Install the "azure-networking-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/azure-networking-audit into .claude/skills/azure-networking-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-networking-audit", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill azure-networking-audit -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "azure-networking-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/azure-networking-audit into .agents/skills/azure-networking-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-networking-audit", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill azure-networking-audit -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "azure-networking-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/azure-networking-audit into .cursor/skills/azure-networking-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-networking-audit", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill azure-networking-audit -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "azure-networking-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/azure-networking-audit into .gemini/skills/azure-networking-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-networking-audit", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill azure-networking-audit -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "azure-networking-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/azure-networking-audit into .github/skills/azure-networking-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-networking-audit", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill azure-networking-audit -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "azure-networking-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/azure-networking-audit into .opencode/skills/azure-networking-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-networking-audit", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
azure-networking-audit
GitHub stars
2.2k
Token cost
~4.5k tokens
SKILL.md length
1,694 words
Files
4 (incl. references)
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0
At a glance
Azure VNet networking audit covering address space design, NSG rule evaluation, Azure Firewall policy analysis, ExpressRoute and VPN Gateway connectivity, VNet Peering topology, and UDR validation…
Works in 6 steps: VNet Inventory and Design Assessment → NSG Rule Audit → Azure Firewall and Network Security → …
Tasks that involve Network security
SKILL.md covers When to Use, Prerequisites, Procedure and Threshold Tables, plus 3 more sections
Calls az
What it does
Azure Networking Audit is an agent skill from LeoYeAI/openclaw-master-skills. Azure VNet networking audit covering address space design, NSG rule evaluation, Azure Firewall policy analysis, ExpressRoute and VPN Gateway connectivity, VNet Peering topology, and UDR validation using read-only Azure CLI commands.
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/cli-reference.md` and `references/vnet-architecture.md`).
It sits in Security, covering Network security. It works with Microsoft Azure. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.
When your agent uses it
Tasks that involve Network security
Example prompts
“/azure-networking-audit”
Workflow steps
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
az
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Azure Networking Audit loads about 4.5k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 1,694 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~64
When it runs· the whole SKILL.md, loaded when a task matches
~4.5k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~10k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/azure-networking-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
azure-networking-audit
description
Azure VNet networking audit covering address space design, NSG rule evaluation, Azure Firewall policy analysis, ExpressRoute and VPN Gateway connectivity, VNet Peering topology, and UDR validation using read-only Azure CLI commands.
Cloud resource audit for Azure Virtual Network (VNet) architecture,
network security posture, and hybrid connectivity. This skill evaluates
provider-specific Azure networking constructs — VNet design, NSG priority-
based rules, Azure Firewall rule collection groups, ExpressRoute circuits,
VNet Peering topology, UDR forced tunneling, and Application Gateway
placement — not generic cloud networking advice.
Scope covers VNet-layer networking: address space planning, subnet
delegation, NSG filtering, Azure Firewall inspection, hybrid connectivity
via ExpressRoute and VPN Gateway, and route management. Out of scope:
Azure Front Door CDN policies, Azure WAF custom rule authoring,
application-layer routing in Application Gateway path rules, and Azure
DNS zone management. Reference references/cli-reference.md for read-only
Azure CLI commands organized by audit step, and references/vnet-architecture.md
for the VNet packet flow model, NSG evaluation order, and ExpressRoute
routing architecture.
When to Use
VNet architecture design review — validating address space allocation, subnet delegation, and service endpoint configuration
Post-migration networking audit — verifying VNet connectivity, NSG rules, and UDR entries after workload migration
Compliance preparation — documenting VNet segmentation, NSG justification, and Azure Firewall logging for auditors
Cost optimization review — identifying unused public IPs, orphaned NICs, and underutilized Application Gateway instances
Prerequisites
Azure CLI authenticated (az account show succeeds)
RBAC permissions — Reader role on target subscription, or granular read permissions: Microsoft.Network/virtualNetworks/read, Microsoft.Network/networkSecurityGroups/read, Microsoft.Network/azureFirewalls/read, Microsoft.Network/expressRouteCircuits/read, Microsoft.Network/virtualNetworkGateways/read, Microsoft.Network/routeTables/read, Microsoft.Network/networkInterfaces/read
Target scope identified — specific subscription, resource group(s), and VNet name(s). Multi-subscription audits require az account set per subscription
Network Watcher enabled — NSG Flow Logs and effective security rules require Network Watcher in the target region. If disabled, document as Critical
Procedure
Follow these six steps sequentially. Each step builds on prior findings,
moving from inventory through security analysis to optimization.
Step 1: VNet Inventory and Design Assessment
Enumerate all VNets in the target subscription and assess architectural design.
az network vnet list --output table
az network vnet show --name <vnet-name> --resource-group <rg>
az network vnet subnet list --vnet-name <vnet-name> --resource-group <rg>
For each VNet, evaluate:
Address space allocation: Primary and additional address spaces. Check RFC 1918 compliance, overlapping address spaces across peered VNets (blocks VNet Peering), and sufficient space for growth.
