Agent skill

Cis Benchmark Audit

by LeoYeAI in LeoYeAI/openclaw-master-skills

CIS benchmark compliance assessment for network infrastructure devices.

Apache-2.0Auto-check passedLegal & Compliance

Install Cis Benchmark Audit

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills cis-benchmark-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cis-benchmark-audit .claude/skills/cis-benchmark-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cis-benchmark-audit
GitHub stars
2.2k
Token cost
~4.1k tokens
SKILL.md length
1,599 words
Files
4 (incl. references)
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0

At a glance

CIS benchmark compliance assessment for network infrastructure devices.

  • Works in 6 steps: Platform Identification and Benchmark… → Management Plane Audit → Control Plane Audit → …
  • Legal & Compliance work in your project
  • SKILL.md covers When to Use, Prerequisites, Procedure and Threshold Tables, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cis Benchmark Audit is an agent skill from LeoYeAI/openclaw-master-skills. CIS benchmark compliance assessment for network infrastructure devices. Maps device configuration against CIS benchmark controls organized by Management Plane, Control Plane, and Data Plane categories across Cisco IOS, PAN-OS, JunOS, and Check Point platforms. References control IDs for traceability without reproducing copyrighted benchmark content.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/cli-reference.md` and `references/control-reference.md`).

It sits in Legal & Compliance. It works with iOS. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • Legal & Compliance work in your project

Example prompts

  • “/cis-benchmark-audit”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Platform Identification and Benchmark Selection
  2. Management Plane Audit
  3. Control Plane Audit
  4. Data Plane Audit
  5. Compliance Scoring and Gap Analysis
  6. Priority-Ranked Remediation Plan

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cis Benchmark Audit loads about 4.1k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 1,599 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 1,599 words, ~4,093 tokens.

Download SKILL.mdSave it as .claude/skills/cis-benchmark-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
cis-benchmark-audit
description
CIS benchmark compliance assessment for network infrastructure devices. Maps device configuration against CIS benchmark controls organized by Management Plane, Control Plane, and Data Plane categories across Cisco IOS, PAN-OS, JunOS, and Check Point platforms. References control IDs for traceability without reproducing copyrighted benchmark content.
license
Apache-2.0
metadata.safety
read-only
metadata.author
network-security-skills-suite
metadata.version
1.0.0
metadata.openclaw
{"emoji":"📋","safetyTier":"read-only","requires":{"bins":["ssh"],"env":[]},"tags":["cis","compliance","benchmark"],"mcpDependencies":[],"egressEndpoints":[]}

CIS Benchmark Compliance Audit

Compliance assessment skill that maps network device configuration against CIS benchmark controls. Organizes audit checks by Management Plane, Control Plane, and Data Plane — the three architectural layers CIS uses to structure network device benchmarks.

Covers the four platforms CIS publishes network device benchmarks for: Cisco IOS, PAN-OS, JunOS, and Check Point. The operator must obtain the applicable CIS benchmark document for their specific platform and version — this skill references CIS control IDs and section categories for traceability but does not reproduce copyrighted benchmark text, remediation steps, or rationale (see D026).

Consult references/control-reference.md for CIS control ID mappings to audit areas and references/cli-reference.md for per-platform read-only verification commands.

When to Use

  • Annual or quarterly CIS compliance audit against network infrastructure
  • Pre-audit preparation — building evidence collection before formal assessment
  • New device commissioning — establishing CIS compliance baseline on day one
  • Post-upgrade verification — confirming controls remain in place after OS upgrade
  • Regulatory compliance evidence — mapping CIS controls to PCI DSS, HIPAA, or SOX technical requirements via CIS crosswalk references
  • Merger/acquisition due diligence — assessing acquired network infrastructure against organizational CIS compliance posture

Prerequisites

  • Read-only CLI or API access to each target device (SSH, console, or management API with read-only administrative role)
  • The applicable CIS benchmark document for the target platform and OS version — operators must obtain their own licensed copy (e.g., "CIS Cisco IOS 16 Benchmark v1.1.0"). This skill references control IDs only
  • Understanding of the device's role in the network architecture — the device's position (edge, core, distribution, management) affects which controls apply and their priority
  • Awareness of any compensating controls already in place that satisfy CIS requirements through alternative mechanisms
  • Documentation of any accepted risk exceptions for controls intentionally not implemented

Procedure

Follow this six-step compliance assessment flow. Each step builds on prior findings. The procedure maps device configuration to CIS benchmark controls organized by management architecture layer.

