Agent skill

Ise Posture Audit

by automateyournetwork in automateyournetwork/netclaw

Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health.

Apache-2.0Auto-check passedLegal & Compliance

Install Ise Posture Audit

skills CLI
$ npx skills add automateyournetwork/netclaw --skill ise-posture-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw ise-posture-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/ise-posture-audit .claude/skills/ise-posture-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ise-posture-audit
GitHub stars
676
Token cost
~3k tokens
SKILL.md length
900 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health.

  • Works in 6 steps: Clear Cache and Establish Baseline → Authorization Policy Review → Posture Compliance Assessment → …
  • Running a periodic ISE compliance audit
  • SKILL.md covers When to Use, How to Call the ISE MCP Tools, Audit Procedure and Severity Rating Criteria, plus 5 more sections
  • Calls python3; needs ISE_PASSWORD

What it does

Ise Posture Audit is an agent skill from automateyournetwork/netclaw. Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health. Use when running a periodic ISE compliance audit, reviewing authorization policies for over-permissiveness, checking TrustSec segmentation, assessing endpoint profiling accuracy, or preparing for SOC2 or PCI-DSS review.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Authorization and RBAC, Healthcare and finance regulation and SOC 2 and security compliance. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Running a periodic ISE compliance audit
  • Reviewing authorization policies for over-permissiveness
  • Checking TrustSec segmentation
  • Assessing endpoint profiling accuracy

Example prompts

  • “/ise-posture-audit”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Clear Cache and Establish Baseline
  2. Authorization Policy Review
  3. Posture Compliance Assessment
  4. Profiling Coverage Analysis
  5. TrustSec SGT Matrix Analysis
  6. Active Session Health

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ISE_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ise Posture Audit loads about 3k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 900 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 900 words, ~2,973 tokens.

Download SKILL.mdSave it as .claude/skills/ise-posture-audit/SKILL.md (or your agent's skills folder).
name
ise-posture-audit
description
Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health. Use when running a periodic ISE compliance audit, reviewing authorization policies for over-permissiveness, checking TrustSec segmentation, assessing endpoint profiling accuracy, or preparing for SOC2 or PCI-DSS review.
license
Apache-2.0
user-invocable
true

ISE Posture and Policy Audit

When to Use

  • Periodic ISE policy compliance audit (SOC2, PCI-DSS, NIST 800-53, HIPAA)
  • Pre-deployment review before onboarding new endpoint types
  • Post-incident review to identify policy gaps that allowed lateral movement
  • TrustSec segmentation validation
  • Profiling accuracy assessment after network changes
  • Quarterly access control hygiene check

How to Call the ISE MCP Tools

All ISE tools are called via mcp-call with the ISE MCP server command:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" TOOL_NAME '{"param":"value"}'

Audit Procedure

Step 1: Clear Cache and Establish Baseline

Start every audit with a fresh cache to ensure current data:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" clear_cache '{}'

Verify connectivity and cache state:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" get_cache_stats '{}'
Step 2: Authorization Policy Review

Pull all policy sets, then drill into authorization rules:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" network_access_policy_set '{}'
bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" network_access_authorization_rules '{}'
bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" network_access_authentication_rules '{}'
bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" network_access_conditions '{}'

Authorization Policy Checks:

CheckWhat to Look ForSeverity If Found
Default AllowDefault rule granting PermitAccess or DenyAccess without conditionsCRITICAL
Overly permissive rulesAuthZ rules with no posture condition and full network accessCRITICAL
Stale rulesRules referencing deleted/unused identity groups or conditionsHIGH
Rule orderingPermissive rules ranked above restrictive rules (shadowing)HIGH
Missing posture checkAuthZ rules that grant access without posture assessmentMEDIUM
Duplicate conditionsMultiple rules with identical match criteriaLOW
Step 3: Posture Compliance Assessment

Review endpoints and identity groups to identify posture gaps:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" endpoints '{}'
bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" identity_groups '{}'

Posture Compliance Checks:

CheckWhat to Look ForSeverity If Found
Endpoints bypassing postureEndpoints with full access but no posture assessment recordedCRITICAL
Non-compliant endpoints on networkEndpoints marked non-compliant but not quarantinedCRITICAL
Missing posture policy for endpoint typeEndpoint categories (BYOD, IoT, contractor) without posture rulesHIGH
Posture reassessment intervalNo periodic reassessment configured (one-time posture only)MEDIUM
Unknown endpoints with accessEndpoints in "Unknown" group with network access beyond guestHIGH
Step 4: Profiling Coverage Analysis

Assess how well ISE is profiling connected endpoints:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" profiler_profiles '{}'

Cross-reference with the endpoint list from Step 3.

