Agent skill

Pyats Security

by automateyournetwork in automateyournetwork/netclaw

Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks.

Apache-2.0Auto-check passedSecurity

Install Pyats Security

skills CLI
$ npx skills add automateyournetwork/netclaw --skill pyats-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw pyats-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/pyats-security .claude/skills/pyats-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pyats-security
GitHub stars
676
Token cost
~2.7k tokens
SKILL.md length
1,021 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks.

  • Works in 9 steps: Pull Running Configuration → Management Plane Hardening → AAA Configuration → …
  • Auditing device security posture
  • SKILL.md covers When to Use, Security Audit Procedure, Security Report Format and ISE Integration (MISSION02…, plus 4 more sections
  • Calls python3; needs ISE_PASSWORD

What it does

Pyats Security is an agent skill from automateyournetwork/netclaw. Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks. Use when auditing device security posture, checking compliance, hardening a router or switch, reviewing access lists, or investigating unauthorized access.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Network security. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Auditing device security posture
  • Checking compliance
  • Hardening a router
  • Reviewing access lists

Example prompts

  • “/pyats-security”

Requirements

  • Python 3
  • Node.js

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Pull Running Configuration
  2. Management Plane Hardening
  3. AAA Configuration
  4. Access Control Lists
  5. Control Plane Policing (CoPP)
  6. Routing Protocol Security
  7. Infrastructure Security
  8. Encryption & Credentials
  9. SNMP Security

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ISE_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pyats Security loads about 2.7k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 1,021 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 1,021 words, ~2,710 tokens.

Download SKILL.mdSave it as .claude/skills/pyats-security/SKILL.md (or your agent's skills folder).
name
pyats-security
description
Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks. Use when auditing device security posture, checking compliance, hardening a router or switch, reviewing access lists, or investigating unauthorized access.
license
Apache-2.0
user-invocable
true

Network Security Audit

When to Use

  • Security posture assessment for compliance (SOC2, PCI-DSS, NIST, CIS)
  • Pre-deployment security review
  • Incident response — checking for unauthorized access or configuration
  • Hardening audit for new devices
  • Periodic security validation

Security Audit Procedure

Step 1: Pull Running Configuration

Always start by capturing the full running config for analysis:

bash
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_show_running_config '{"device_name":"R1"}'

Scan the full config for the checks below.

Step 2: Management Plane Hardening

Check these items in the running config:

CheckWhat to Look ForFinding If Missing
SSH versionip ssh version 2CRITICAL: SSHv1 vulnerable to MITM
Telnet disabledNo transport input telnet on VTY linesCRITICAL: Telnet sends cleartext credentials
VTY ACLaccess-class on VTY linesHIGH: Unrestricted management access
Console timeoutexec-timeout on console (not 0 0)MEDIUM: Unattended console sessions
VTY timeoutexec-timeout on VTY lines (not 0 0)MEDIUM: Stale management sessions
Password encryptionservice password-encryptionMEDIUM: Type 0 passwords visible
Enable secretenable secret (not enable password)HIGH: Enable password uses weak hash
Login bannerbanner login or banner motdLOW: Legal/compliance requirement
HTTP server disabledno ip http serverMEDIUM: Unnecessary attack surface
HTTPS serverip http secure-server if web management neededMEDIUM: Use HTTPS not HTTP
Aux port disabledno exec on aux lineLOW: Unused port open
Step 3: AAA Configuration
bash
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show aaa servers"}'

AAA checks in running config:

  • aaa new-model enabled
  • aaa authentication login configured (not just local)
  • aaa authorization exec configured
  • aaa accounting configured for commands and connections
  • TACACS+ or RADIUS server defined with encryption
  • Local fallback account exists (in case AAA server unreachable)
  • aaa authentication enable uses enable secret not enable password
Step 4: Access Control Lists
bash
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show ip access-lists"}'

ACL analysis:

  • Check hit counts — ACEs with 0 matches may be unnecessary or misplaced
  • Look for overly permissive rules (permit ip any any)
  • Verify explicit deny at the end with logging (deny ip any any log)
  • Check ACL is applied to the correct interface and direction
  • Verify VTY access-class restricts management to known networks
  • Look for ACLs referenced in route-maps, NAT, or other features
Step 5: Control Plane Policing (CoPP)

Check in running config for:

  • control-plane section with service-policy
  • CoPP policy-map classifying and rate-limiting traffic to the CPU
  • Protection against: ICMP floods, TTL-expired floods, fragmentation attacks, ARP storms
bash
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show policy-map control-plane"}'
Step 6: Routing Protocol Security