Subnet layout: Identify subnets by purpose — workload subnets, AzureFirewallSubnet (required name for Azure Firewall), GatewaySubnet (required for VPN Gateway and ExpressRoute Gateway), AzureBastionSubnet. Verify required named subnets exist for deployed services.
Subnet delegation: Check delegations to Azure services (Microsoft.Sql/managedInstances, Microsoft.Web/serverFarms). Delegated subnets restrict which resources can deploy — a subnet delegated to SQL Managed Instance cannot host VMs or other services.
Service endpoints vs Private Endpoints: Service endpoints route PaaS traffic over Azure backbone but don't remove public endpoints on the PaaS resource. Private Endpoints create a private IP within the VNet for the PaaS service, removing public exposure entirely. Audit whether data services (Storage, SQL, Key Vault) use Private Endpoints (preferred for zero-trust) or service endpoints (legacy approach with broader exposure).
DDoS Protection: Verify whether DDoS Protection Standard is enabled on the VNet. Basic DDoS protection is automatic for all Azure resources; Standard adds volumetric attack mitigation, cost protection guarantees, and access to the DDoS Rapid Response team.
Step 2: NSG Rule Audit
Audit Network Security Groups using Azure's priority-based evaluation model.
az network nsg list --output table
az network nsg rule list --nsg-name <nsg-name> --resource-group <rg> --include-default --output table
NSG rules evaluate by priority (lowest number = highest priority, range 100–4096). First match wins.
Priority ordering conflicts: An Allow at priority 200 cannot be overridden by a Deny at 300. Verify Deny rules have lower priority numbers than conflicting Allows — inverse of AWS NACL logic.
Default NSG rules: Azure creates three default inbound rules (AllowVNetInBound 65000, AllowAzureLoadBalancerInBound 65001, DenyAllInBound 65500) and three outbound defaults (AllowVNetOutBound, AllowInternetOutBound, DenyAllOutBound). These cannot be deleted but are overridden by any custom rule with lower priority number.
Internet inbound: NSG rules permitting inbound from * or the Internet service tag. SSH/RDP from Internet is Critical; HTTPS on an Application Gateway subnet may be acceptable. The Internet service tag covers all public IP space excluding VNet, peered VNet, and on-premises address ranges.
Effective security rules: NSGs apply at both subnet and NIC level. Azure evaluates subnet NSG first (inbound), then NIC NSG — traffic must pass both. Use az network nic show-effective-nsg to see the combined effective rules with resolved priorities. A rule allowed by subnet NSG but denied by NIC NSG is effectively denied.
Application Security Groups (ASGs): ASGs group NICs for use as source/destination in NSG rules instead of IP ranges. Audit ASG membership for correctness.
Unused NSGs: NSGs not associated with any subnet or NIC are cleanup candidates.
Step 3: Azure Firewall and Network Security
Evaluate Azure Firewall policies, rule collection groups, and threat intelligence.
az network firewall list --output table
az network firewall policy rule-collection-group list --policy-name <policy> --resource-group <rg>
Rule collection group priority: Azure Firewall processes rule collection groups by priority (lowest first). DNAT rules process first, then Network rules, then Application rules.
DNAT rules: Translate inbound traffic to private IPs. Verify each DNAT rule maps to a valid backend. Stale DNAT rules pointing to decommissioned hosts create exposure.
Network rules: Permit/deny by IP, port, protocol. Audit for overly broad rules (* source/destination, wide port ranges).
Application rules: Filter outbound by FQDN/URL. Verify application rules enforce FQDN restrictions for workload internet access.
Threat intelligence mode: Azure Firewall supports threat intelligence filtering in Alert or Deny mode. Verify production firewalls use Deny mode.
IDPS: Azure Firewall Premium supports signature-based IDPS. Verify mode (Alert vs Alert and Deny) and that bypass rules are justified.
Azure Firewall subnet: AzureFirewallSubnet must be /26 or larger with a public IP and UDRs routing traffic through it.
Step 4: Connectivity Analysis
Evaluate hybrid and inter-VNet connectivity through ExpressRoute, VPN Gateway, and VNet Peering.
ExpressRoute:
az network express-route show --name <circuit> --resource-group <rg>
az network express-route peering list --circuit-name <circuit> --resource-group <rg>
Circuit status: Verify ExpressRoute circuit shows "Provisioned" (provider side) and "Enabled" (Azure side). "NotProvisioned" means the provider has not completed circuit setup — no traffic will flow.
BGP peering state: Check Azure Private Peering and Microsoft Peering BGP session state. State should be "Connected" — "Idle" or "Active" without "Connected" indicates peering negotiation failure (ASN mismatch, VLAN ID mismatch, or provider issue).
Advertised routes: Verify on-premises routes are visible in Azure via az network express-route list-route-tables and Azure VNet routes are advertised back to on-premises. Missing routes cause silent traffic drops.
VPN Gateway:
az network vpn-connection show --name <conn> --resource-group <rg>
Connection status: Should show "Connected". "Connecting" indicates IKE/IPsec parameter mismatch.
Gateway SKU: Basic SKU lacks BGP and zone-redundancy. VpnGw2+ recommended for production.
VNet Peering:
az network vnet peering list --vnet-name <vnet> --resource-group <rg> --output table
Peering state: Both sides must show "Connected". "Initiated" means reciprocal peering missing.
