Search Context
instructa/agent-skills
Find, clone, inspect, and summarize high-quality GitHub reference repositories for coding agents.
CIS benchmark compliance assessment for network infrastructure devices.
$ npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills cis-benchmark-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cis-benchmark-audit .claude/skills/cis-benchmark-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cis-benchmark-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cis-benchmark-audit into .claude/skills/cis-benchmark-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cis-benchmark-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cis-benchmark-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills cis-benchmark-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cis-benchmark-audit .agents/skills/cis-benchmark-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cis-benchmark-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cis-benchmark-audit into .agents/skills/cis-benchmark-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cis-benchmark-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills cis-benchmark-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cis-benchmark-audit .cursor/skills/cis-benchmark-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cis-benchmark-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cis-benchmark-audit into .cursor/skills/cis-benchmark-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cis-benchmark-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/cis-benchmark-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills cis-benchmark-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cis-benchmark-audit .gemini/skills/cis-benchmark-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cis-benchmark-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cis-benchmark-audit into .gemini/skills/cis-benchmark-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cis-benchmark-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills cis-benchmark-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cis-benchmark-audit .github/skills/cis-benchmark-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cis-benchmark-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cis-benchmark-audit into .github/skills/cis-benchmark-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cis-benchmark-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills cis-benchmark-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cis-benchmark-audit .opencode/skills/cis-benchmark-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cis-benchmark-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cis-benchmark-audit into .opencode/skills/cis-benchmark-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cis-benchmark-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cis-benchmark-auditCIS benchmark compliance assessment for network infrastructure devices.
Cis Benchmark Audit is an agent skill from LeoYeAI/openclaw-master-skills. CIS benchmark compliance assessment for network infrastructure devices. Maps device configuration against CIS benchmark controls organized by Management Plane, Control Plane, and Data Plane categories across Cisco IOS, PAN-OS, JunOS, and Check Point platforms. References control IDs for traceability without reproducing copyrighted benchmark content.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/cli-reference.md` and `references/control-reference.md`).
It sits in Legal & Compliance. It works with iOS. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cis Benchmark Audit loads about 4.1k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 1,599 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 1,599 words, ~4,093 tokens.
.claude/skills/cis-benchmark-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Compliance assessment skill that maps network device configuration against CIS benchmark controls. Organizes audit checks by Management Plane, Control Plane, and Data Plane — the three architectural layers CIS uses to structure network device benchmarks.
Covers the four platforms CIS publishes network device benchmarks for: Cisco IOS, PAN-OS, JunOS, and Check Point. The operator must obtain the applicable CIS benchmark document for their specific platform and version — this skill references CIS control IDs and section categories for traceability but does not reproduce copyrighted benchmark text, remediation steps, or rationale (see D026).
Consult references/control-reference.md for CIS control ID mappings to
audit areas and references/cli-reference.md for per-platform read-only
verification commands.
Follow this six-step compliance assessment flow. Each step builds on prior findings. The procedure maps device configuration to CIS benchmark controls organized by management architecture layer.
Identify the device platform, OS version, and hardware model. Select the matching CIS benchmark by ID and version.
[Cisco] show version — capture IOS/IOS-XE version, hardware model
[PAN-OS] show system info — capture PAN-OS version, platform model
[JunOS] show version — capture Junos OS version, hardware model
[CheckPoint] fw ver and cpinfo -y all — capture Gaia OS version, platform
Record the exact benchmark ID that matches your platform version (e.g., "CIS Cisco IOS 16 Benchmark v1.1.0", "CIS Palo Alto Firewall 10 Benchmark v1.0.0"). If no benchmark exists for the exact OS version, use the closest available and document the version gap.
Determine the CIS profile level to assess against:
Assess controls that protect device management access and monitoring. This covers CIS sections typically numbered 1.x and 2.x.
Local authentication and authorization:
[Cisco] show running-config | section aaa — verify AAA is enabled with
TACACS+ or RADIUS, check that local fallback accounts use strong hashing
(algorithm-type scrypt or secret 9).
[PAN-OS] show config running | match authentication — verify
authentication profile binds to RADIUS/LDAP/SAML, check password complexity
profile exists.