OSPF authentication:

  • Check for ip ospf authentication message-digest on interfaces
  • Or area-level: area X authentication message-digest
  • Verify ip ospf message-digest-key is configured

BGP security:

  • neighbor X password (MD5 authentication)
  • neighbor X ttl-security hops N (GTSM — Generalized TTL Security Mechanism)
  • neighbor X prefix-list or neighbor X maximum-prefix (prefix limits)
  • Check for bogon filtering on eBGP peers

EIGRP authentication:

  • Named mode: af-interface with authentication mode md5 and authentication key-chain
  • Classic mode: ip authentication mode eigrp and ip authentication key-chain eigrp
Step 7: Infrastructure Security

Check in running config:

FeatureConfigPurpose
uRPFip verify unicast source reachable-via rxAnti-spoofing
TCP keepalivesservice tcp-keepalives-in, service tcp-keepalives-outDead session cleanup
CDP restrictedno cdp enable on external interfacesInformation leak prevention
LLDP restrictedno lldp transmit / no lldp receive on externalInformation leak prevention
IP source routing disabledno ip source-routePrevent source-routed attacks
Directed broadcast disabledno ip directed-broadcast per interfaceSmurf attack prevention
ICMP redirects disabledno ip redirects per interfaceMITM prevention
Proxy ARP disabledno ip proxy-arp on external interfacesARP spoofing prevention
Gratuitous ARPno ip gratuitous-arpsARP cache poisoning prevention
IP unreachables limitedno ip unreachables on externalReconnaissance prevention
Timestampsservice timestamps log datetime msec localtimeForensics
Logging bufferlogging buffered with adequate sizeEvent capture
Remote logginglogging host X.X.X.XCentralized log collection
Show full SKILL.md (432 more words)Show less
Step 8: Encryption & Credentials
bash
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show crypto key mypubkey rsa"}'

Check:

  • RSA key size >= 2048 bits (CRITICAL if < 1024)
  • SSH version 2 only
  • No Type 0 (cleartext) passwords in running config
  • Enable secret uses Type 8 or Type 9 (scrypt) if available
  • SNMP community strings are not "public" or "private"
  • SNMPv3 preferred over v2c
Step 9: SNMP Security
bash
PYATS_TESTBED_PATH=$PYATS_TESTBED_PATH python3 $MCP_CALL "${PYATS_PYTHON:-python3} -u $PYATS_MCP_SCRIPT" pyats_run_show_command '{"device_name":"R1","command":"show snmp"}'

Checks:

  • No default community strings (public, private, cisco)
  • RO communities have ACL restricting source
  • RW communities have ACL restricting source (or don't exist at all)
  • SNMPv3 with authPriv preferred
  • SNMP traps configured to central monitoring

Security Report Format

Device: R1 | IOS-XE 17.x.x
Security Audit Date: YYYY-MM-DD

CRITICAL FINDINGS (Fix Immediately):
  1. [C-001] SSHv1 enabled — upgrade to SSH version 2 only
  2. [C-002] No VTY access-class — management plane exposed

HIGH FINDINGS (Fix This Week):
  3. [H-001] No OSPF authentication on Gi1 — route injection risk
  4. [H-002] SNMP community 'public' with no ACL

MEDIUM FINDINGS (Fix This Month):
  5. [M-001] No CoPP policy — CPU vulnerable to floods
  6. [M-002] HTTP server enabled — disable or restrict

LOW / INFORMATIONAL:
  7. [L-001] No login banner configured
  8. [I-001] CDP enabled globally (acceptable on internal interfaces)

Summary: 2 Critical | 2 High | 2 Medium | 2 Low

ISE Integration (MISSION02 Enhancement)

When ISE is available ($ISE_MCP_SCRIPT is set), extend the security audit with identity verification:

Verify Device is Registered as NAD

Check that the device is registered in ISE as a Network Access Device:

bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" network_devices '{}'

Flags:

  • Device not registered as NAD → CRITICAL: Not participating in ISE enforcement
  • Device registered but no RADIUS/TACACS config on device → HIGH: ISE configured but device not using it
Check Active Sessions on Device
bash
ISE_BASE=$ISE_BASE USERNAME=$ISE_USERNAME PASSWORD=$ISE_PASSWORD python3 $MCP_CALL "python3 -u $ISE_MCP_SCRIPT" active_sessions '{}'

Filter sessions for this device's IP to see authenticated endpoints.

