Agent skill

Paloalto Panorama

by automateyournetwork in automateyournetwork/netclaw

Palo Alto Panorama operations — device groups, templates, security policy search, NAT review, commit status, and audit workflows.

Apache-2.0Auto-check passedDevOps & Cloud

Install Paloalto Panorama

skills CLI
$ npx skills add automateyournetwork/netclaw --skill paloalto-panorama -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw paloalto-panorama --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/paloalto-panorama .claude/skills/paloalto-panorama && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
paloalto-panorama
GitHub stars
676
Token cost
~780 tokens
SKILL.md length
331 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Palo Alto Panorama operations — device groups, templates, security policy search, NAT review, commit status, and audit workflows.

  • Works in 5 steps: Resolve the relevant device group and… → Search security and NAT policies using… → Review address objects, dynamic tags,… → …
  • Searching Palo Alto firewall rules
  • SKILL.md covers MCP Server, How to Call the MCP Tools, Typical Tool Coverage and When to Use, plus 4 more sections
  • Calls python3; needs PANOS_API_KEY

What it does

Paloalto Panorama is an agent skill from automateyournetwork/netclaw. Palo Alto Panorama operations — device groups, templates, security policy search, NAT review, commit status, and audit workflows. Use when searching Palo Alto firewall rules, checking if traffic is allowed through Panorama, reviewing NAT policies, or auditing device groups.

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud networking. It works with Model Context Protocol and ServiceNow. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Searching Palo Alto firewall rules
  • Checking if traffic is allowed through Panorama
  • Reviewing NAT policies
  • Auditing device groups

Example prompts

  • “/paloalto-panorama”

Requirements

  • Python 3
  • A credential in PANOS_API_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the relevant device group and target firewalls.
  2. Search security and NAT policies using source, destination, application, and service.
  3. Review address objects, dynamic tags, and zones tied to the traffic path.
  4. If a policy change is required, create and approve a ServiceNow CR before any write action.
  5. Verify commit status and post-change traffic behavior.

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PANOS_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Paloalto Panorama loads about 780 tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 331 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~780

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 331 words, ~780 tokens.

Download SKILL.mdSave it as .claude/skills/paloalto-panorama/SKILL.md (or your agent's skills folder).
name
paloalto-panorama
description
Palo Alto Panorama operations — device groups, templates, security policy search, NAT review, commit status, and audit workflows. Use when searching Palo Alto firewall rules, checking if traffic is allowed through Panorama, reviewing NAT policies, or auditing device groups.
license
Apache-2.0
user-invocable
true

Palo Alto Panorama

MCP Server

  • Source: iflow-mcp-cdot65-palo-alto-mcp / palo-alto-mcp
  • Command: $PANOS_MCP_CMD
  • Transport: stdio
  • Requires: PANOS_HOSTNAME, PANOS_API_KEY
  • Preferred use: read-only audit and validation; gate policy writes behind ServiceNow CRs

How to Call the MCP Tools

bash
python3 $MCP_CALL "$PANOS_MCP_CMD" TOOL_NAME '{"param":"value"}'

Typical Tool Coverage

  • Device groups and managed firewalls
  • Templates and template stacks
  • Security policy rule search
  • NAT policy review
  • Address objects, services, tags, and zones
  • Commit queues and recent job status

When to Use

  • “Can host A reach host B through Palo Alto?”
  • Policy hygiene reviews and duplicate-rule cleanup
  • Pre-change dependency analysis on Panorama-managed estates
  • Commit validation after approved firewall changes

Workflow: Rule Impact Analysis

  1. Resolve the relevant device group and target firewalls.
  2. Search security and NAT policies using source, destination, application, and service.
  3. Review address objects, dynamic tags, and zones tied to the traffic path.
  4. If a policy change is required, create and approve a ServiceNow CR before any write action.
  5. Verify commit status and post-change traffic behavior.