[JunOS] show configuration system authentication-order — verify
TACACS+/RADIUS is primary with local fallback, check show configuration system login for account policies.
[CheckPoint] show configuration aaa — verify RADIUS/TACACS+ integration,
check administrator account password policies.
SSH and management transport: Verify SSH v2 only (no SSHv1 or Telnet), session timeout configured, management access restricted to specific source addresses or management VLAN. Check certificate-based authentication where supported.
Logging and monitoring: Verify syslog is configured to a remote server with appropriate severity levels (informational minimum for security events), SNMP v3 with authentication and encryption (no v1/v2c with community strings), and NTP authentication to trusted time sources.
Login banners: Confirm legal notice/warning banners are configured on all management access methods (console, VTY, web UI).
Assess controls that protect routing and signaling protocols. CIS sections typically numbered 3.x.
Routing protocol authentication: Verify OSPF, BGP, and IS-IS neighbor authentication is enabled.
[Cisco] show ip ospf interface — check for authentication type
(MD5 or SHA-256). show ip bgp neighbors — verify password is set per
neighbor.
[PAN-OS] show routing protocol ospf area — verify area authentication.
show routing protocol bgp peer — check MD5 authentication.
[JunOS] show ospf interface detail — verify authentication-type.
show bgp neighbor — check authentication-key presence.
[CheckPoint] Routing configured via Gaia Clish: show route ospf with
show configuration ospf for authentication settings.
Control Plane Protection: Verify rate limiting on management-bound traffic to prevent CPU exhaustion from packet floods targeting the control plane processor.
[Cisco] show policy-map control-plane — verify CoPP (Control Plane
Policing) is applied with appropriate rate limits.
[JunOS] show firewall filter — verify loopback/lo0 filter protects
the routing engine with rate-limit policers.
ARP and DHCP protection: Verify Dynamic ARP Inspection (DAI) and DHCP snooping on access-layer switches to prevent ARP spoofing and rogue DHCP attacks.
Assess controls that protect traffic forwarding. CIS sections typically numbered 4.x and 5.x.
Access control lists: Verify explicit deny rules with logging at ACL boundaries. Check that infrastructure ACLs protect device management addresses from data plane traffic.
Unicast Reverse Path Forwarding (uRPF):
[Cisco] show ip interface — check for ip verify unicast source reachable-via on external-facing interfaces.
[JunOS] show configuration interfaces — check for family inet rpf-check
on upstream interfaces.
Anti-spoofing via uRPF validates source addresses against the routing table, dropping packets with forged source IPs.
Storm control and port security: Verify broadcast/multicast/unicast storm control thresholds on access ports. Check 802.1X or MAC-based authentication on edge ports where applicable.
Encryption: Verify management traffic encryption (SSH, HTTPS, SNMPv3). Assess MACsec for LAN encryption and IPsec for WAN links where required by organizational policy or CIS Level 2 controls.
Tally results per CIS section and per architectural plane.
For each control tested, record:
Calculate compliance percentage per plane:
Compliance % = (Pass / (Pass + Fail)) × 100 (exclude N/A from denominator)
Identify critical gaps — any Level 1 control failure in the Management Plane is a priority finding because it affects the security of all other controls (if management access is compromised, all other controls are bypassable).
Order findings for remediation based on CIS control level and operational impact.
Priority 1 — Level 1 Management Plane failures: AAA bypass, cleartext management protocols, missing logging. These undermine all other controls.
Priority 2 — Level 1 Control/Data Plane failures: Unauthenticated routing protocols, missing ACLs, disabled uRPF. These allow traffic manipulation or spoofing.
Priority 3 — Level 2 Management Plane items: Enhanced encryption, additional monitoring, granular access controls. These add defense-in-depth.
Priority 4 — Level 2 Control/Data Plane items: CoPP fine-tuning, MACsec deployment, advanced storm control thresholds. These optimize existing protections.
