Agent skill

AWS Networking Audit

by LeoYeAI in LeoYeAI/openclaw-master-skills

AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource…

Apache-2.0Auto-check passedDevOps & Cloud

Install AWS Networking Audit

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill aws-networking-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills aws-networking-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aws-networking-audit .claude/skills/aws-networking-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-networking-audit
GitHub stars
2.2k
Token cost
~4.5k tokens
SKILL.md length
1,673 words
Files
4 (incl. references)
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0

At a glance

AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource…

  • Works in 6 steps: VPC Inventory and Design Assessment → Security Group and NACL Analysis → Transit Gateway and Connectivity… → …
  • Tasks that involve Cloud networking
  • SKILL.md covers When to Use, Prerequisites, Procedure and Threshold Tables, plus 3 more sections
  • Calls aws

What it does

AWS Networking Audit is an agent skill from LeoYeAI/openclaw-master-skills. AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource optimization using read-only AWS CLI commands.

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/cli-reference.md` and `references/vpc-architecture.md`).

It sits in DevOps & Cloud, covering Cloud networking and Digital forensics. It works with Amazon Web Services. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cloud networking
  • Tasks that involve Digital forensics

Example prompts

  • “/aws-networking-audit”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. VPC Inventory and Design Assessment
  2. Security Group and NACL Analysis
  3. Transit Gateway and Connectivity Assessment
  4. VPC Flow Log Analysis
  5. Route Table Validation
  6. Report and Optimization

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Networking Audit loads about 4.5k tokens when it runs, and up to ~8.6k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 1,673 words, ~4,542 tokens.

Download SKILL.mdSave it as .claude/skills/aws-networking-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
aws-networking-audit
description
AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource optimization using read-only AWS CLI commands.
license
Apache-2.0
metadata.safety
read-only
metadata.author
network-security-skills-suite
metadata.version
1.0.0
metadata.openclaw
{"emoji":"☁️","safetyTier":"read-only","requires":{"bins":["aws"],"env":["AWS_ACCESS_KEY_ID"]},"tags":["aws","vpc","cloud"],"mcpDependencies":["aws-network-mcp…

AWS VPC Networking Security Audit

Cloud resource audit for AWS Virtual Private Cloud (VPC) architecture, security posture, and connectivity. This skill evaluates provider-specific AWS networking constructs — VPC design, Security Groups, NACLs, Transit Gateway topologies, VPC Flow Logs, Route Tables, and ENI placement — not generic cloud networking advice.

Scope covers VPC-layer networking: CIDR planning, subnet tier layout, security filtering, inter-VPC connectivity, and traffic observability. Out of scope: CloudFront distributions, WAF rules, application-layer load balancing (ALB content routing), and DNS (Route 53) configuration. Reference references/cli-reference.md for read-only AWS CLI commands organized by audit step, and references/vpc-architecture.md for the VPC packet flow model, Security Group vs NACL evaluation order, and Transit Gateway routing architecture.

When to Use

  • VPC architecture design review — validating CIDR allocation, subnet tier layout, and AZ distribution before or after deployment
  • Post-migration networking audit — verifying VPC connectivity, Security Group rules, and Route Table entries after workload migration
  • Security assessment — identifying overly permissive Security Group rules, default NACL exposure, and missing VPC Flow Log coverage
  • Connectivity troubleshooting — diagnosing Transit Gateway route propagation failures, VPC peering asymmetric routing, or black-hole routes
  • Compliance preparation — documenting VPC segmentation, Security Group justification, and Flow Log retention for auditors
  • Cost optimization review — identifying unused Elastic Network Interfaces (ENIs), unattached Elastic IPs (EIPs), and cross-AZ traffic patterns

Prerequisites

  • AWS CLI v2 configured with valid credentials (aws sts get-caller-identity succeeds)
  • IAM permissions — minimum read-only policy covering: ec2:DescribeVpcs, ec2:DescribeSubnets, ec2:DescribeSecurityGroups, ec2:DescribeNetworkAcls, ec2:DescribeTransitGateways, ec2:DescribeTransitGatewayRouteTables, ec2:DescribeRouteTables, ec2:DescribeFlowLogs, ec2:DescribeNetworkInterfaces, ec2:DescribeVpcPeeringConnections, ec2:DescribeVpcEndpoints, ec2:DescribeAddresses, logs:FilterLogEvents, logs:DescribeLogGroups
  • Target scope identified — specific VPC ID(s), AWS account, and region. Multi-account audits require cross-account IAM roles or AWS Organizations access
  • VPC Flow Logs enabled — Step 4 requires active Flow Logs publishing to CloudWatch Logs or S3. If Flow Logs are not enabled, document this as a Critical finding

Procedure

Follow these six steps sequentially. Each step builds on prior findings, moving from inventory through security analysis to optimization.