Step 1: Platform Identification and Benchmark Selection

Identify the device platform, OS version, and hardware model. Select the matching CIS benchmark by ID and version.

[Cisco] show version — capture IOS/IOS-XE version, hardware model [PAN-OS] show system info — capture PAN-OS version, platform model [JunOS] show version — capture Junos OS version, hardware model [CheckPoint] fw ver and cpinfo -y all — capture Gaia OS version, platform

Record the exact benchmark ID that matches your platform version (e.g., "CIS Cisco IOS 16 Benchmark v1.1.0", "CIS Palo Alto Firewall 10 Benchmark v1.0.0"). If no benchmark exists for the exact OS version, use the closest available and document the version gap.

Determine the CIS profile level to assess against:

  • Level 1: Essential security controls, broadly applicable
  • Level 2: Defense-in-depth controls, may reduce functionality
Step 2: Management Plane Audit

Assess controls that protect device management access and monitoring. This covers CIS sections typically numbered 1.x and 2.x.

Local authentication and authorization:

[Cisco] show running-config | section aaa — verify AAA is enabled with TACACS+ or RADIUS, check that local fallback accounts use strong hashing (algorithm-type scrypt or secret 9).

[PAN-OS] show config running | match authentication — verify authentication profile binds to RADIUS/LDAP/SAML, check password complexity profile exists.

[JunOS] show configuration system authentication-order — verify TACACS+/RADIUS is primary with local fallback, check show configuration system login for account policies.

[CheckPoint] show configuration aaa — verify RADIUS/TACACS+ integration, check administrator account password policies.

SSH and management transport: Verify SSH v2 only (no SSHv1 or Telnet), session timeout configured, management access restricted to specific source addresses or management VLAN. Check certificate-based authentication where supported.

Logging and monitoring: Verify syslog is configured to a remote server with appropriate severity levels (informational minimum for security events), SNMP v3 with authentication and encryption (no v1/v2c with community strings), and NTP authentication to trusted time sources.

Login banners: Confirm legal notice/warning banners are configured on all management access methods (console, VTY, web UI).

Step 3: Control Plane Audit

Assess controls that protect routing and signaling protocols. CIS sections typically numbered 3.x.

Routing protocol authentication: Verify OSPF, BGP, and IS-IS neighbor authentication is enabled.

[Cisco] show ip ospf interface — check for authentication type (MD5 or SHA-256). show ip bgp neighbors — verify password is set per neighbor.

[PAN-OS] show routing protocol ospf area — verify area authentication. show routing protocol bgp peer — check MD5 authentication.

[JunOS] show ospf interface detail — verify authentication-type. show bgp neighbor — check authentication-key presence.

[CheckPoint] Routing configured via Gaia Clish: show route ospf with show configuration ospf for authentication settings.

Control Plane Protection: Verify rate limiting on management-bound traffic to prevent CPU exhaustion from packet floods targeting the control plane processor.

[Cisco] show policy-map control-plane — verify CoPP (Control Plane Policing) is applied with appropriate rate limits.

[JunOS] show firewall filter — verify loopback/lo0 filter protects the routing engine with rate-limit policers.

ARP and DHCP protection: Verify Dynamic ARP Inspection (DAI) and DHCP snooping on access-layer switches to prevent ARP spoofing and rogue DHCP attacks.

Step 4: Data Plane Audit

Assess controls that protect traffic forwarding. CIS sections typically numbered 4.x and 5.x.

Access control lists: Verify explicit deny rules with logging at ACL boundaries. Check that infrastructure ACLs protect device management addresses from data plane traffic.

Unicast Reverse Path Forwarding (uRPF):

[Cisco] show ip interface — check for ip verify unicast source reachable-via on external-facing interfaces.

