Firewall Config
sickn33/agentic-awesome-skills
Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills.
Check Point R80+/R81.x rulebase layer analysis with blade activation audit, SmartConsole management plane validation, NAT policy review, identity awareness assessment, and compliance verification.
$ npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills checkpoint-firewall-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/checkpoint-firewall-audit .claude/skills/checkpoint-firewall-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "checkpoint-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/checkpoint-firewall-audit into .claude/skills/checkpoint-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checkpoint-firewall-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/checkpoint-firewall-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills checkpoint-firewall-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/checkpoint-firewall-audit .agents/skills/checkpoint-firewall-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "checkpoint-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/checkpoint-firewall-audit into .agents/skills/checkpoint-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checkpoint-firewall-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills checkpoint-firewall-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/checkpoint-firewall-audit .cursor/skills/checkpoint-firewall-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "checkpoint-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/checkpoint-firewall-audit into .cursor/skills/checkpoint-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checkpoint-firewall-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/checkpoint-firewall-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills checkpoint-firewall-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/checkpoint-firewall-audit .gemini/skills/checkpoint-firewall-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "checkpoint-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/checkpoint-firewall-audit into .gemini/skills/checkpoint-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checkpoint-firewall-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills checkpoint-firewall-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/checkpoint-firewall-audit .github/skills/checkpoint-firewall-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "checkpoint-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/checkpoint-firewall-audit into .github/skills/checkpoint-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checkpoint-firewall-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills checkpoint-firewall-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/checkpoint-firewall-audit .opencode/skills/checkpoint-firewall-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "checkpoint-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/checkpoint-firewall-audit into .opencode/skills/checkpoint-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "checkpoint-firewall-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
checkpoint-firewall-auditCheck Point R80+/R81.x rulebase layer analysis with blade activation audit, SmartConsole management plane validation, NAT policy review, identity awareness assessment, and compliance verification.
Checkpoint Firewall Audit is an agent skill from LeoYeAI/openclaw-master-skills. Check Point R80+/R81.x rulebase layer analysis with blade activation audit, SmartConsole management plane validation, NAT policy review, identity awareness assessment, and compliance verification. Systematic layer-by-layer evaluation for Check Point Security Gateways managed via Management Server or Multi-Domain Server (MDS).
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/cli-reference.md` and `references/policy-model.md`).
The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Checkpoint Firewall Audit loads about 4.5k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 1,684 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 1,684 words, ~4,492 tokens.
.claude/skills/checkpoint-firewall-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Policy-audit-driven analysis of Check Point Security Gateway policies. Unlike generic firewall checklists that check for open ports and default-deny, this skill evaluates the Check Point-specific security architecture: rulebase ordered and inline layers, Software Blade activation coverage, management plane trust (SIC), and the Unified Policy model introduced in R80+.
Covers R80.x and R81.x gateways managed via SmartConsole connected to a
Security Management Server or Multi-Domain Server (MDS). Reference
references/policy-model.md for the R80+ architecture and layer model,
and references/cli-reference.md for read-only CLI and API commands.
mgmt_cli / Web API)fw, cpstat, and cpview commands (Expert mode)Follow this audit flow sequentially. Each step builds on prior findings. The procedure moves from management architecture through rulebase layer analysis to blade activation, NAT, identity, and compliance verification.
Map the management plane topology.
cpstat mg
mgmt_cli show gateways-and-servers --format json -r trueRecord: Management Server hostname and version, Log Server(s), Security Gateway(s) with version and SIC status. In MDS environments, list all domains and their assigned gateways.
Verify SIC trust between Management Server and each gateway:
cpstat sic
fw statSIC (Secure Internal Communication) trust must be established for policy installation and log forwarding. A gateway with SIC status other than "Trust established" cannot receive policy updates — stale policy is a Critical finding.
For Multi-Domain deployments, verify domain isolation:
mdsstatEach domain should be an independent management container. Cross-domain policy leakage indicates architecture misconfiguration.