Step 1: VPC Inventory and Design Assessment

Enumerate all VPCs in the target region and assess architectural design.

aws ec2 describe-vpcs --region <region> --output table
aws ec2 describe-subnets --filters "Name=vpc-id,Values=<vpc-id>" --output table

For each VPC, evaluate:

  • CIDR block allocation: Primary and secondary CIDR blocks. Check for RFC 1918 compliance, overlapping CIDRs across VPCs (blocks peering), and sufficient address space for growth. VPCs support up to 5 CIDR blocks.
  • Subnet tier layout: Identify public subnets (Route Table routes to Internet Gateway), private subnets (Route Table routes to NAT Gateway), and isolated subnets (no internet route). Verify each tier exists and workloads are placed in the correct tier.
  • Availability Zone distribution: Subnets should span at least 2 AZs for resilience. Single-AZ VPC designs are a High finding.
  • DNS settings: Verify enableDnsSupport and enableDnsHostnames are enabled — required for VPC endpoints and private DNS resolution.
  • Tenancy: Default vs dedicated. Dedicated tenancy has significant cost implications; verify it is intentional.
Step 2: Security Group and NACL Analysis

Audit stateful Security Group rules and stateless NACL rules for overly permissive access.

Security Group analysis:

aws ec2 describe-security-groups --filters "Name=vpc-id,Values=<vpc-id>"

For each Security Group, evaluate inbound and outbound rules:

  • 0.0.0.0/0 inbound rules: Any Security Group rule permitting inbound from 0.0.0.0/0 (or ::/0) is a finding. Severity depends on port: SSH/RDP from 0.0.0.0/0 is Critical; HTTPS from 0.0.0.0/0 on a public ALB may be acceptable.
  • SG-to-ENI mapping on public subnets: Cross-reference Security Groups with ENIs on public subnets. An overly permissive Security Group attached to an ENI in a public subnet with a public IP is higher risk than the same Security Group on a private subnet.
  • Default Security Group: The VPC default Security Group allows all inbound from itself and all outbound. If any ENI uses the default Security Group, flag as Medium — workloads should use purpose-specific Security Groups.
  • Unused Security Groups: Security Groups with no associated ENIs are cleanup candidates.

NACL analysis:

aws ec2 describe-network-acls --filters "Name=vpc-id,Values=<vpc-id>"

NACLs are stateless — evaluate both inbound and outbound rule sets:

  • Rule ordering: NACLs evaluate rules by rule number (lowest first). A broad permit at rule 100 cannot be overridden by a deny at rule 200. Verify deny rules are numbered lower than corresponding permits.
  • Default NACL: Allows all inbound and outbound traffic. Subnets using the default NACL have no network-layer filtering beyond Security Groups. Flag as Medium if used on production subnets.
  • Ephemeral port range: Outbound NACLs must permit ephemeral ports (1024–65535) for return traffic. Missing ephemeral port rules break TCP connections.
Step 3: Transit Gateway and Connectivity Assessment

Evaluate inter-VPC and hybrid connectivity through Transit Gateway (TGW), VPC Peering, and VPC Endpoints.

Transit Gateway:

aws ec2 describe-transit-gateways
aws ec2 describe-transit-gateway-route-tables --transit-gateway-id <tgw-id>
aws ec2 search-transit-gateway-routes --transit-gateway-route-table-id <tgw-rt-id> --filters "Name=state,Values=active"
  • TGW route table associations: Each VPC attachment should be associated with the correct TGW Route Table. Misassociations cause traffic to route to wrong VPCs.
  • Route propagation: Verify propagation is enabled for VPC attachments that need dynamic routing. Disabled propagation requires manual static routes — check for stale entries.
  • TGW peering: For multi-region Transit Gateway peering, verify routes are propagated across regions and CIDR blocks don't overlap.

VPC Peering:

aws ec2 describe-vpc-peering-connections --filters "Name=status-code,Values=active"
  • Route validation: VPC peering is non-transitive. Verify Route Tables in both VPCs contain routes pointing to the peering connection for the peer CIDR. Missing routes cause silent packet drops.
  • DNS resolution: Check AllowDnsResolutionFromRemoteVpc for cross-VPC private DNS.

