AWS Cdk Development
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install.
$ npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw fortimanager-ops --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/fortimanager-ops .claude/skills/fortimanager-ops && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fortimanager-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortimanager-ops into .claude/skills/fortimanager-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortimanager-ops", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortimanager-opsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw fortimanager-ops --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/fortimanager-ops .agents/skills/fortimanager-ops && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fortimanager-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortimanager-ops into .agents/skills/fortimanager-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortimanager-ops", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw fortimanager-ops --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/fortimanager-ops .cursor/skills/fortimanager-ops && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fortimanager-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortimanager-ops into .cursor/skills/fortimanager-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortimanager-ops", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/fortimanager-ops--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw fortimanager-ops --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/fortimanager-ops .gemini/skills/fortimanager-ops && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fortimanager-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortimanager-ops into .gemini/skills/fortimanager-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortimanager-ops", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw fortimanager-opsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/fortimanager-ops .github/skills/fortimanager-ops && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fortimanager-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortimanager-ops into .github/skills/fortimanager-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortimanager-ops", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw fortimanager-ops --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/fortimanager-ops .opencode/skills/fortimanager-ops && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fortimanager-ops" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/fortimanager-ops into .opencode/skills/fortimanager-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fortimanager-ops", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fortimanager-opsFortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install.
Fortimanager Ops is an agent skill from automateyournetwork/netclaw. FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install. Use when auditing FortiGate firewall policy at the MANAGER level (intent), reviewing ADOM policy packages, or planning a package install with rollback context.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud. It works with Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are jsonc).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
FORTIMANAGER_API_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fortimanager Ops loads about 1.6k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 656 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 656 words, ~1,568 tokens.
.claude/skills/fortimanager-ops/SKILL.md (or your agent's skills folder).fortinet-mcp (NetClaw-authored, spec 080 / roadmap R3)$FORTINET_MCP_CMDFORTIMANAGER_HOST, FORTIMANAGER_API_TOKENv2.0.0: this skill previously declared
FORTIMANAGER_MCP_CMDpointing atjmpijll/fortimanager-mcp, which was never vendored, never registered and not installable — the skill was a claim with no server behind it. It is now backed byfortinet-mcp, and the command variable changed toFORTINET_MCP_CMDbecause one server serves all three Fortinet planes.
FortiManager holds INTENT. It does not know what a device is actually doing.
| Question | Plane | Skill |
|---|---|---|
| "What policy is supposed to apply here?" | manager | this skill |
| "What is the box actually running? Is the tunnel up?" | device | fortigate-ops |
| "Has anything ever matched this rule?" | analyzer | fortianalyzer-ops |
| "Run a raw FortiOS CLI command" | CLI | multivendor-raw-cli (spec 076) |
A policy package and a FortiGate's running config legitimately diverge between
installs. That gap is where drift, unauthorised change and failed installs live —
use fgt_compare_with_manager to surface it rather than assuming they agree.
| Tool | What it answers |
|---|---|
fmg_list_adoms | Which ADOMs exist. The ADOM scopes everything else |
fmg_list_devices | Managed FortiGates, connection and sync status |
fmg_list_policy_packages | Packages in an ADOM and their install targets |
fmg_get_policy_package | Ordered rules: position, action, enabled state |
fmg_search_rules | Rules matching a source, destination, service or object |
fmg_resolve_object | Object/group → members, resolved recursively |
fmg_get_revisions | Revision history — rollback context |
fmg_preview_install | What an install would change. No gate required |
fmg_check_change_record | Is a ServiceNow CR approved? Read-only |
fmg_install_package | Production change. Two gates, see below |
{ "plane": "manager", "scope": {"adom": "root", "package": "Corp"},
"source": "...", "outcome": "ok", "data": {...}, "notes": [] }outcome distinguishes results that look alike: ok, empty_result,
plane_unreachable, auth_expired, auth_missing, scope_indeterminate, and the
three separate write refusals. An expired session is auth_expired, never "no
policies exist" — that would be a silent, plausible, wrong answer.