[JunOS] show configuration interfaces — check for family inet rpf-check on upstream interfaces.

Anti-spoofing via uRPF validates source addresses against the routing table, dropping packets with forged source IPs.

Storm control and port security: Verify broadcast/multicast/unicast storm control thresholds on access ports. Check 802.1X or MAC-based authentication on edge ports where applicable.

Encryption: Verify management traffic encryption (SSH, HTTPS, SNMPv3). Assess MACsec for LAN encryption and IPsec for WAN links where required by organizational policy or CIS Level 2 controls.

Show full SKILL.md (666 more words)Show less
Step 5: Compliance Scoring and Gap Analysis

Tally results per CIS section and per architectural plane.

For each control tested, record:

  • Pass: Device configuration satisfies the control requirement
  • Fail: Device configuration does not meet the control requirement
  • Not Applicable: Control does not apply to this device role or deployment model (document justification)

Calculate compliance percentage per plane: Compliance % = (Pass / (Pass + Fail)) × 100 (exclude N/A from denominator)

Identify critical gaps — any Level 1 control failure in the Management Plane is a priority finding because it affects the security of all other controls (if management access is compromised, all other controls are bypassable).

Step 6: Priority-Ranked Remediation Plan

Order findings for remediation based on CIS control level and operational impact.

Priority 1 — Level 1 Management Plane failures: AAA bypass, cleartext management protocols, missing logging. These undermine all other controls.

Priority 2 — Level 1 Control/Data Plane failures: Unauthenticated routing protocols, missing ACLs, disabled uRPF. These allow traffic manipulation or spoofing.

Priority 3 — Level 2 Management Plane items: Enhanced encryption, additional monitoring, granular access controls. These add defense-in-depth.

Priority 4 — Level 2 Control/Data Plane items: CoPP fine-tuning, MACsec deployment, advanced storm control thresholds. These optimize existing protections.

Group remediation actions by effort:

  • Quick wins: Configuration commands that can be applied in a maintenance window without service impact
  • Planned changes: Items requiring change management, testing, or coordination with other teams
  • Projects: Items requiring infrastructure changes, new hardware, or significant design work

Threshold Tables

Compliance Violation Severity
SeverityCIS LevelConditionExamples
CriticalLevel 1 failManagement access without AAA or encryptionTelnet enabled, no AAA configuration, SNMP v1/v2c with default community, no remote logging configured
HighLevel 1 failPartial control implementation with gapsNTP configured but without authentication, SSH enabled but v1 not disabled, login banner missing on some access methods
MediumLevel 2 failDefense-in-depth control not implementedCoPP not configured, uRPF not enabled on external interfaces, storm control disabled on access ports
LowLevel 2Optional hardening not appliedCustom banner text not meeting organizational standard, SNMP informational traps not tuned, optional encryption on internal-only links
Compliance Posture Summary
Score RangePostureGuidance
90–100%StrongAddress remaining gaps in next maintenance cycle
70–89%ModeratePrioritize Level 1 failures, schedule Level 2 within quarter
50–69%WeakImmediate remediation plan required, escalate to management
<50%CriticalDevice may require isolation until baseline controls are applied

Decision Trees

Compliance Remediation Priority
CIS control finding: FAIL
├── Is it a Level 1 control?
│   ├── Yes
│   │   ├── Management Plane control?
│   │   │   ├── Yes → PRIORITY 1 (Critical/High)
│   │   │   │   ├── Is device internet-facing?
│   │   │   │   │   ├── Yes → Immediate remediation required
│   │   │   │   │   └── No → Remediate within 7 days
│   │   │   │   └── Is there a compensating control?
│   │   │   │       ├── Yes → Document compensating control, schedule fix
│   │   │   │       └── No → Escalate immediately
│   │   │   └── Control/Data Plane control?
│   │   │       └── PRIORITY 2 (High)
│   │   │           └── Remediate within 30 days
│   │   └── No (Level 2 control)
│   │       ├── Management Plane?
│   │       │   └── PRIORITY 3 (Medium)
│   │       │       └── Schedule within quarter
│   │       └── Control/Data Plane?
│   │           └── PRIORITY 4 (Low/Medium)
│   │               └── Schedule within next audit cycle
│
└── Control marked Not Applicable?
    ├── Justified? (deployment model, device role)
    │   ├── Yes → Document exception with approval
    │   └── No → Re-evaluate, may be a gap
Benchmark Version Selection
Identify target device OS version
├── Exact CIS benchmark version available?
│   ├── Yes → Use exact match
│   └── No → Use nearest lower version benchmark
│       ├── Gap > 2 major versions?
│       │   ├── Yes → Flag reduced coverage, request updated benchmark
│       │   └── No → Acceptable, note version delta in report
│       └── New OS features not covered by benchmark?
│           └── Document as out-of-scope for this assessment