Integration with Other Skills

SkillIntegration
servicenow-change-workflowRequired for Panorama policy writes and commits
slack-network-alertsDeliver firewall findings and blocked-path summaries
te-path-analysisCorrelate blocked or impaired paths with external reachability
netbox-reconcileMap firewall objects to source-of-truth IP ownership

Important Rules

  • Never push firewall policy without approved change control
  • Always check Panorama commit status after a write
  • Policy hit counts and logs should validate the outcome

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that PANOS_API_KEY, PANOS_HOSTNAME, PANOS_MCP_CMD are set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/paloalto-panorama of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Paloalto Panorama next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Paloalto Panorama compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Paloalto Panorama this skillautomateyournetwork/netclaw676—~780Automated safety check: PassApache-2.0
Unifienuno/unifi-mcp-server284—~1kAutomated safety check: PassApache-2.0
Frontmcp Deploymentagentfront/frontmcp146—~9.2kAutomated safety check: NotesApache-2.0
Openfdd Railway CLIbbartling/open-fdd173—~2.3kAutomated safety check: NotesCustom licence
Azure Computemicrosoft/GitHub-Copilot-for-Azure255—~657Automated safety check: PassMIT
AWS Containersaws/agent-toolkit-for-aws2.8k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Unifi

    enuno/unifi-mcp-server

    Manage UniFi network infrastructure via the UniFi MCP Server.

    284 GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Frontmcp Deployment

    agentfront/frontmcp

    A skill your agent uses when deploying, building for production, packaging, or shipping a FrontMCP server.

    146 GitHub stars~9.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Openfdd Railway CLI

    bbartling/open-fdd

    A skill your agent uses when installing, authenticating, linking, or re-pinning the Open-FDD Railway hub (central/mqtt/web) via the Railway CLI on bensbench.

    173 GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Azure Compute

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure VM/VMSS router. An agent skill from microsoft/GitHub-Copilot-for-Azure.

    255 GitHub stars~657 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Containers

    aws/agent-toolkit-for-aws

    Official

    Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry).

    2.8k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Categories

Questions about Paloalto Panorama

What does Paloalto Panorama do?

Palo Alto Panorama operations — device groups, templates, security policy search, NAT review, commit status, and audit workflows. Paloalto Panorama is an agent skill from automateyournetwork/netclaw. Palo Alto Panorama operations — device groups, templates, security policy search, NAT review, commit status, and audit workflows.

When should I use Paloalto Panorama?

Paloalto Panorama fits situations like: searching Palo Alto firewall rules; checking if traffic is allowed through Panorama; reviewing NAT policies; auditing device groups.

How do I install Paloalto Panorama in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill paloalto-panorama -a claude-code`. Or copy the skill folder (workspace/skills/paloalto-panorama in automateyournetwork/netclaw) into .claude/skills/paloalto-panorama in your project. Claude Code loads it when a task matches its description.

How do I install Paloalto Panorama in Codex?

Run `npx skills add automateyournetwork/netclaw --skill paloalto-panorama -a codex`. Or copy the skill folder (workspace/skills/paloalto-panorama in automateyournetwork/netclaw) into .agents/skills/paloalto-panorama in your project. Codex loads it when a task matches its description.

Can I use Paloalto Panorama in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill paloalto-panorama -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/paloalto-panorama, .gemini/skills/paloalto-panorama, .github/skills/paloalto-panorama and .opencode/skills/paloalto-panorama in your project.

What does Paloalto Panorama need to run?

Going by SKILL.md and its folder, Paloalto Panorama needs the command-line tools its instructions call (python3) and credentials named PANOS_API_KEY. Our summary lists: Python 3; A credential in PANOS_API_KEY.

Does Paloalto Panorama access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Paloalto Panorama safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Paloalto Panorama use?

Paloalto Panorama is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Paloalto Panorama use?

About 780 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Paloalto Panorama?

Skills that share tags, products or a category with Paloalto Panorama: Unifi (enuno/unifi-mcp-server, 284 stars), Frontmcp Deployment (agentfront/frontmcp, 146 stars), Openfdd Railway CLI (bbartling/open-fdd, 173 stars) and Azure Compute (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Paloalto Panorama?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.