Profiling Checks:

CheckWhat to Look ForSeverity If Found
Unknown endpoint ratioMore than 10% of endpoints profiled as "Unknown"HIGH
Unmatched profilesCustom profiles with zero matched endpoints (dead profiles)LOW
Missing critical profilesNo profiles for known device types on the network (printers, phones, cameras)MEDIUM
Profile certaintyEndpoints with low certainty factor (< 20) receiving production accessHIGH
Profiling probe coverageInsufficient probe types enabled for accurate classificationMEDIUM
Step 5: TrustSec SGT Matrix Analysis

Review Security Group Tags and their access control:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" trustsec_sgts '{}'
bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" trustsec_sgacls '{}'
bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" trustsec_egress_matrix_cell '{}'

TrustSec Checks:

CheckWhat to Look ForSeverity If Found
Permit-all SGACLsSGACLs with permit ip (no restrictions between segments)CRITICAL
Missing matrix cellsSGT-to-SGT pairs with no defined policy (defaults to permit or deny?)HIGH
Unused SGTsSGTs defined but assigned to zero endpointsLOW
Overly broad SGTsSingle SGT assigned to endpoints with different trust levelsHIGH
No deny loggingSGACLs with deny rules but no log keywordMEDIUM
Flat segmentationFewer than 3 SGTs defined (minimal micro-segmentation)HIGH
Step 6: Active Session Health

Review current active sessions for anomalies:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" active_sessions '{}'

Session Health Checks:

CheckWhat to Look ForSeverity If Found
Long-lived sessionsSessions active for > 24 hours without reauthenticationMEDIUM
Failed auth spikesMultiple failed authentications from same MAC/IP in short windowHIGH
Guest on production VLANGuest-profiled endpoints on non-guest VLANsCRITICAL
Multiple MACs per portMore than expected endpoints on a single switchport (hub or rogue AP)HIGH
Auth method mismatchEndpoints using MAB when 802.1X is expected for that device typeMEDIUM
Show full SKILL.md (351 more words)Show less

Severity Rating Criteria

CRITICAL -- Immediate risk of unauthorized access or data exfiltration:

  • Default permit-all authorization rules
  • Non-compliant endpoints with unrestricted access
  • Guest endpoints on production VLANs
  • Permit-all SGACLs between untrusted and trusted segments

HIGH -- Significant policy gap that could be exploited:

  • Unknown endpoints with production access
  • Missing TrustSec matrix entries
  • Stale or shadowed authorization rules
  • Low-certainty profiling with production access

MEDIUM -- Policy weakness that should be addressed this cycle:

  • Missing posture reassessment
  • Auth method mismatches
  • Insufficient profiling probes
  • Long-lived sessions without reauth

LOW -- Housekeeping and hygiene items:

  • Unused SGTs or dead profiles
  • Duplicate authorization conditions
  • Minor documentation gaps

Audit Report Format

ISE Posture Audit Report
ISE Deployment: $ISE_BASE
Audit Date: YYYY-MM-DD

CRITICAL FINDINGS (Immediate Action Required):
  1. [C-001] Default AuthZ rule grants PermitAccess — all unmatched endpoints get full access
  2. [C-002] 14 endpoints marked non-compliant but not quarantined
  3. [C-003] SGACL "Permit_All" applied to IoT-to-Server matrix cell

HIGH FINDINGS (Address This Week):
  4. [H-001] 23% of endpoints profiled as "Unknown" — profiling gap
  5. [H-002] SGT "Employees" assigned to both corporate laptops and contractor devices
  6. [H-003] 3 authorization rules shadowed by permissive rule at rank 1

MEDIUM FINDINGS (Address This Month):
  7. [M-001] No posture reassessment configured — one-time check only
  8. [M-002] 47 sessions active > 24h without reauthentication
  9. [M-003] 12 endpoints using MAB instead of expected 802.1X

LOW / INFORMATIONAL:
  10. [L-001] 5 unused SGTs: "Test_SGT", "Legacy_Printers", etc.
  11. [L-002] 3 profiler profiles with zero matched endpoints

Summary: 3 Critical | 3 High | 3 Medium | 2 Low

Policy Sets Reviewed: N
Authorization Rules Reviewed: N
Endpoints Analyzed: N
SGTs Evaluated: N
Active Sessions Checked: N