VPC Endpoints:

aws ec2 describe-vpc-endpoints --filters "Name=vpc-id,Values=<vpc-id>"
  • Gateway endpoints: S3 and DynamoDB. Verify Route Table entries exist for gateway endpoint prefix lists.
  • Interface endpoints (PrivateLink): Verify ENI placement in appropriate subnets and Security Group rules permit traffic from workloads.
Step 4: VPC Flow Log Analysis

Analyze VPC Flow Logs for security events and traffic patterns.

aws ec2 describe-flow-logs --filter "Name=resource-id,Values=<vpc-id>"

Verify Flow Logs are enabled at the VPC level (not just subnet or ENI level) with REJECT and ACCEPT capture. If Flow Logs are not enabled, document as Critical and recommend enabling before further analysis.

For active Flow Logs, query CloudWatch Logs:

aws logs filter-log-events --log-group-name <flow-log-group> --filter-pattern "REJECT"

Analyze patterns:

  • Reject patterns: High-volume REJECTs from external IPs suggest scanning or attack traffic. REJECTs between internal subnets indicate Security Group or NACL misconfigurations.
  • Cross-AZ traffic volume: Flow Logs show source/destination AZ. Significant cross-AZ traffic incurs data transfer costs — identify top cross-AZ flows.
  • Top talkers: Aggregate by source/destination ENI to find highest-volume flows. Unexpected top talkers may indicate compromised instances or data exfiltration.
  • SG deny correlation: Flow Log REJECTs from specific ENIs should correlate with Security Group rules. If an ENI shows REJECTs for traffic that its Security Group should permit, investigate NACL interference.
Show full SKILL.md (661 more words)Show less
Step 5: Route Table Validation

Audit Route Tables for correctness, efficiency, and security.

aws ec2 describe-route-tables --filters "Name=vpc-id,Values=<vpc-id>"

For each Route Table, evaluate:

  • Main vs custom Route Tables: The VPC main Route Table is the default for subnets without explicit association. Verify the main Route Table has restrictive routes — an overly permissive main Route Table affects all unassociated subnets.
  • Most-specific route precedence: AWS Route Tables use longest prefix match. Verify that more-specific routes take precedence as intended and don't create unintended traffic paths.
  • Black-hole routes: Routes with status "blackhole" indicate the target (NAT Gateway, VPC peering, TGW attachment) was deleted. Black-hole routes silently drop traffic. Remove or replace.
  • NAT Gateway routing: Private subnets should route 0.0.0.0/0 to a NAT Gateway for outbound internet access. Verify NAT Gateway is in a public subnet with an EIP. Multi-AZ deployments should have one NAT Gateway per AZ to avoid cross-AZ traffic and single-AZ failure.
  • VPC endpoint routes: Gateway endpoint routes (S3, DynamoDB prefix lists) should exist in Route Tables for subnets that access those services.
Step 6: Report and Optimization

Compile findings and identify resource optimization opportunities.

Unused resource cleanup:

aws ec2 describe-network-interfaces --filters "Name=vpc-id,Values=<vpc-id>" "Name=status,Values=available"
aws ec2 describe-addresses --filters "Name=domain,Values=vpc"
  • Unused ENIs: ENIs in "available" status are not attached to instances. Identify orphaned ENIs from terminated instances or failed deployments.
  • Unattached EIPs: Elastic IPs not associated with an ENI incur hourly charges. Release or associate.
  • NAT Gateway optimization: Consolidate NAT Gateways if traffic volume doesn't justify per-AZ deployment, or deploy per-AZ if cross-AZ data transfer costs exceed NAT Gateway costs.

Compile the findings report using the Report Template section.

Threshold Tables

Security Group Rule Severity
FindingSeverityRationale
SG allows SSH (22) from 0.0.0.0/0CriticalDirect shell access from internet
SG allows RDP (3389) from 0.0.0.0/0CriticalRemote desktop open to internet
SG allows all ports from 0.0.0.0/0CriticalNo port restriction on internet access
ENI on public subnet using default SGHighDefault SG permits all inbound from group members
SG with >50 inbound rulesHighExcessive complexity; likely over-permissive
SG allows database ports from non-app subnetsHighDatabase access not restricted to application tier
SG with no description on rulesMediumLimits auditability and rule justification
SG with 0 associated ENIsMediumUnused — cleanup candidate
VPC Flow Log Reject Rate
Reject Rate (per minute)SeverityAction
>1000 external-source REJECTsHighActive scanning or DDoS — review source IPs
>100 internal-to-internal REJECTsHighMisconfigured SG or NACL — investigate rules
10–100 external REJECTsMediumBackground noise — monitor trend
<10 external REJECTsLowNormal background scanning
Subnet Utilization
Available IPs (% of CIDR)SeverityAction
<10% remainingHighSubnet exhaustion risk — plan CIDR expansion
10–25% remainingMediumMonitor growth — plan expansion proactively
>75% unusedLowOver-provisioned — consider smaller CIDR next time