fmg_list_adoms → pick the ADOM. A package name is unique only within one.fmg_list_policy_packages → find the package and its install targets.fmg_get_policy_package → ordered rules. Note position: shadowing is positional.fmg_resolve_object on every group a rule references. A rule reported only by
object name is not an audit — "allow GRP_CORP to GRP_DMZ" says nothing about
which addresses that permits.fmg_get_revisions → rollback context before proposing any change.fwrule-analyzer for overlap, shadowing and conflict analysis.fmg_get_policy_package — the intent.fgt_compare_with_manager (in fortigate-ops) — the divergence.only_in_device entries are candidate out-of-band changes: someone edited
the firewall directly. This is the single most valuable finding here.only_in_manager usually means the package has not been installed since those
rules were added — check fmg_list_devices sync status.fmg_install_package pushes policy to production firewalls — the highest
blast-radius action available here.
| Condition | Outcome |
|---|---|
FORTINET_ALLOW_WRITES not set | refused_read_only |
No approved_by | refused_no_approval |
| No approved ServiceNow CR (non-lab) | refused_no_change_record |
| Both present | proceeds: revision identified → install → verify |
Human approval and a ServiceNow change record are different gates. A CR does not imply a human said yes; a human saying yes does not imply change control approved it. Lab devices waive the CR gate only — never the approval gate — and a device that cannot be classified is treated as production.
Always run fmg_preview_install first. It shows what would change and needs no gate.
| Skill | How they compose |
|---|---|
fortigate-ops | Device-plane state; fgt_compare_with_manager for drift |
fortianalyzer-ops | Whether a rule has actually matched traffic |
fwrule-analyzer | Feed retrieved policy to its FortiOS parser for overlap/shadowing |
servicenow-change-workflow | Supplies the CR that satisfies gate 2 of fmg_install_package |
multivendor-raw-cli | Raw FortiOS CLI (spec 076) — a different plane, not a substitute |
gait-session-tracking | Every operation here is GAIT-audited automatically |
auth_expired is not "no data".© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/fortimanager-ops of automateyournetwork/netclaw.
Open the folder on GitHubat commit aa90e7d
Fortimanager Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fortimanager Ops this skillautomateyournetwork/netclaw | 676 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| AWS Cdk Developmentzxkane/aws-skills | 367 | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| Rocketmq Rust Local Clustermxsm/rocketmq-rust | 1.5k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Root Cause Analysiskubeshark/kubeshark | 12k | — | ~5.3k | Automated safety check: Pass | Apache-2.0 | |
| Trigger.dev Cost Savings Auditpapermark/papermark | 9.2k | — | ~1.3k | Automated safety check: Pass | Custom licence |
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
mxsm/rocketmq-rust
Set up, start, verify, inspect, and stop local development clusters from the current rocketmq-rust checkout.
kubeshark/kubeshark
Investigates past Kubernetes incidents from Kubeshark traffic snapshots: takes captures, dissects API calls, extracts PCAPs and compares traffic over time.
papermark/papermark
Audits Trigger.dev tasks, schedules and run history for wasteful machine sizes, retries, polling and cron frequency to cut spend.
every-app/open-seo
Triage OpenSEO production errors in Cloudflare Workers Observability — verified query recipes, counting gotchas, and a known-noise filter list applied automatically.
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
Works with
Categories
FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install. Fortimanager Ops is an agent skill from automateyournetwork/netclaw. FortiManager policy operations — ADOM inventory, policy package review, recursive object resolution, revision history, install preview, and gated package install.
Fortimanager Ops fits situations like: auditing FortiGate firewall policy at the MANAGER level (intent); reviewing ADOM policy packages; planning a package install with rollback context.
Run `npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a claude-code`. Or copy the skill folder (workspace/skills/fortimanager-ops in automateyournetwork/netclaw) into .claude/skills/fortimanager-ops in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a codex`. Or copy the skill folder (workspace/skills/fortimanager-ops in automateyournetwork/netclaw) into .agents/skills/fortimanager-ops in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill fortimanager-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fortimanager-ops, .gemini/skills/fortimanager-ops, .github/skills/fortimanager-ops and .opencode/skills/fortimanager-ops in your project.
Going by SKILL.md and its folder, Fortimanager Ops needs credentials named FORTIMANAGER_API_TOKEN. Our summary lists: A credential in FORTIMANAGER_API_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fortimanager Ops is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fortimanager Ops: AWS Cdk Development (zxkane/aws-skills, 367 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Rocketmq Rust Local Cluster (mxsm/rocketmq-rust, 1.5k stars) and Kubernetes Network Root Cause Analysis (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.