Group remediation actions by effort:
| Severity | CIS Level | Condition | Examples |
|---|---|---|---|
| Critical | Level 1 fail | Management access without AAA or encryption | Telnet enabled, no AAA configuration, SNMP v1/v2c with default community, no remote logging configured |
| High | Level 1 fail | Partial control implementation with gaps | NTP configured but without authentication, SSH enabled but v1 not disabled, login banner missing on some access methods |
| Medium | Level 2 fail | Defense-in-depth control not implemented | CoPP not configured, uRPF not enabled on external interfaces, storm control disabled on access ports |
| Low | Level 2 | Optional hardening not applied | Custom banner text not meeting organizational standard, SNMP informational traps not tuned, optional encryption on internal-only links |
| Score Range | Posture | Guidance |
|---|---|---|
| 90–100% | Strong | Address remaining gaps in next maintenance cycle |
| 70–89% | Moderate | Prioritize Level 1 failures, schedule Level 2 within quarter |
| 50–69% | Weak | Immediate remediation plan required, escalate to management |
| <50% | Critical | Device may require isolation until baseline controls are applied |
CIS control finding: FAIL
├── Is it a Level 1 control?
│ ├── Yes
│ │ ├── Management Plane control?
│ │ │ ├── Yes → PRIORITY 1 (Critical/High)
│ │ │ │ ├── Is device internet-facing?
│ │ │ │ │ ├── Yes → Immediate remediation required
│ │ │ │ │ └── No → Remediate within 7 days
│ │ │ │ └── Is there a compensating control?
│ │ │ │ ├── Yes → Document compensating control, schedule fix
│ │ │ │ └── No → Escalate immediately
│ │ │ └── Control/Data Plane control?
│ │ │ └── PRIORITY 2 (High)
│ │ │ └── Remediate within 30 days
│ │ └── No (Level 2 control)
│ │ ├── Management Plane?
│ │ │ └── PRIORITY 3 (Medium)
│ │ │ └── Schedule within quarter
│ │ └── Control/Data Plane?
│ │ └── PRIORITY 4 (Low/Medium)
│ │ └── Schedule within next audit cycle
│
└── Control marked Not Applicable?
├── Justified? (deployment model, device role)
│ ├── Yes → Document exception with approval
│ └── No → Re-evaluate, may be a gapIdentify target device OS version
├── Exact CIS benchmark version available?
│ ├── Yes → Use exact match
│ └── No → Use nearest lower version benchmark
│ ├── Gap > 2 major versions?
│ │ ├── Yes → Flag reduced coverage, request updated benchmark
│ │ └── No → Acceptable, note version delta in report
│ └── New OS features not covered by benchmark?
│ └── Document as out-of-scope for this assessmentCIS BENCHMARK COMPLIANCE ASSESSMENT
======================================
Device: [hostname]
Platform: [Cisco IOS / PAN-OS / JunOS / Check Point]
OS Version: [version]
Device Role: [edge / core / distribution / access]
Audit Date: [timestamp]
Performed By: [operator/agent]
BENCHMARK REFERENCE:
- Benchmark ID: [e.g., CIS Cisco IOS 16 Benchmark v1.1.0]
- Profile Level Assessed: [Level 1 / Level 1+2]
- Note: Operator must obtain licensed copy for full control descriptions
COMPLIANCE SCORE BY PLANE:
Management Plane: [n] pass / [n] fail / [n] N/A ([%] compliant)
Control Plane: [n] pass / [n] fail / [n] N/A ([%] compliant)
Data Plane: [n] pass / [n] fail / [n] N/A ([%] compliant)
Overall: [n] pass / [n] fail / [n] N/A ([%] compliant)
CRITICAL FINDINGS (Level 1 Failures):
1. [CIS Control ID] — [Config area] — [Finding summary]
Plane: [Management/Control/Data]
Current State: [what was observed]
Impact: [operational risk]
HIGH FINDINGS (Level 1 Partial / Level 2 Critical):
1. [CIS Control ID] — [Config area] — [Finding summary]
REMEDIATION PLAN:
Priority 1 (Immediate — Level 1 Management Plane):
- [Action] — [CIS Control ID] — [Estimated effort]
Priority 2 (30-day — Level 1 Control/Data Plane):
- [Action] — [CIS Control ID] — [Estimated effort]
Priority 3 (Quarter — Level 2):
- [Action] — [CIS Control ID] — [Estimated effort]
EXCEPTIONS AND COMPENSATING CONTROLS:
- [CIS Control ID] — [Reason for exception] — [Compensating control]
NEXT ASSESSMENT: [based on posture — Critical: 30d, Weak: 90d, Moderate: 180d, Strong: 365d]CIS benchmarks target specific OS versions. When the device runs a version not covered by any published benchmark, use the nearest available benchmark and document the gap. New features introduced after the benchmark's target version may not have corresponding controls — assess these independently.