Check Management Server disk space and health — a full log partition prevents logging:
cpstat os -f disk
cpviewR80+ uses a Unified Policy model with ordered layers. Each layer is an independent rulebase evaluated sequentially.
mgmt_cli show access-rulebase name "Network" --format json -r trueRetrieve each access layer and evaluate:
enabled: false consume rulebase space
but do not evaluate. Flag for cleanup.mgmt_cli show access-rulebase name "Network" details-level full --format json -r trueUse details-level full to retrieve source, destination, service, action,
track, and profile bindings for each rule.
Check Point Software Blades provide security functions. Each blade must be licensed and enabled per gateway.
cpstat blades
cpstat fwVerify activation status for each blade on every gateway:
| Blade | Function | Expected On |
|---|---|---|
| Firewall | Stateful packet inspection | All gateways |
| IPS | Intrusion prevention signatures | Internet-facing gateways |
| Application Control | Application identification and enforcement | Internet-facing gateways |
| URL Filtering | URL categorization and blocking | Gateways with user web traffic |
| Anti-Bot | Bot C2 communication detection | All gateways |
| Anti-Virus | File-based malware scanning | All gateways |
| Threat Emulation | Sandbox analysis for unknown files | Internet-facing gateways |
| Threat Extraction | Content disarm and reconstruction | Email/download gateways |
| Content Awareness | Data visibility and DLP | Gateways handling sensitive data |
| HTTPS Inspection | TLS decryption for content inspection | Internet-facing gateways |
Compare licensed blades (contract entitlement) against enabled blades. Licensed but disabled blades represent undeployed security capability. Enabled but unlicensed blades will stop functioning on license expiry.
cpstat licenseStat
cplic printCheck Threat Prevention profiles assigned to rules — blades are only effective when both enabled on the gateway AND referenced in policy rules via a Threat Prevention profile.
Check Point supports two NAT methods: Automatic NAT (per-object) and Manual NAT (explicit rulebase).
mgmt_cli show nat-rulebase --format json -r trueEvaluate NAT policy:
Verify that NAT does not expose internal addressing or create unintended access paths. Cross-reference static NAT entries with security policy rules.
If Identity Awareness blade is enabled, evaluate the identity integration.
pdp status stat
mgmt_cli show access-roles --format json -r trueCheck:
Verify log infrastructure and compliance monitoring.
cpstat logging
fw log -tCheck:
cpstat antimalware
cpstat appiVerify Threat Prevention signature databases are current:
| Database | Maximum Age | Check |
|---|---|---|
| IPS signatures | 7 days | cpstat ips |
| Application Control DB | 7 days | cpstat appi |
| Anti-Bot signatures | 24 hours | cpstat antimalware |
| Anti-Virus signatures | 24 hours | cpstat antimalware |
| URL Filtering DB | 7 days | cpstat urlf |
| Finding | Severity | Rationale |
|---|---|---|
| Source=Any, Destination=Any, Service=Any, Action=Accept | Critical | Fully open rule — permits all traffic within the layer |
| Gateway SIC trust not established | Critical | Gateway cannot receive policy updates; running stale policy |
| Licensed blades not enabled on internet-facing gateway | High | Purchased security capability not deployed |
| Rule with Action=Accept and no Threat Prevention profile | High | Traffic passes without IPS, Anti-Bot, or AV inspection |
| HTTPS Inspection not enabled on internet-bound traffic | High | Encrypted traffic bypasses content inspection blades |
| Threat Prevention signatures >7 days old | High | Detection gap for recently discovered threats |
| Missing Stealth rule (no rule protecting gateway itself) | High | Gateway management plane exposed to data-plane traffic |
| Manual NAT rule conflicts with Automatic NAT | Medium | Unexpected NAT behavior; traffic may not translate as intended |
| Rules with zero hit count >90 days | Medium | Unused rules — cleanup candidates |
| Disabled rules in production layer | Medium | Audit confusion; stale configuration |
| Track=None on Drop/Reject rule | Medium | Security-relevant denied traffic not logged |
| Identity Awareness source connectivity failure | Medium | Identity-based rules unable to match users; fallback behavior |
| Log Server connectivity intermittent | Medium | Log gaps reduce incident investigation capability |
| Implicit cleanup rule handling all denied traffic | Low | Expected behavior, but verify logging is enabled |
| Coverage | Maturity | Guidance |
|---|---|---|
| All licensed blades enabled + profiles in policy | Mature | Maintain; review profile settings quarterly |
| Blades enabled but profiles not referenced in rules | Developing | Bind Threat Prevention profiles to all Accept rules |
| Licensed blades not enabled | Immature | Enable blades and create Threat Prevention profiles |
Rule has Source=Any, Destination=Any, Service=Any
├── Action = Accept?