NVD CVE Vulnerability Scan

After Step 1 (show version), extract the IOS-XE version and scan for known vulnerabilities:

bash
python3 $MCP_CALL "npx -y nvd-cve-mcp-server" search_cves '{"keyword":"Cisco IOS XE 17.9.4","resultsPerPage":10}'

For each CVE found:

  1. Check CVSS score (flag CVSS >= 7.0)
  2. Cross-reference running config for exposure (e.g., CVE requires HTTP server → check if ip http server is configured)
  3. Produce exposure correlation: CVE + running-config = actual risk

Severity mapping:

  • CVSS >= 9.0 → CRITICAL
  • CVSS >= 7.0 → HIGH
  • CVSS >= 4.0 → MEDIUM
  • CVSS < 4.0 → LOW

Fleet-Wide Security Audit (pCall)

Run the full 9-step audit on ALL devices simultaneously using multiple exec commands. Aggregate findings across the fleet and sort by severity for prioritized remediation.

GAIT Audit Trail

Record the security audit in GAIT:

bash
python3 $MCP_CALL "python3 -u $GAIT_MCP_SCRIPT" gait_record_turn '{"user_text":"Example only: replace with the actual authorized request.","assistant_text":"Security audit on R1: 2 CRITICAL (no enable secret, telnet enabled), 2 HIGH, 2 MEDIUM, 2 LOW findings.","artifacts":[]}'

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that GAIT_MCP_SCRIPT, ISE_MCP_SCRIPT, ISE_PASSWORD, ISE_USERNAME, PYATS_MCP_SCRIPT, PYATS_TESTBED_PATH are set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

Audit examples are illustrative. Replace request, outcomes, identifiers and counts with observed session evidence; do not record these example results as facts. Inspect MCP isError, returned ok, and the recorded turn with gait_show when validating a new client/schema. Follow gait-session-tracking for branch checkout.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/pyats-security of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Pyats Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pyats Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pyats Security this skillautomateyournetwork/netclaw676—~2.7kAutomated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Wireshark Analysiszebbern/claude-code-guide4.7k8 repos~3kAutomated safety check: PassMIT
IotnetBrownFineSecurity/iothackbot8591 repos~1kAutomated safety check: NotesMIT
mTLS Configurationwshobson/agents40k9 repos~588Automated safety check: PassMIT
Netzhinkgit/embeddedskills734—~1.1kAutomated safety check: PassMIT

Similar skills

  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Wireshark Analysis

    zebbern/claude-code-guide

    This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…

    4.7k GitHub starsUsed in 8 repos~3k tokens
    SecurityAuto-check passed
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    859 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • mTLS Configuration

    wshobson/agents

    Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging.

    40k GitHub starsUsed in 9 repos~588 tokens
    SecurityAuto-check passed
  • Net

    zhinkgit/embeddedskills

    嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills.

    734 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Firewall Config

    sickn33/agentic-awesome-skills

    Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.2k tokens
    SecurityAuto-check: notes

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated 4 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Pyats Security

What does Pyats Security do?

Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks. Pyats Security is an agent skill from automateyournetwork/netclaw. Network security audit - ACLs, AAA, control plane policing, management plane hardening, encryption, port security, and CIS benchmark checks.

When should I use Pyats Security?

Pyats Security fits situations like: auditing device security posture; checking compliance; hardening a router; reviewing access lists.

How do I install Pyats Security in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill pyats-security -a claude-code`. Or copy the skill folder (workspace/skills/pyats-security in automateyournetwork/netclaw) into .claude/skills/pyats-security in your project. Claude Code loads it when a task matches its description.

How do I install Pyats Security in Codex?

Run `npx skills add automateyournetwork/netclaw --skill pyats-security -a codex`. Or copy the skill folder (workspace/skills/pyats-security in automateyournetwork/netclaw) into .agents/skills/pyats-security in your project. Codex loads it when a task matches its description.

Can I use Pyats Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill pyats-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pyats-security, .gemini/skills/pyats-security, .github/skills/pyats-security and .opencode/skills/pyats-security in your project.

What does Pyats Security need to run?

Going by SKILL.md and its folder, Pyats Security needs the command-line tools its instructions call (python3) and credentials named ISE_PASSWORD. Our summary lists: Python 3; Node.js.

Does Pyats Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Pyats Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pyats Security use?

Pyats Security is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pyats Security use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pyats Security?

Skills that share tags, products or a category with Pyats Security: Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Wireshark Analysis (zebbern/claude-code-guide, 4.7k stars), Iotnet (BrownFineSecurity/iothackbot, 859 stars) and mTLS Configuration (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pyats Security?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.