Agent skill

Fortimanager Ops

by automateyournetwork in automateyournetwork/netclaw

FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install.

Apache-2.0Auto-check passedDevOps & Cloud

Install Fortimanager Ops

skills CLI
$ npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw fortimanager-ops --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/fortimanager-ops .claude/skills/fortimanager-ops && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fortimanager-ops
GitHub stars
676
Token cost
~1.6k tokens
SKILL.md length
656 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install.

  • Works in 6 steps: fmg_list_adoms → pick the ADOM. A… → fmg_list_policy_packages → find the… → fmg_get_policy_package → ordered rules.… → …
  • Auditing FortiGate firewall policy at the MANAGER level (intent)
  • SKILL.md covers MCP Server, The distinction this skill…, Tools (8 read-only + 2 write) and Every response carries its…, plus 5 more sections
  • Needs FORTIMANAGER_API_TOKEN

What it does

Fortimanager Ops is an agent skill from automateyournetwork/netclaw. FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install. Use when auditing FortiGate firewall policy at the MANAGER level (intent), reviewing ADOM policy packages, or planning a package install with rollback context.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Auditing FortiGate firewall policy at the MANAGER level (intent)
  • Reviewing ADOM policy packages
  • Planning a package install with rollback context

Example prompts

  • “/fortimanager-ops”

Requirements

  • A credential in FORTIMANAGER_API_TOKEN

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. fmg_list_adoms → pick the ADOM. A package name is unique only within one.
  2. fmg_list_policy_packages → find the package and its install targets.
  3. fmg_get_policy_package → ordered rules. Note position: shadowing is positional.
  4. fmg_resolve_object on every group a rule references. **A rule reported only by
  5. fmg_get_revisions → rollback context before proposing any change.
  6. Feed the rules to fwrule-analyzer for overlap, shadowing and conflict analysis.

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are jsonc).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FORTIMANAGER_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fortimanager Ops loads about 1.6k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 656 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 656 words, ~1,568 tokens.

Download SKILL.mdSave it as .claude/skills/fortimanager-ops/SKILL.md (or your agent's skills folder).
name
fortimanager-ops
description
FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install. Use when auditing FortiGate firewall policy at the MANAGER level (intent), reviewing ADOM policy packages, or planning a package install with rollback context.
version
2.0.0
license
Apache-2.0
tags
fortinet, fortimanager, firewall, policy, adom, security, multi-vendor
user-invocable
true

FortiManager Operations — the manager plane

MCP Server

  • Server: fortinet-mcp (NetClaw-authored, spec 080 / roadmap R3)
  • Command: $FORTINET_MCP_CMD
  • Transport: stdio
  • Requires: FORTIMANAGER_HOST, FORTIMANAGER_API_TOKEN
  • Mode: read-only by default; installs require two gates (below)

v2.0.0: this skill previously declared FORTIMANAGER_MCP_CMD pointing at jmpijll/fortimanager-mcp, which was never vendored, never registered and not installable — the skill was a claim with no server behind it. It is now backed by fortinet-mcp, and the command variable changed to FORTINET_MCP_CMD because one server serves all three Fortinet planes.

The distinction this skill exists to protect

FortiManager holds INTENT. It does not know what a device is actually doing.

QuestionPlaneSkill
"What policy is supposed to apply here?"managerthis skill
"What is the box actually running? Is the tunnel up?"devicefortigate-ops
"Has anything ever matched this rule?"analyzerfortianalyzer-ops
"Run a raw FortiOS CLI command"CLImultivendor-raw-cli (spec 076)

A policy package and a FortiGate's running config legitimately diverge between installs. That gap is where drift, unauthorised change and failed installs live — use fgt_compare_with_manager to surface it rather than assuming they agree.

Tools (8 read-only + 2 write)

ToolWhat it answers
fmg_list_adomsWhich ADOMs exist. The ADOM scopes everything else
fmg_list_devicesManaged FortiGates, connection and sync status
fmg_list_policy_packagesPackages in an ADOM and their install targets
fmg_get_policy_packageOrdered rules: position, action, enabled state
fmg_search_rulesRules matching a source, destination, service or object
fmg_resolve_objectObject/group → members, resolved recursively
fmg_get_revisionsRevision history — rollback context
fmg_preview_installWhat an install would change. No gate required
fmg_check_change_recordIs a ServiceNow CR approved? Read-only
fmg_install_packageProduction change. Two gates, see below

Every response carries its plane and scope

jsonc
{ "plane": "manager", "scope": {"adom": "root", "package": "Corp"},
  "source": "...", "outcome": "ok", "data": {...}, "notes": [] }

outcome distinguishes results that look alike: ok, empty_result, plane_unreachable, auth_expired, auth_missing, scope_indeterminate, and the three separate write refusals. An expired session is auth_expired, never "no policies exist" — that would be a silent, plausible, wrong answer.