Transit settings:AllowGatewayTransit on hub and UseRemoteGateways on spoke enable shared ExpressRoute/VPN. Verify settings match hub-spoke intent.
Address space overlap: VNet Peering requires non-overlapping address spaces. Compare both VNets.
Forwarded traffic:AllowForwardedTraffic must be enabled on both peering links for transit routing through Azure Firewall in the hub.
Show full SKILL.md (606 more words)Show less
Step 5: UDR and Routing Validation
Audit User-Defined Routes for correctness, forced tunneling, and conflicts.
az network route-table list --output table
az network route-table route list --route-table-name <rt> --resource-group <rg>
az network nic show-effective-route-table --name <nic> --resource-group <rg>
Forced tunneling: UDRs with 0.0.0.0/0 next-hop to Azure Firewall or NVA force internet traffic through inspection. Verify forced tunneling is NOT applied to AzureFirewallSubnet, GatewaySubnet, or AzureBastionSubnet.
Asymmetric routing: Inbound via ExpressRoute but return via Azure Firewall UDR causes asymmetry. Verify UDR next-hop addresses match expected traffic paths in both directions.
Effective routes per NIC: Azure resolves UDR > BGP > system routes. Use az network nic show-effective-route-table for final effective routes.
BGP route propagation: UDR tables can disable BGP propagation (disableBgpRoutePropagation). When disabled, ExpressRoute/VPN routes are not injected. Verify this matches routing design.
Next-hop validation: UDR routes to virtual appliance IPs must reference running, healthy NVAs or Azure Firewall. A stopped VM next-hop creates a silent black hole.
Step 6: Report and Optimization
Compile findings and identify resource optimization opportunities.
az network nic list --query "[?virtualMachine==null]" --output table
az network public-ip list --query "[?ipConfiguration==null]" --output table
Orphaned NICs: NICs not attached to a VM — common after deletions. Each may have NSG rules and private IPs consuming address space.
Unassociated public IPs: Standard SKU public IPs incur charges when unassociated. Release or associate.
If Network Watcher NSG Flow Logs are not configured, traffic visibility is
limited to NSG hit counts. NSG Flow Logs require Network Watcher enabled
and a storage account. Version 2 includes throughput data. Document
missing Flow Logs as High.
Effective Security Rules Show Unexpected Allows
Use az network nic show-effective-nsg for combined subnet and NIC NSG
rules. Check for: higher-priority Allow in NIC NSG overriding subnet Deny,
default rules (65000+) permitting VNet-to-VNet traffic, or ASG membership
including unintended NICs.
ExpressRoute BGP Session Not Established
Verify VLAN ID matches between Azure and provider. Check BGP ASN matches
on-premises router. Use az network express-route peering show to compare
settings. Both primary and secondary should show "Connected".
VNet Peering Shows Initiated But Not Connected
Both peering links must be created. "Initiated" means only one side is
configured. Create the reciprocal link. Cross-subscription peering requires
RBAC on both subscriptions.
UDR Causing Asymmetric Routing
When ExpressRoute delivers inbound traffic directly but UDR routes return
traffic through Azure Firewall, asymmetric routing occurs — the firewall
drops return packets with no session state. Ensure UDR routes both
directions through the firewall, or configure Azure Firewall SNAT.
Azure Networking Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Azure Networking Audit compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Azure Networking Audit this skillLeoYeAI/openclaw-master-skills
Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR.
Plan, deploy, operate, and troubleshoot Azure Local (formerly Azure Stack HCI): sizing and prerequisites, Arc registration, lifecycle updates, workloads (Azure Local VMs, AKS on Azure Local, images…
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
How do I install Azure Networking Audit in Claude Code?
Run `npx skills add LeoYeAI/openclaw-master-skills --skill azure-networking-audit -a claude-code`. Or copy the skill folder (skills/azure-networking-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/azure-networking-audit in your project. Claude Code loads it when a task matches its description.
How do I install Azure Networking Audit in Codex?
Run `npx skills add LeoYeAI/openclaw-master-skills --skill azure-networking-audit -a codex`. Or copy the skill folder (skills/azure-networking-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/azure-networking-audit in your project. Codex loads it when a task matches its description.
Can I use Azure Networking Audit in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill azure-networking-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-networking-audit, .gemini/skills/azure-networking-audit, .github/skills/azure-networking-audit and .opencode/skills/azure-networking-audit in your project.
What does Azure Networking Audit need to run?
Going by SKILL.md and its folder, Azure Networking Audit needs the command-line tools its instructions call (az).
Does Azure Networking Audit access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Azure Networking Audit safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Azure Networking Audit use?
Azure Networking Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Azure Networking Audit use?
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.7k tokens, read only when the agent opens those files.
What are the alternatives to Azure Networking Audit?
Skills that share tags, products or a category with Azure Networking Audit: Azure Network Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Azure Firewall (vinayaklatthe/microsoft-security-skills, 175 stars), Defender For Containers (vinayaklatthe/microsoft-security-skills, 175 stars) and Defender For Iot (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Azure Networking Audit?
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.