│ ├── Yes → CRITICAL: Fully open rule
│ │ ├── Is this a temporary migration rule?
│ │ │ ├── Yes → Set expiration, add to migration tracker
│ │ │ └── No → Immediate remediation required
│ │ └── Identify actual traffic via SmartLog:
│ │ Filter by rule number → analyze source/dest/service
│ │ → Replace with specific objects and services
│ └── No (Drop/Reject) → This is the cleanup rule; verify Track=Log
│
├── Threat Prevention profile bound?
│ ├── No → Bind profile BEFORE narrowing rule scope
│ │ └── Ensures threat visibility during migration
│ └── Yes → Proceed with scope reduction
│
└── Rule in ordered layer or inline layer?
├── Ordered layer → Affects all traffic in that layer
└── Inline layer → Scoped to parent rule match
└── Check parent rule scope to assess true exposureGateway missing expected blades
├── Blade licensed?
│ ├── No → Procurement required; document risk until enabled
│ └── Yes → Enable blade in SmartConsole gateway object
│ ├── IPS → Assign IPS profile; set to Prevent mode
│ ├── Application Control → Create/assign App Control policy
│ ├── Anti-Bot → Assign profile; enable in Threat Prevention
│ ├── Anti-Virus → Assign profile; enable in Threat Prevention
│ ├── Threat Emulation → Assign profile; select emulation env
│ ├── HTTPS Inspection → Configure CA cert + inspection policy
│ └── URL Filtering → Assign categorization profile
│
├── Performance concern?
│ ├── SecureXL acceleration enabled? → Verify blade compatibility
│ └── CoreXL CPU allocation → Check SNDs and FW workers balance
│ cpstat os -f multi_cpu
│
└── After enabling → Install policy and verify blade active:
cpstat blades -f blade_nameCHECK POINT SECURITY POLICY AUDIT REPORT
==========================================
Management Server: [hostname] [version]
Gateway(s): [hostname(s)] [version(s)]
Domain: [domain name (MDS) / N/A (SMS)]
Policy Name: [installed policy name]
Audit Date: [timestamp]
Performed By: [operator/agent]
MANAGEMENT ARCHITECTURE:
- Management Server: [hostname] R[version]
- Log Server: [hostname(s)]
- Gateways: [count] ([list with SIC status])
- MDS domains: [count or N/A]
RULEBASE LAYER SUMMARY:
- Ordered layers: [count] ([layer names])
- Total rules across layers: [count]
- Accept rules: [n] | Drop rules: [n] | Inline layers: [n]
- Rules with Threat Prevention profiles: [n] / [accept count]
- Rules with zero hits (>90d): [count]
- Disabled rules: [count]
BLADE ACTIVATION:
Per Gateway: [gateway name]
- Licensed blades: [list]
- Enabled blades: [list]
- Gap: [licensed but not enabled]
NAT SUMMARY:
- Manual NAT rules: [count]
- Automatic NAT objects: [count]
- Static NAT entries: [count]
- Conflicting rules identified: [count or none]
IDENTITY AWARENESS:
- Identity sources: [list with status]
- Access roles in policy: [count]
- Coverage gaps: [segments without identity]
FINDINGS:
1. [Severity] [Category] — [Description]
Layer: [layer name]
Rule Number: [n]
Issue: [specific problem]
Current Config: [what the rule does now]
Recommendation: [specific remediation]
SIGNATURE CURRENCY:
- IPS: [version] ([age])
- App Control: [version] ([age])
- Anti-Bot: [version] ([age])
- Anti-Virus: [version] ([age])
RECOMMENDATIONS:
- [Prioritized action list by severity]
NEXT AUDIT: [CRITICAL: 30d, HIGH: 90d, clean: 180d]Auditing rulebases with hundreds of rules across multiple ordered layers
is impractical via SmartConsole alone. Use the Management API to export
all layers programmatically:
mgmt_cli show access-rulebase name "<layer>" details-level full --format json -r true
Iterate over all layers and merge into a single dataset for automated
shadow detection, profile gap analysis, and hit count review.