The same logical control (e.g., AAA configuration) exists in different
configuration hierarchies per platform. Cisco IOS uses aaa new-model in
global config, PAN-OS uses authentication profiles in device settings, JunOS
uses system authentication-order, and Check Point uses SmartConsole or
Gaia Clish. The references/cli-reference.md file provides the correct
audit command per platform.
Some CIS controls assume a specific deployment model. For example, DHCP snooping controls apply to access-layer switches but not to core routers or firewalls. 802.1X controls apply to wired access ports but not to WAN interfaces. Document each N/A determination with a clear justification tied to the device's role in the network architecture.
PAN-OS virtual systems (vsys), Cisco VDCs/VRFs, and JunOS logical systems create isolated administrative domains within a single physical device. Each virtual context should be assessed independently — controls in one context do not automatically apply to others. Inventory all contexts before beginning the audit with platform-specific enumeration commands.
When a CIS control cannot be implemented exactly as described but an equivalent protection exists, document the compensating control with: what CIS control it addresses, what alternative mechanism is in place, and why it provides equivalent or better protection. Accepted risk exceptions require management sign-off with a review date.
© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/cis-benchmark-audit of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
Cis Benchmark Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cis Benchmark Audit this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Search Contextinstructa/agent-skills | 139 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Mediationpoingstudios/godot-admob-plugin | 632 | — | ~2k | Automated safety check: Pass | MIT | |
| Google Mobile Ads Validategoogle/skills | 21k | — | ~603 | Automated safety check: Pass | Apache-2.0 | |
| Consent Flowgustavscirulis/snapgrid | 116 | 1 repos | ~2.6k | Automated safety check: Notes | Custom licence | |
| Managing Mobile App Consentmukul975/Privacy-Data-Protection-Skills | 301 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 |
instructa/agent-skills
Find, clone, inspect, and summarize high-quality GitHub reference repositories for coding agents.
poingstudios/godot-admob-plugin
Create and maintain mediation network plugins (e.g., AppLovin, Vungle, Meta, IronSource) across Godot, C, Android, and iOS.
google/skills
Validates a project's Google Mobile Ads (GMA) SDK integration for iOS, Android, or Unity projects.
gustavscirulis/snapgrid
Generates GDPR/CCPA/DPDP privacy consent flows with granular category preferences, consent state persistence, audit logging, and ATT (App Tracking Transparency) integration.
mukul975/Privacy-Data-Protection-Skills
Guide for mobile-specific consent management covering Apple ATT framework for iOS, Android permission model, in-app consent flows, SDK consent propagation to third-party libraries, and IDFA/GAID…
HoangNguyen0403/agent-skills-standard
Secure iOS apps with secure storage, biometrics, and data protection.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Works with
Categories
CIS benchmark compliance assessment for network infrastructure devices. Cis Benchmark Audit is an agent skill from LeoYeAI/openclaw-master-skills. CIS benchmark compliance assessment for network infrastructure devices.
Cis Benchmark Audit fits situations like: legal & Compliance work in your project.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a claude-code`. Or copy the skill folder (skills/cis-benchmark-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/cis-benchmark-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a codex`. Or copy the skill folder (skills/cis-benchmark-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/cis-benchmark-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill cis-benchmark-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cis-benchmark-audit, .gemini/skills/cis-benchmark-audit, .github/skills/cis-benchmark-audit and .opencode/skills/cis-benchmark-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Cis Benchmark Audit is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cis Benchmark Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Cis Benchmark Audit: Search Context (instructa/agent-skills, 139 stars), Mediation (poingstudios/godot-admob-plugin, 632 stars), Google Mobile Ads Validate (google/skills, 21k stars) and Consent Flow (gustavscirulis/snapgrid, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.