Gitops Knowledge
fluxcd/agent-skills
Flux CD and Flux Operator expert — answers questions and generates schema-validated YAML for all Flux CRDs (not repo auditing or live cluster debugging).
FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and…
$ npx skills add automateyournetwork/netclaw --skill fortigate-ops -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw fortigate-ops --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/fortigate-ops .claude/skills/fortigate-ops && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fortigate-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortigate-ops into .claude/skills/fortigate-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortigate-ops", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortigate-opsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill fortigate-ops -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw fortigate-ops --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/fortigate-ops .agents/skills/fortigate-ops && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fortigate-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortigate-ops into .agents/skills/fortigate-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortigate-ops", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill fortigate-ops -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw fortigate-ops --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/fortigate-ops .cursor/skills/fortigate-ops && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fortigate-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortigate-ops into .cursor/skills/fortigate-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortigate-ops", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/fortigate-ops--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill fortigate-ops -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw fortigate-ops --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/fortigate-ops .gemini/skills/fortigate-ops && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fortigate-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortigate-ops into .gemini/skills/fortigate-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortigate-ops", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw fortigate-opsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill fortigate-ops -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/fortigate-ops .github/skills/fortigate-ops && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fortigate-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortigate-ops into .github/skills/fortigate-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortigate-ops", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill fortigate-ops -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw fortigate-ops --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/fortigate-ops .opencode/skills/fortigate-ops && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fortigate-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortigate-ops into .opencode/skills/fortigate-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortigate-ops", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fortigate-opsFortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and…
Fortigate Ops is an agent skill from automateyournetwork/netclaw. FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and manager-vs-device drift detection. Use when asking what a FortiGate is ACTUALLY doing right now, whether a tunnel is up, or whether the device matches FortiManager's intent.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering GitOps. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are jsonc).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
FORTIGATE_API_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fortigate Ops loads about 1.4k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 673 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 673 words, ~1,445 tokens.
.claude/skills/fortigate-ops/SKILL.md (or your agent's skills folder).fortinet-mcp (NetClaw-authored, spec 080 / roadmap R3)$FORTINET_MCP_CMDFORTIGATE_HOST, FORTIGATE_API_TOKENA FortiGate knows what it is doing. It does not know what it was supposed to do.
| Question | Plane | Skill |
|---|---|---|
| "Is the tunnel up? What's in the routing table?" | device | this skill |
| "What policy is intended across the estate?" | manager | fortimanager-ops |
| "Has anything ever matched this rule?" | analyzer | fortianalyzer-ops |
| "Run a raw FortiOS CLI command" | CLI | multivendor-raw-cli (spec 076) |
If a device does not answer, this skill reports that it did not answer. It never substitutes FortiManager's intended configuration as though it were observed state — that would turn "the box is unreachable" into a confident, wrong description of a box nobody can see.
| Tool | What it answers |
|---|---|
fgt_system_status | Hostname, serial, version, HA mode, which member answered |
fgt_list_interfaces | Interfaces: link, addressing, speed, error counters, per VDOM |
fgt_get_routes | Routing table as observed, optional protocol filter |
fgt_vpn_tunnels | IPsec tunnels — phase 1 and phase 2 separately |
fgt_get_policies | Firewall policy as running on the device |
fgt_compare_with_manager | Divergence between intent and observed state |
This is the single most important behaviour here.
A tunnel with phase 1 up and phase 2 down is neither "up" nor "down". It is a
specific and common fault — usually a proxy-ID or selector mismatch — where IKE
negotiated fine and no traffic can actually pass. Collapsing the two into one
status field destroys the only signal that distinguishes it from a healthy tunnel
or a dead one.
fgt_vpn_tunnels therefore returns phase1_status, phase2_status, and
phase2_selectors[] per selector pair, because one down selector out of five is
still a fault worth naming.
{ "plane": "device", "scope": {"device": "FGVMEVS9GWUAOMBD", "vdom": "root"},
"source": "...", "outcome": "ok", "data": {...}, "notes": [] }Scope is mandatory. A figure without its VDOM is ambiguous on a multi-VDOM unit, so a response that cannot name its scope is returned as an error rather than as an unqualified result.
fgt_vpn_tunnels — read both phases.fgt_get_routes for a path
to the remote gateway.phase2_selectors[] for which pair failed.fgt_get_policies) or to the analyzer plane for whether anything matched.fgt_compare_with_manager with the ADOM and package.only_in_device → rules on the box that are absent from the policy package.