Integration with Other Skills

  • Use pyats-security to verify device-side 802.1X configuration matches ISE policy (RADIUS server config, dot1x port settings, CoPP for RADIUS traffic)
  • Use gait-session-tracking to record the full audit in the GAIT immutable audit trail
  • Use markmap-viz to visualize the ISE policy hierarchy (Policy Sets > AuthZ Rules > Conditions > Results)
  • Use ise-incident-response when a CRITICAL finding requires immediate endpoint investigation
  • Use servicenow-change-workflow to create Change Requests for ISE policy remediation

GAIT Audit Trail

After completing the audit, record the session in GAIT:

bash
python3 $MCP_CALL "python3 -u $GAIT_MCP_SCRIPT" gait_record_turn '{"user_text":"Example only: replace with the actual authorized request.","assistant_text":"ISE posture audit completed. ISE: $ISE_BASE. Findings: 3 CRITICAL, 3 HIGH, 3 MEDIUM, 2 LOW. Critical items: default permit-all AuthZ rule, 14 non-compliant endpoints not quarantined, permit-all SGACL on IoT-to-Server cell.","artifacts":[]}'

Markmap Visualization

Generate a policy hierarchy mind map for the audit report:

bash
python3 $MCP_CALL "node $MARKMAP_MCP_SCRIPT" markmap_customize '{"markdown_content":"# ISE Policy Audit\n## CRITICAL\n### Default AuthZ permits all\n### Non-compliant endpoints active\n### Permit-all SGACL\n## HIGH\n### 23% Unknown endpoints\n### SGT overlap (employees + contractors)\n### Shadowed AuthZ rules\n## MEDIUM\n### No posture reassessment\n### Long-lived sessions\n### MAB instead of 802.1X\n## LOW\n### Unused SGTs\n### Dead profiler profiles","theme":"dark"}'

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that GAIT_MCP_SCRIPT, ISE_BASE, ISE_MCP_SCRIPT, ISE_PASSWORD, ISE_USERNAME, MARKMAP_MCP_SCRIPT are set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

Audit examples are illustrative. Replace request, outcomes, identifiers and counts with observed session evidence; do not record these example results as facts. Inspect MCP isError, returned ok, and the recorded turn with gait_show when validating a new client/schema. Follow gait-session-tracking for branch checkout.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/ise-posture-audit of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Ise Posture Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ise Posture Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ise Posture Audit this skillautomateyournetwork/netclaw676—~3kAutomated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Implementing Network Access Controlmukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: NotesApache-2.0
Grc Knowledgemlunato47/claude-grc-plugin184—~6.1kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.2kAutomated safety check: PassMIT

Similar skills

  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Implementing Network Access Control

    mukul975/Anthropic-Cybersecurity-Skills

    Implements 802.1X port-based network access control using RADIUS authentication, PacketFence NAC, and switch configuration to enforce identity-based access policies, posture assessment, and…

    34k GitHub stars~3.8k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check: notes
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    946 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    277k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Questions about Ise Posture Audit

What does Ise Posture Audit do?

Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health. Ise Posture Audit is an agent skill from automateyournetwork/netclaw. Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health.

When should I use Ise Posture Audit?

Ise Posture Audit fits situations like: running a periodic ISE compliance audit; reviewing authorization policies for over-permissiveness; checking TrustSec segmentation; assessing endpoint profiling accuracy.

How do I install Ise Posture Audit in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill ise-posture-audit -a claude-code`. Or copy the skill folder (workspace/skills/ise-posture-audit in automateyournetwork/netclaw) into .claude/skills/ise-posture-audit in your project. Claude Code loads it when a task matches its description.

How do I install Ise Posture Audit in Codex?

Run `npx skills add automateyournetwork/netclaw --skill ise-posture-audit -a codex`. Or copy the skill folder (workspace/skills/ise-posture-audit in automateyournetwork/netclaw) into .agents/skills/ise-posture-audit in your project. Codex loads it when a task matches its description.

Can I use Ise Posture Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill ise-posture-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ise-posture-audit, .gemini/skills/ise-posture-audit, .github/skills/ise-posture-audit and .opencode/skills/ise-posture-audit in your project.

What does Ise Posture Audit need to run?

Going by SKILL.md and its folder, Ise Posture Audit needs the command-line tools its instructions call (python3) and credentials named ISE_PASSWORD. Our summary lists: Python 3.

Does Ise Posture Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ise Posture Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ise Posture Audit use?

Ise Posture Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ise Posture Audit use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ise Posture Audit?

Skills that share tags, products or a category with Ise Posture Audit: Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars), Implementing Network Access Control (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Grc Knowledge (mlunato47/claude-grc-plugin, 184 stars) and Audit Report (harness/harness-skills, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ise Posture Audit?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.