Install the "cisco-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cisco-firewall-audit into .claude/skills/cisco-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cisco-firewall-audit", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "cisco-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cisco-firewall-audit into .agents/skills/cisco-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cisco-firewall-audit", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "cisco-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cisco-firewall-audit into .cursor/skills/cisco-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cisco-firewall-audit", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "cisco-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cisco-firewall-audit into .gemini/skills/cisco-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cisco-firewall-audit", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "cisco-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cisco-firewall-audit into .github/skills/cisco-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cisco-firewall-audit", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "cisco-firewall-audit" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/cisco-firewall-audit into .opencode/skills/cisco-firewall-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cisco-firewall-audit", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
cisco-firewall-audit
GitHub stars
2.2k
Token cost
~4.8k tokens
SKILL.md length
1,866 words
Files
4 (incl. references)
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0
At a glance
Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment…
Works in 6 steps: Platform Identification and Architecture… → Access Policy Analysis → NAT Policy Audit → …
Tasks that involve Authorization and RBAC
SKILL.md covers When to Use, Prerequisites, Procedure and Threshold Tables, plus 3 more sections
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Cisco Firewall Audit is an agent skill from LeoYeAI/openclaw-master-skills. Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment, VPN configuration review, and logging completeness verification.
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/cli-reference.md` and `references/policy-model.md`).
It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.
When your agent uses it
Tasks that involve Authorization and RBAC
Example prompts
“/cisco-firewall-audit”
Workflow steps
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Cisco Firewall Audit loads about 4.8k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 1,866 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~71
When it runs· the whole SKILL.md, loaded when a task matches
~4.8k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~11k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/cisco-firewall-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
cisco-firewall-audit
description
Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment, VPN configuration review, and logging completeness verification.
Policy-audit-driven analysis covering both Cisco ASA (classic) and Firepower
Threat Defense (FTD). Unlike generic firewall checklists that check for open
ports and default-deny, this skill evaluates the platform-specific security
architecture: ASA security levels with interface-bound ACLs and Modular
Policy Framework, or FTD Access Control Policy with Snort IPS integration
and Firepower Management Center (FMC) orchestration.
Where platforms diverge, sections use [ASA] and [FTD] labels.
Shared concepts apply to both platforms unlabeled. Covers ASA 9.x+ and
FTD 6.x+ / 7.x+ managed by FMC or FDM. Reference
references/policy-model.md for the ASA security-level model and FTD ACP
evaluation chain, and references/cli-reference.md for dual-platform
read-only commands.
When to Use
ACL review after rule changes or migration from ASA to FTD
Annual or quarterly compliance audit requiring per-rule justification
Post-incident rule assessment to identify how traffic was permitted
[ASA] Security level and interface ACL gap analysis
[FTD] Access Control Policy rule ordering and IPS coverage review
[FTD] Snort IPS policy tuning assessment — false positive vs detection gap balance
NAT policy validation after network re-addressing or migration
VPN configuration security review — site-to-site and remote access
Failover / HA posture verification
Pre-migration baseline before ASA-to-FTD conversion
Prerequisites
[ASA] Privilege level 5+ (read-only show commands) or ASDM read-only access
[FTD] Read-only analyst access to FMC web UI or FMC REST API; Expert shell access for Snort-level diagnostics
Understanding of the interface topology — which interfaces exist, their security levels ([ASA]), and network segment assignments
Knowledge of expected access policies per interface pair or zone
For multi-context ASA: access to system and each security context
[FTD] Knowledge of IPS policy baseline — which Snort ruleset and network analysis policy are expected
Active configuration — audit evaluates the running configuration, not pending changes
Procedure
Follow this audit flow sequentially. Each step builds on prior findings.
The procedure moves from platform identification through access policy,
NAT, inspection/IPS, VPN, and logging.
Step 1: Platform Identification and Architecture Inventory
Determine the platform and collect architectural baseline.
[ASA] Inventory interfaces, security levels, and context mode:
show interface ip brief
show nameif
show mode
Security levels (0–100) determine implicit traffic flow: traffic from a
higher security level to a lower is permitted by default (unless ACLs
override); lower-to-higher is denied by default. Record each interface
name, security level, and IP address.
For multi-context ASA:
show context
changeto context <name>
show interface ip brief
[FTD] Identify management model and registered devices:
show managers
FTD managed by FMC: policy is pushed from FMC — audit via FMC UI/API.
FTD managed by FDM (local): policy configured on-device — audit via
FDM web UI or REST API.