Report Template

CIS BENCHMARK COMPLIANCE ASSESSMENT
======================================
Device: [hostname]
Platform: [Cisco IOS / PAN-OS / JunOS / Check Point]
OS Version: [version]
Device Role: [edge / core / distribution / access]
Audit Date: [timestamp]
Performed By: [operator/agent]

BENCHMARK REFERENCE:
- Benchmark ID: [e.g., CIS Cisco IOS 16 Benchmark v1.1.0]
- Profile Level Assessed: [Level 1 / Level 1+2]
- Note: Operator must obtain licensed copy for full control descriptions

COMPLIANCE SCORE BY PLANE:
  Management Plane: [n] pass / [n] fail / [n] N/A  ([%] compliant)
  Control Plane:    [n] pass / [n] fail / [n] N/A  ([%] compliant)
  Data Plane:       [n] pass / [n] fail / [n] N/A  ([%] compliant)
  Overall:          [n] pass / [n] fail / [n] N/A  ([%] compliant)

CRITICAL FINDINGS (Level 1 Failures):
1. [CIS Control ID] — [Config area] — [Finding summary]
   Plane: [Management/Control/Data]
   Current State: [what was observed]
   Impact: [operational risk]

HIGH FINDINGS (Level 1 Partial / Level 2 Critical):
1. [CIS Control ID] — [Config area] — [Finding summary]

REMEDIATION PLAN:
Priority 1 (Immediate — Level 1 Management Plane):
  - [Action] — [CIS Control ID] — [Estimated effort]

Priority 2 (30-day — Level 1 Control/Data Plane):
  - [Action] — [CIS Control ID] — [Estimated effort]

Priority 3 (Quarter — Level 2):
  - [Action] — [CIS Control ID] — [Estimated effort]

EXCEPTIONS AND COMPENSATING CONTROLS:
- [CIS Control ID] — [Reason for exception] — [Compensating control]

NEXT ASSESSMENT: [based on posture — Critical: 30d, Weak: 90d, Moderate: 180d, Strong: 365d]

Troubleshooting

Benchmark Version Mismatch

CIS benchmarks target specific OS versions. When the device runs a version not covered by any published benchmark, use the nearest available benchmark and document the gap. New features introduced after the benchmark's target version may not have corresponding controls — assess these independently.

Platform-Specific Configuration Locations

The same logical control (e.g., AAA configuration) exists in different configuration hierarchies per platform. Cisco IOS uses aaa new-model in global config, PAN-OS uses authentication profiles in device settings, JunOS uses system authentication-order, and Check Point uses SmartConsole or Gaia Clish. The references/cli-reference.md file provides the correct audit command per platform.

Controls Not Applicable to All Deployment Models

Some CIS controls assume a specific deployment model. For example, DHCP snooping controls apply to access-layer switches but not to core routers or firewalls. 802.1X controls apply to wired access ports but not to WAN interfaces. Document each N/A determination with a clear justification tied to the device's role in the network architecture.

Multi-Context and Virtual System Considerations

PAN-OS virtual systems (vsys), Cisco VDCs/VRFs, and JunOS logical systems create isolated administrative domains within a single physical device. Each virtual context should be assessed independently — controls in one context do not automatically apply to others. Inventory all contexts before beginning the audit with platform-specific enumeration commands.