Decision Trees

Is This Security Group Rule Overly Permissive?
Security Group rule under review
├── Source is 0.0.0.0/0 (or ::/0)?
│   ├── Yes
│   │   ├── Port = 22 (SSH) or 3389 (RDP)?
│   │   │   ├── Yes → CRITICAL: Management ports open to internet
│   │   │   │   └── Restrict to known IP ranges or use SSM/bastion
│   │   │   └── No
│   │   │       ├── Port = 443 (HTTPS) on public-facing ALB/NLB?
│   │   │       │   ├── Yes → Acceptable for public services
│   │   │       │   └── No → HIGH: Review necessity of open port
│   │   │       └── Port = ALL?
│   │   │           └── CRITICAL: All ports open to internet
│   │   └── ENI attached to public subnet instance?
│   │       ├── Yes → Risk amplified — instance directly reachable
│   │       └── No (private subnet) → Lower risk but still flag
│   └── No (specific source CIDR or SG reference)
│       ├── SG self-reference?
│       │   └── Acceptable for cluster communication
│       └── Cross-VPC or broad CIDR (/8, /16)?
│           └── Medium — verify least-privilege intent
Is This VPC Design Following AWS Best Practices?
VPC design under review
├── Multiple AZs used?
│   ├── No → HIGH: Single point of failure
│   └── Yes
│       ├── Subnet tiers defined (public/private/isolated)?
│       │   ├── No → HIGH: Flat network — no segmentation
│       │   └── Yes
│       │       ├── Public subnets have IGW route?
│       │       │   └── Verify only intended subnets are public
│       │       ├── Private subnets route to NAT GW?
│       │       │   ├── Per-AZ NAT GW? → Best practice
│       │       │   └── Single NAT GW → Cost-optimized but AZ risk
│       │       └── Isolated subnets have no internet route?
│       │           └── Verify — should only reach VPC endpoints
│       ├── VPC Flow Logs enabled?
│       │   ├── No → CRITICAL: No traffic visibility
│       │   └── Yes → Check retention and capture scope
│       └── CIDR planning?
│           ├── Overlaps with peered VPCs? → Blocks connectivity
│           └── Sufficient for growth? → Plan secondary CIDRs

Report Template

AWS VPC NETWORKING AUDIT REPORT
==================================
Account: [account-id] ([account-alias])
Region: [region]
VPC: [vpc-id] ([Name tag])
CIDR Blocks: [primary] [secondary if any]
Audit Date: [timestamp]
Performed By: [operator/agent]

VPC ARCHITECTURE:
Subnets: [total] (public:[n] private:[n] isolated:[n])
AZs: [list]
DNS: enableDnsSupport=[yes/no] enableDnsHostnames=[yes/no]
Tenancy: [default/dedicated]

SECURITY GROUPS:
Total: [n] | With 0.0.0.0/0 inbound: [n] | Unused (0 ENIs): [n]
Default SG in use: [yes/no — ENI count]
Rules total: [n] inbound / [n] outbound

NACLs:
Total: [n] | Using default NACL: [n subnets]
Custom NACLs: [n] | Stateless rules reviewed: [n]

CONNECTIVITY:
Transit Gateway: [tgw-id or N/A] | Attachments: [n]
VPC Peering: [n active] | Route validation: [pass/issues]
VPC Endpoints: [n] (gateway:[n] interface:[n])

FLOW LOGS:
Status: [enabled/disabled] | Capture: [ALL/ACCEPT/REJECT]
Log destination: [CloudWatch/S3] | Retention: [days]
Reject rate: [n/min avg] | Top reject sources: [list]

ROUTE TABLES:
Total: [n] | Main RT associations: [n subnets]
Black-hole routes: [n] | NAT GW routes: [n]

RESOURCE OPTIMIZATION:
Unused ENIs: [n] | Unattached EIPs: [n]
Cross-AZ traffic: [high/moderate/low]
NAT GW count: [n] across [n] AZs

FINDINGS:
1. [Severity] [Category] — [Description]
   Resource: [sg-xxx / rtb-xxx / nacl-xxx]
   Issue: [detail] → Recommendation: [action]

RECOMMENDATIONS: [prioritized by severity]
NEXT AUDIT: [CRITICAL findings: 30d, HIGH: 90d, clean: 180d]

Troubleshooting

VPC Flow Logs Not Enabled

If aws ec2 describe-flow-logs returns empty for the target VPC, Flow Logs are not configured. Document as a Critical finding — no traffic visibility. Flow Logs require an IAM role with logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents permissions. Enabling Flow Logs is a non-disruptive operation.