Check failover/HA status on both platforms:
show failover
show failover state
Record active/standby status, failover interface, and last failover time.
Step 2: Access Policy Analysis
[ASA] ACL-based access control:
show access-list
show running-config access-list
show running-config access-group
ASA uses interface-bound ACLs. Each ACL is applied inbound or outbound on
an interface via access-group. Evaluate:
ACL evaluation order: Top-down within each ACL. First matching ACE
(Access Control Entry) is applied. Implicit deny at the bottom.
Global ACL: If configured, applies to all interfaces. Interface ACLs
are evaluated before the global ACL.
Overly permissive ACEs:permit ip any any or permit tcp any any
entries are Critical findings — they permit all traffic of that protocol.
Unused ACEs: ACEs with zero hit counts (check show access-list
output for hitcnt=0) over 90+ days are cleanup candidates.
EtherType ACLs: Used on transparent firewall interfaces. Review for
overly broad EtherType permits.
show access-list <acl-name> brief
[FTD] Access Control Policy (ACP):
Access the ACP via FMC UI or REST API. The ACP evaluates traffic through
a defined chain (see references/policy-model.md). Evaluate:
Prefilter policy: Hardware-level rules that bypass Snort. Overly
broad prefilter Trust rules skip all inspection.
SSL policy: Determines which TLS flows are decrypted for inspection.
Access Control rules: Top-down evaluation. Actions: Allow (with or
without IPS), Trust (bypass Snort), Block, Monitor.
Rules with Action=Allow and no Intrusion Policy pass traffic without
IPS inspection.
Rules with Action=Trust bypass all further inspection including IPS
and file/malware — use only for verified trusted flows.
Default action: Applied when no rule matches. Should be Block with
logging, not Allow.
Intrusion Policy binding: Each Allow rule can bind an Intrusion
Policy (Snort ruleset). Rules without one pass traffic uninspected.
system support diagnostic-cli
show access-control-config
Step 3: NAT Policy Audit
[ASA] NAT order of operations:
show nat
show nat detail
show running-config nat
show xlate
ASA NAT evaluates in three sections:
Section 1 (Manual NAT / Twice NAT): Explicit rules, top-down. Highest
priority. Used for fine-grained control.
Section 2 (Auto NAT / Object NAT): Per-object NAT definitions.
Evaluated after Section 1. Ordering: static rules first, then dynamic.
Section 3 (Manual NAT after-auto): Low-priority manual rules evaluated
after auto NAT. Used for catch-all translations.
Check for NAT rule conflicts — a Section 1 rule that matches the same traffic
as a Section 2 object NAT always wins. Verify that static NAT entries for
published servers have corresponding ACL entries restricting access.
[FTD] NAT rules in FMC:
FTD NAT follows the same three-section model as ASA but is configured via
FMC. Review NAT rules in the FMC NAT policy. Verify:
Manual NAT rules take precedence over auto NAT
NAT rules align with ACP rules — ensure translated addresses match ACP
source/destination references
No unnecessary identity NAT rules consuming processing
Cross-reference NAT entries with access policy on both platforms — static NAT
that exposes internal servers must have restrictive access rules.
Step 4: Inspection and IPS Assessment
[ASA] Modular Policy Framework (MPF):
show running-config class-map
show running-config policy-map
show running-config service-policy
show service-policy
Default inspection: ASA enables inspection for common protocols
(HTTP, DNS, FTP, etc.) via the global_policy. Verify the global
policy is applied (service-policy global_policy global).
Custom inspections: Additional class-maps/policy-maps for specific
traffic patterns. Verify they are applied to correct interfaces.
Missing inspections: Traffic not matching any class-map in the
service-policy receives no application-layer inspection — only ACL
enforcement.
Connection limits: MPF can set connection limits and timeouts.
Review for overly permissive or missing connection limits on
internet-facing interfaces.
[FTD] Snort IPS and File/Malware policies:
Intrusion Policy: Each ACP Allow rule can reference an Intrusion
Policy that determines the Snort ruleset. Check that internet-facing
Allow rules bind an Intrusion Policy.
Snort rule sets: Verify the base policy (Balanced Security and
Connectivity, Connectivity Over Security, Security Over Connectivity,
Maximum Detection). For production environments, "Balanced Security
and Connectivity" is the minimum recommended baseline.
Network Analysis Policy (NAP): Controls protocol decoder settings
and preprocessor configuration. Misconfigured NAP can cause Snort
detection gaps.
File and Malware Policy: Detects and blocks malware file transfers.