Someone changed the firewall directly. This is the highest-value finding this
skill produces and it is invisible from either plane alone.only_in_manager → package not installed since those rules were added.A FortiGate-VM evaluation licence caps the unit at 1 vCPU, 2 GB RAM, 3 interfaces,
3 routes and 3 firewall policies. A small ruleset on such a device is a lab limit,
not the estate's real posture — fgt_get_policies says so in its notes.
An unlicensed FortiGate refuses REST authentication entirely: every request
returns 401 regardless of token validity, trusthost, or admin profile. If every call
fails with auth_expired, check get system status for License Status: Valid
before suspecting the token.
| Skill | How they compose |
|---|---|
fortimanager-ops | The intent this device is measured against |
fortianalyzer-ops | Whether traffic actually matched what is configured here |
fwrule-analyzer | Feed fgt_get_policies output to its FortiOS parser |
multivendor-raw-cli | Raw CLI (spec 076). Use when you need command output, not structure |
pyats-troubleshoot | Correlate firewall path findings with routing/device state elsewhere |
gait-session-tracking | Every operation here is GAIT-audited automatically |
fortimanager-ops and its two gates.© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/fortigate-ops of automateyournetwork/netclaw.
Open the folder on GitHubat commit 95bb17e
Fortigate Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fortigate Ops this skillautomateyournetwork/netclaw | 676 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Gitops Knowledgefluxcd/agent-skills | 231 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Ksaildevantler-tech/ksail | 165 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| H Verifym0n0x41d/haft | 1.4k | — | ~3.5k | Automated safety check: Notes | Custom licence | |
| Gitops Cluster Debugfluxcd/agent-skills | 231 | — | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Create Policyharness/harness-skills | 115 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 |
fluxcd/agent-skills
Flux CD and Flux Operator expert — answers questions and generates schema-validated YAML for all Flux CRDs (not repo auditing or live cluster debugging).
devantler-tech/ksail
Use the ksail CLI to spin up and manage Kubernetes clusters (Kind/K3d/Talos/vCluster/KWOK — local via Docker; EKS — cloud via AWS) and GitOps workloads declaratively.
m0n0x41d/haft
Verifies that a recorded DecisionRecord still holds — baseline-vs-measure evidence loop with drift detection per FPF Evidence Decay.
fluxcd/agent-skills
Debug and troubleshoot Flux CD on live Kubernetes clusters (not local repo files) via the Flux MCP server — inspects Flux resource status, reads controller logs, traces dependency chains, and…
harness/harness-skills
Create OPA governance policies for Harness via MCP. An agent skill from harness/harness-skills.
ruvnet/ruflo
Generate and maintain documentation with drift detection. An agent skill from ruvnet/ruflo.
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
Works with
Categories
FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and…. Fortigate Ops is an agent skill from automateyournetwork/netclaw. FortiGate device operations — system status, interfaces, routing, IPsec VPN tunnel state with phase 1 and phase 2 reported separately, HA member identification, per-VDOM scoping, and manager-vs-device drift detection.
Fortigate Ops fits situations like: asking what a FortiGate is ACTUALLY doing right now; whether a tunnel is up; whether the device matches FortiManagers intent.
Run `npx skills add automateyournetwork/netclaw --skill fortigate-ops -a claude-code`. Or copy the skill folder (workspace/skills/fortigate-ops in automateyournetwork/netclaw) into .claude/skills/fortigate-ops in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill fortigate-ops -a codex`. Or copy the skill folder (workspace/skills/fortigate-ops in automateyournetwork/netclaw) into .agents/skills/fortigate-ops in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill fortigate-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fortigate-ops, .gemini/skills/fortigate-ops, .github/skills/fortigate-ops and .opencode/skills/fortigate-ops in your project.
Going by SKILL.md and its folder, Fortigate Ops needs credentials named FORTIGATE_API_TOKEN. Our summary lists: A credential in FORTIGATE_API_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fortigate Ops is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fortigate Ops: Gitops Knowledge (fluxcd/agent-skills, 231 stars), Ksail (devantler-tech/ksail, 165 stars), H Verify (m0n0x41d/haft, 1.4k stars) and Gitops Cluster Debug (fluxcd/agent-skills, 231 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.