Security Group Not Attached to Expected ENI

Use aws ec2 describe-network-interfaces --filters "Name=group-id,Values=<sg-id>" to find all ENIs associated with a Security Group. If the expected ENI is missing, check whether the instance was replaced (Auto Scaling) or the SG was modified.

Transit Gateway Route Propagation Disabled

If TGW routes are missing, verify propagation is enabled on the TGW Route Table for the relevant VPC attachment. Use aws ec2 get-transit-gateway-route-table-propagations to check. Disabled propagation requires manual static route entries.

Black-Hole Routes in Route Tables

Routes with status "blackhole" occur when the target resource (NAT Gateway, VPC Peering Connection, TGW Attachment) is deleted but the route entry remains. Identify affected subnets and either remove the route or create a replacement target.

Cross-Account VPC Audit

For multi-account environments using AWS Organizations, use aws sts assume-role to obtain temporary credentials for each account. Alternatively, use AWS Config aggregator or AWS RAM (Resource Access Manager) shared resources for centralized visibility.

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/aws-networking-audit of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • _meta.json
  • references/cli-reference.md
  • references/vpc-architecture.md

Open the folder on GitHubat commit e5199b5

Compare with similar skills

AWS Networking Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Networking Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Networking Audit this skillLeoYeAI/openclaw-master-skills2.2k—~4.5kAutomated safety check: PassApache-2.0
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0
Hybrid Cloud Networkingwshobson/agents40k11 repos~1.5kAutomated safety check: PassMIT
Dt Obs AWSDynatrace/dynatrace-for-ai163—~4.2kAutomated safety check: PassApache-2.0
AWS Ecs Fargatesickn33/agentic-awesome-skills47k2 repos~3kAutomated safety check: PassMIT
Load Balancingsickn33/agentic-awesome-skills47k2 repos~2.9kAutomated safety check: NotesMIT

Similar skills

  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Configure secure, high-performance connectivity between on-premises infrastructure and cloud platforms using VPN and dedicated connections.

    40k GitHub starsUsed in 11 repos~1.5k tokens
    DevOps & CloudAuto-check passed
  • Dt Obs AWS

    Dynatrace/dynatrace-for-ai

    AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.

    163 GitHub stars~4.2k tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed
  • AWS Ecs Fargate

    sickn33/agentic-awesome-skills

    Deploy containers on ECS and Fargate. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3k tokens
    DevOps & CloudAuto-check passed
  • Load Balancing

    sickn33/agentic-awesome-skills

    Configure load balancers and traffic distribution. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.9k tokens
    DevOps & CloudAuto-check: notes
  • Performing Cloud Forensics Investigation

    mukul975/Anthropic-Cybersecurity-Skills

    Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs…

    34k GitHub stars~3.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about AWS Networking Audit

What does AWS Networking Audit do?

AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource…. AWS Networking Audit is an agent skill from LeoYeAI/openclaw-master-skills. AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource optimization using read-only AWS CLI commands.

When should I use AWS Networking Audit?

AWS Networking Audit fits situations like: tasks that involve Cloud networking; tasks that involve Digital forensics.

How do I install AWS Networking Audit in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill aws-networking-audit -a claude-code`. Or copy the skill folder (skills/aws-networking-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/aws-networking-audit in your project. Claude Code loads it when a task matches its description.

How do I install AWS Networking Audit in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill aws-networking-audit -a codex`. Or copy the skill folder (skills/aws-networking-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/aws-networking-audit in your project. Codex loads it when a task matches its description.

Can I use AWS Networking Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill aws-networking-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-networking-audit, .gemini/skills/aws-networking-audit, .github/skills/aws-networking-audit and .opencode/skills/aws-networking-audit in your project.

What does AWS Networking Audit need to run?

Going by SKILL.md and its folder, AWS Networking Audit needs the command-line tools its instructions call (aws).

Does AWS Networking Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AWS Networking Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AWS Networking Audit use?

AWS Networking Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Networking Audit use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4k tokens, read only when the agent opens those files.

What are the alternatives to AWS Networking Audit?

Skills that share tags, products or a category with AWS Networking Audit: Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars), Hybrid Cloud Networking (wshobson/agents, 40k stars), Dt Obs AWS (Dynatrace/dynatrace-for-ai, 163 stars) and AWS Ecs Fargate (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Networking Audit?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.