Workflow: policy package audit

  1. fmg_list_adoms → pick the ADOM. A package name is unique only within one.
  2. fmg_list_policy_packages → find the package and its install targets.
  3. fmg_get_policy_package → ordered rules. Note position: shadowing is positional.
  4. fmg_resolve_object on every group a rule references. A rule reported only by object name is not an audit — "allow GRP_CORP to GRP_DMZ" says nothing about which addresses that permits.
  5. fmg_get_revisions → rollback context before proposing any change.
  6. Feed the rules to fwrule-analyzer for overlap, shadowing and conflict analysis.
Show full SKILL.md (271 more words)Show less

Workflow: is intent matching reality?

  1. fmg_get_policy_package — the intent.
  2. fgt_compare_with_manager (in fortigate-ops) — the divergence.
  3. only_in_device entries are candidate out-of-band changes: someone edited the firewall directly. This is the single most valuable finding here.
  4. only_in_manager usually means the package has not been installed since those rules were added — check fmg_list_devices sync status.

Writes: two gates, and neither substitutes for the other

fmg_install_package pushes policy to production firewalls — the highest blast-radius action available here.

ConditionOutcome
FORTINET_ALLOW_WRITES not setrefused_read_only
No approved_byrefused_no_approval
No approved ServiceNow CR (non-lab)refused_no_change_record
Both presentproceeds: revision identified → install → verify

Human approval and a ServiceNow change record are different gates. A CR does not imply a human said yes; a human saying yes does not imply change control approved it. Lab devices waive the CR gate only — never the approval gate — and a device that cannot be classified is treated as production.

Always run fmg_preview_install first. It shows what would change and needs no gate.

Integration with other skills

SkillHow they compose
fortigate-opsDevice-plane state; fgt_compare_with_manager for drift
fortianalyzer-opsWhether a rule has actually matched traffic
fwrule-analyzerFeed retrieved policy to its FortiOS parser for overlap/shadowing
servicenow-change-workflowSupplies the CR that satisfies gate 2 of fmg_install_package
multivendor-raw-cliRaw FortiOS CLI (spec 076) — a different plane, not a substitute
gait-session-trackingEvery operation here is GAIT-audited automatically

Important rules

  • Treat package install as production change execution — baseline, verify, rollback.
  • Always name the ADOM. A package without one is ambiguous.
  • Resolve objects before drawing conclusions.
  • Never present manager intent as observed device state.
  • An empty result is not an error, and auth_expired is not "no data".

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/fortimanager-ops of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Fortimanager Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fortimanager Ops compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fortimanager Ops this skillautomateyournetwork/netclaw676—~1.6kAutomated safety check: PassApache-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Rocketmq Rust Local Clustermxsm/rocketmq-rust1.5k—~2kAutomated safety check: PassApache-2.0
Kubernetes Network Root Cause Analysiskubeshark/kubeshark12k—~5.3kAutomated safety check: PassApache-2.0
Trigger.dev Cost Savings Auditpapermark/papermark9.2k—~1.3kAutomated safety check: PassCustom licence

Similar skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Rocketmq Rust Local Cluster

    mxsm/rocketmq-rust

    Set up, start, verify, inspect, and stop local development clusters from the current rocketmq-rust checkout.

    1.5k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.

    12k GitHub stars~5.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Audits Trigger.dev tasks, schedules and run history for wasteful machine sizes, retries, polling and cron frequency to cut spend.

    9.2k GitHub stars~1.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Observability Triage

    every-app/open-seo

    Triage OpenSEO production errors in Cloudflare Workers Observability — verified query recipes, counting gotchas, and a known-noise filter list applied automatically.

    23k GitHub stars~1.7k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Categories

Questions about Fortimanager Ops

What does Fortimanager Ops do?

FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install. Fortimanager Ops is an agent skill from automateyournetwork/netclaw. FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install.

When should I use Fortimanager Ops?

Fortimanager Ops fits situations like: auditing FortiGate firewall policy at the MANAGER level (intent); reviewing ADOM policy packages; planning a package install with rollback context.

How do I install Fortimanager Ops in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a claude-code`. Or copy the skill folder (workspace/skills/fortimanager-ops in automateyournetwork/netclaw) into .claude/skills/fortimanager-ops in your project. Claude Code loads it when a task matches its description.

How do I install Fortimanager Ops in Codex?

Run `npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a codex`. Or copy the skill folder (workspace/skills/fortimanager-ops in automateyournetwork/netclaw) into .agents/skills/fortimanager-ops in your project. Codex loads it when a task matches its description.

Can I use Fortimanager Ops in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fortimanager-ops, .gemini/skills/fortimanager-ops, .github/skills/fortimanager-ops and .opencode/skills/fortimanager-ops in your project.

What does Fortimanager Ops need to run?

Going by SKILL.md and its folder, Fortimanager Ops needs credentials named FORTIMANAGER_API_TOKEN. Our summary lists: A credential in FORTIMANAGER_API_TOKEN.

Does Fortimanager Ops access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fortimanager Ops safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fortimanager Ops use?

Fortimanager Ops is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fortimanager Ops use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fortimanager Ops?

Skills that share tags, products or a category with Fortimanager Ops: AWS Cdk Development (zxkane/aws-skills, 367 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Rocketmq Rust Local Cluster (mxsm/rocketmq-rust, 1.5k stars) and Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fortimanager Ops?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.