn "the box is unreachable" into a confident, wrong description of a box nobody can see.

Tools (6, all read-only)

ToolWhat it answers
fgt_system_statusHostname, serial, version, HA mode, which member answered
fgt_list_interfacesInterfaces: link, addressing, speed, error counters, per VDOM
fgt_get_routesRouting table as observed, optional protocol filter
fgt_vpn_tunnelsIPsec tunnels — phase 1 and phase 2 separately
fgt_get_policiesFirewall policy as running on the device
fgt_compare_with_managerDivergence between intent and observed state

Phase 1 and phase 2 are reported separately, always

This is the single most important behaviour here.

A tunnel with phase 1 up and phase 2 down is neither "up" nor "down". It is a specific and common fault — usually a proxy-ID or selector mismatch — where IKE negotiated fine and no traffic can actually pass. Collapsing the two into one status field destroys the only signal that distinguishes it from a healthy tunnel or a dead one.

fgt_vpn_tunnels therefore returns phase1_status, phase2_status, and phase2_selectors[] per selector pair, because one down selector out of five is still a fault worth naming.

Every response carries its plane and scope

jsonc
{ "plane": "device", "scope": {"device": "FGVMEVS9GWUAOMBD", "vdom": "root"},
  "source": "...", "outcome": "ok", "data": {...}, "notes": [] }

Scope is mandatory. A figure without its VDOM is ambiguous on a multi-VDOM unit, so a response that cannot name its scope is returned as an error rather than as an unqualified result.

Workflow: "is the tunnel up?"

  1. fgt_vpn_tunnels — read both phases.
  2. Phase 1 down → IKE/peer/PSK/routing problem. Check fgt_get_routes for a path to the remote gateway.
  3. Phase 1 up, phase 2 down → selector/proxy-ID mismatch. Inspect phase2_selectors[] for which pair failed.
  4. Both up but no traffic → not a tunnel problem. Move to policy (fgt_get_policies) or to the analyzer plane for whether anything matched.
Show full SKILL.md (266 more words)Show less

Workflow: out-of-band change detection

  1. fgt_compare_with_manager with the ADOM and package.
  2. only_in_device → rules on the box that are absent from the policy package. Someone changed the firewall directly. This is the highest-value finding this skill produces and it is invisible from either plane alone.
  3. only_in_manager → package not installed since those rules were added.
  4. If either plane is unreachable, the tool refuses to compare and names the plane that failed. A half-comparison would be worse than none.

Notes on evaluation-licensed labs

A FortiGate-VM evaluation licence caps the unit at 1 vCPU, 2 GB RAM, 3 interfaces, 3 routes and 3 firewall policies. A small ruleset on such a device is a lab limit, not the estate's real posture — fgt_get_policies says so in its notes.

An unlicensed FortiGate refuses REST authentication entirely: every request returns 401 regardless of token validity, trusthost, or admin profile. If every call fails with auth_expired, check get system status for License Status: Valid before suspecting the token.

Integration with other skills

SkillHow they compose
fortimanager-opsThe intent this device is measured against
fortianalyzer-opsWhether traffic actually matched what is configured here
fwrule-analyzerFeed fgt_get_policies output to its FortiOS parser
multivendor-raw-cliRaw CLI (spec 076). Use when you need command output, not structure
pyats-troubleshootCorrelate firewall path findings with routing/device state elsewhere
gait-session-trackingEvery operation here is GAIT-audited automatically

Important rules

  • Read-only. This skill cannot change a FortiGate. Policy changes go through fortimanager-ops and its two gates.
  • Never report phase 1 and phase 2 as one status.
  • Never fill an unreachable device's silence with manager data.
  • Always carry the VDOM.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/fortigate-ops of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Fortigate Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fortigate Ops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fortigate Ops this skillautomateyournetwork/netclaw676—~1.4kAutomated safety check: PassApache-2.0
Gitops Knowledgefluxcd/agent-skills231—~3.8kAutomated safety check: PassApache-2.0
Ksaildevantler-tech/ksail165—~1.1kAutomated safety check: PassCustom licence
H Verifym0n0x41d/haft1.4k—~3.5kAutomated safety check: NotesCustom licence
Gitops Cluster Debugfluxcd/agent-skills231—~4.2kAutomated safety check: PassApache-2.0
Create Policyharness/harness-skills115—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Gitops Knowledge

    fluxcd/agent-skills

    Flux CD and Flux Operator expert — answers questions and generates schema-validated YAML for all Flux CRDs (not repo auditing or live cluster debugging).

    231 GitHub stars~3.8k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Ksail

    devantler-tech/ksail

    Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.

    165 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • H Verify

    m0n0x41d/haft

    Verifies that a recorded DecisionRecord still holds — baseline-vs-measure evidence loop with drift detection per FPF Evidence Decay.

    1.4k GitHub stars~3.5k tokensUpdated 11 days ago
    DevOps & CloudAuto-check: notes
  • Gitops Cluster Debug

    fluxcd/agent-skills

    Debug and troubleshoot Flux CD on live Kubernetes clusters (not local repo files) via the Flux MCP server — inspects Flux resource status, reads controller logs, traces dependency chains, and…

    231 GitHub stars~4.2k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Create Policy

    harness/harness-skills

    Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills.

    115 GitHub stars~1.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Doc Gen

    ruvnet/ruflo

    Generate and maintain documentation with drift detection. An agent skill from ruvnet/ruflo.

    74k GitHub stars~271 tokensUpdated today
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated 4 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Fortigate Ops

What does Fortigate Ops do?

FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and…. Fortigate Ops is an agent skill from automateyournetwork/netclaw. FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and manager-vs-device drift detection.

When should I use Fortigate Ops?

Fortigate Ops fits situations like: asking what a FortiGate is ACTUALLY doing right now; whether a tunnel is up; whether the device matches FortiManagers intent.

How do I install Fortigate Ops in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill fortigate-ops -a claude-code`. Or copy the skill folder (workspace/skills/fortigate-ops in automateyournetwork/netclaw) into .claude/skills/fortigate-ops in your project. Claude Code loads it when a task matches its description.

How do I install Fortigate Ops in Codex?

Run `npx skills add automateyournetwork/netclaw --skill fortigate-ops -a codex`. Or copy the skill folder (workspace/skills/fortigate-ops in automateyournetwork/netclaw) into .agents/skills/fortigate-ops in your project. Codex loads it when a task matches its description.

Can I use Fortigate Ops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill fortigate-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fortigate-ops, .gemini/skills/fortigate-ops, .github/skills/fortigate-ops and .opencode/skills/fortigate-ops in your project.

What does Fortigate Ops need to run?

Going by SKILL.md and its folder, Fortigate Ops needs credentials named FORTIGATE_API_TOKEN. Our summary lists: A credential in FORTIGATE_API_TOKEN.

Does Fortigate Ops access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fortigate Ops safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fortigate Ops use?

Fortigate Ops is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fortigate Ops use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fortigate Ops?

Skills that share tags, products or a category with Fortigate Ops: Gitops Knowledge (fluxcd/agent-skills, 231 stars), Ksail (devantler-tech/ksail, 165 stars), H Verify (m0n0x41d/haft, 1.4k stars) and Gitops Cluster Debug (fluxcd/agent-skills, 231 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fortigate Ops?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.