Compensating Controls Documentation

When a CIS control cannot be implemented exactly as described but an equivalent protection exists, document the compensating control with: what CIS control it addresses, what alternative mechanism is in place, and why it provides equivalent or better protection. Accepted risk exceptions require management sign-off with a review date.

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/cis-benchmark-audit of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • _meta.json
  • references/cli-reference.md
  • references/control-reference.md

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Cis Benchmark Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cis Benchmark Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cis Benchmark Audit this skillLeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassApache-2.0
Search Contextinstructa/agent-skills139—~2.1kAutomated safety check: PassMIT
Mediationpoingstudios/godot-admob-plugin632—~2kAutomated safety check: PassMIT
Google Mobile Ads Validategoogle/skills21k—~603Automated safety check: PassApache-2.0
Consent Flowgustavscirulis/snapgrid1161 repos~2.6kAutomated safety check: NotesCustom licence
Managing Mobile App Consentmukul975/Privacy-Data-Protection-Skills301—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Search Context

    instructa/agent-skills

    Find, clone, inspect, and summarize high-quality GitHub reference repositories for coding agents.

    139 GitHub stars~2.1k tokensUpdated 11 days ago
    MobileAuto-check passed
  • Mediation

    poingstudios/godot-admob-plugin

    Create and maintain mediation network plugins (e.g., AppLovin, Vungle, Meta, IronSource) across Godot, C, Android, and iOS.

    632 GitHub stars~2k tokensUpdated 9 days ago
    Game DevelopmentAuto-check passed
  • Official

    Validates a project's Google Mobile Ads (GMA) SDK integration for iOS, Android, or Unity projects.

    21k GitHub stars~603 tokensUpdated today
    Backend & APIsAuto-check passed
  • Consent Flow

    gustavscirulis/snapgrid

    Generates GDPR/CCPA/DPDP privacy consent flows with granular category preferences, consent state persistence, audit logging, and ATT (App Tracking Transparency) integration.

    116 GitHub starsUsed in 1 repo~2.6k tokens
    Legal & ComplianceAuto-check: notes
  • Managing Mobile App Consent

    mukul975/Privacy-Data-Protection-Skills

    Guide for mobile-specific consent management covering Apple ATT framework for iOS, Android permission model, in-app consent flows, SDK consent propagation to third-party libraries, and IDFA/GAID…

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Legal & ComplianceAuto-check passed
  • iOS Security

    HoangNguyen0403/agent-skills-standard

    Secure iOS apps with secure storage, biometrics, and data protection.

    572 GitHub stars~500 tokensUpdated today
    MobileAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Cis Benchmark Audit

What does Cis Benchmark Audit do?

CIS benchmark compliance assessment for network infrastructure devices. Cis Benchmark Audit is an agent skill from LeoYeAI/openclaw-master-skills. CIS benchmark compliance assessment for network infrastructure devices.

When should I use Cis Benchmark Audit?

Cis Benchmark Audit fits situations like: legal & Compliance work in your project.

How do I install Cis Benchmark Audit in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a claude-code`. Or copy the skill folder (skills/cis-benchmark-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/cis-benchmark-audit in your project. Claude Code loads it when a task matches its description.

How do I install Cis Benchmark Audit in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a codex`. Or copy the skill folder (skills/cis-benchmark-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/cis-benchmark-audit in your project. Codex loads it when a task matches its description.

Can I use Cis Benchmark Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cis-benchmark-audit, .gemini/skills/cis-benchmark-audit, .github/skills/cis-benchmark-audit and .opencode/skills/cis-benchmark-audit in your project.

What does Cis Benchmark Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Cis Benchmark Audit is instructions for the agent only.

Does Cis Benchmark Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cis Benchmark Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cis Benchmark Audit use?

Cis Benchmark Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cis Benchmark Audit use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.

What are the alternatives to Cis Benchmark Audit?

Skills that share tags, products or a category with Cis Benchmark Audit: Search Context (instructa/agent-skills, 139 stars), Mediation (poingstudios/godot-admob-plugin, 632 stars), Google Mobile Ads Validate (google/skills, 21k stars) and Consent Flow (gustavscirulis/snapgrid, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cis Benchmark Audit?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.