In MDS deployments, each domain is an isolated management container. The auditor must connect to each domain separately (or use the MDS-level API with domain context). Policy in one domain does not affect another — but verify that cross-domain traffic paths have consistent policies on both domain gateways.
If a gateway shows "Policy out of date" in SmartConsole, the running policy
may not match the current rulebase. Use fw stat on the gateway to see
the installed policy name and timestamp. Compare with SmartConsole to
identify the delta. Audit findings should be based on the installed policy,
not the pending session.
SecureXL accelerates traffic by bypassing full inspection for established
sessions. Some blades (especially IPS and Threat Emulation) require traffic
to pass through the Firewall kernel (Medium Path or Firewall Path), not
the accelerated path. Verify SecureXL template status:
fwaccel stat and fwaccel templates -S
Templates that match security-sensitive traffic and bypass blade inspection
are a finding.
In ClusterXL (HA) deployments, verify both members run the same policy
version and software release. In VSX (Virtual System Extension) deployments,
each virtual system has independent policy — audit each VS separately.
Use vsx stat -v to list virtual systems.
© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/checkpoint-firewall-audit of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
Checkpoint Firewall Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Checkpoint Firewall Audit this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Firewall Configsickn33/agentic-awesome-skills | 47k | 2 repos | ~3.2k | Automated safety check: Notes | MIT | |
| Checkpoint Promotionwshobson/agents | 40k | — | ~2k | Automated safety check: Pass | MIT | |
| Checkpointpedrohcgs/claude-code-my-workflow | 1.7k | — | ~2.8k | Automated safety check: Notes | MIT | |
| Implementing GCP Vpc Firewall Rulesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Checkpointcodewithmukesh/dotnet-claude-kit | 755 | — | ~817 | Automated safety check: Notes | MIT |
sickn33/agentic-awesome-skills
Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills.
wshobson/agents
Gate fine-tuned checkpoints with drift budgets, paired comparison, and forgetting checks before promotion.
pedrohcgs/claude-code-my-workflow
Save a structured state snapshot before stopping or handing off.
mukul975/Anthropic-Cybersecurity-Skills
Implements and audits GCP VPC firewall rules using gcloud, covering auditing overly permissive rules, creating restrictive ingress/egress rules, hierarchical firewall policies, and monitoring rule…
codewithmukesh/dotnet-claude-kit
Mid-session save point: create a descriptive git commit and a brief handoff note, then keep working.
automateyournetwork/netclaw
Inspect Check Point security policies, threat intelligence, gateways, and SASE through its MCP integrations.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Check Point R80+/R81.x rulebase layer analysis with blade activation audit, SmartConsole management plane validation, NAT policy review, identity awareness assessment, and compliance verification. Checkpoint Firewall Audit is an agent skill from LeoYeAI/openclaw-master-skills.x rulebase layer analysis with blade activation audit, SmartConsole management plane validation, NAT policy review, identity awareness assessment, and compliance verification.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a claude-code`. Or copy the skill folder (skills/checkpoint-firewall-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/checkpoint-firewall-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a codex`. Or copy the skill folder (skills/checkpoint-firewall-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/checkpoint-firewall-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill checkpoint-firewall-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/checkpoint-firewall-audit, .gemini/skills/checkpoint-firewall-audit, .github/skills/checkpoint-firewall-audit and .opencode/skills/checkpoint-firewall-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Checkpoint Firewall Audit is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Checkpoint Firewall Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Checkpoint Firewall Audit: Firewall Config (sickn33/agentic-awesome-skills, 47k stars), Checkpoint Promotion (wshobson/agents, 40k stars), Checkpoint (pedrohcgs/claude-code-my-workflow, 1.7k stars) and Implementing GCP Vpc Firewall Rules (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.