Verify binding on rules permitting file-carrying protocols
(HTTP, SMTP, FTP, SMB).
Snort deployment mode: Inline (can block) vs passive (alert only).
Production deployments should use inline mode for active prevention.
system support diagnostic-cli
show snort statistics
Show full SKILL.md (774 more words)Show less
Step 5: VPN and Remote Access Audit
Evaluate VPN configuration security on both platforms.
show crypto ipsec sa
show crypto ikev2 sa
show vpn-sessiondb
Check:
Site-to-site tunnels: Verify IKE version (IKEv2 preferred over
IKEv1), encryption algorithms (AES-256-GCM recommended; DES/3DES are
findings), DH groups (group 14+ recommended; groups 1/2/5 are weak),
and PFS settings.
Crypto maps / tunnel groups:[ASA] Review crypto map entries
and tunnel group definitions. [FTD] Review site-to-site VPN
topology in FMC.
AnyConnect / remote access VPN: If configured, evaluate:
Authentication method (certificate + MFA preferred over password-only)
Split tunneling settings (full tunnel recommended for security;
split tunnel for performance — document the choice)
Connection profiles and group policies
Client certificate validation settings
Banner and session timeout configuration
show running-config tunnel-group
show running-config group-policy
IKE/IPSec SA lifetimes: Very long lifetimes (>24h IKE, >8h IPSec)
increase exposure if keys are compromised.
Step 6: Logging and Monitoring
Evaluate logging configuration and coverage.
[ASA] Syslog configuration:
show logging
show running-config logging
Syslog severity: Verify logging level is set to at least
"informational" (level 6) for security-relevant events. Level 5
(notifications) misses connection teardown events. Level 7 (debugging)
generates excessive volume.
Syslog destinations: Verify syslog server(s) are configured and
reachable. Check for encrypted syslog (TCP/TLS) for log integrity.
SNMP: If configured, verify community strings are not defaults and
SNMP v3 is used for authentication/encryption.
[FTD] Firepower event logging:
Connection events: In FMC, verify connection logging is enabled on
ACP rules. "Log at End of Connection" is standard; "Log at Beginning"
adds volume but provides immediate visibility.
Intrusion events: Automatically logged by Snort when rules trigger.
Verify events are forwarded to the SIEM.
eStreamer: The Firepower event streaming API for SIEM integration.
Verify eStreamer client connectivity if in use.
Security Analytics / SecureX: If integrated, verify telemetry
forwarding is active.
When evaluating an ASA for migration to FTD, document: ACL count, NAT rules,
MPF inspections, VPN configurations (crypto maps don't migrate directly),
and multi-context usage (FTD does not support multi-context). The Cisco
Firepower Migration Tool provides a baseline but audit the migrated policy
for accuracy — automated migration often produces suboptimal rule ordering.
Multi-Context ASA Audits
Each security context is an independent firewall with its own interfaces,
ACLs, NAT, and routing. Audit each context separately via
changeto context <name>. Use show context in the system context to
list all contexts and show resource allocation for per-context limits.
Large ACLs (>1000 ACEs)
Export the configuration (show running-config access-list) and parse
programmatically. Prioritize by hit count — high-hit-count ACEs carry
the most traffic. Zero-hit-count ACEs over 90 days are removal candidates.
FTD Diagnostic CLI
FTD runs Snort on top of an ASA-derived data plane. Use
system support diagnostic-cli for ASA-style show commands. The
canonical policy source is FMC — the diagnostic CLI shows deployed results.
Packet Tracer for Policy Verification
Both platforms support packet tracer for simulating traffic:
Cisco Firewall Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Cisco Firewall Audit compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Cisco Firewall Audit this skillLeoYeAI/openclaw-master-skills
Implements device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that…
Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP…
Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.
A skill your agent uses when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired…
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment…. Cisco Firewall Audit is an agent skill from LeoYeAI/openclaw-master-skills. Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment, VPN configuration review, and logging completeness verification.
When should I use Cisco Firewall Audit?
Cisco Firewall Audit fits situations like: tasks that involve Authorization and RBAC.
How do I install Cisco Firewall Audit in Claude Code?
Run `npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a claude-code`. Or copy the skill folder (skills/cisco-firewall-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/cisco-firewall-audit in your project. Claude Code loads it when a task matches its description.
How do I install Cisco Firewall Audit in Codex?
Run `npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a codex`. Or copy the skill folder (skills/cisco-firewall-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/cisco-firewall-audit in your project. Codex loads it when a task matches its description.
Can I use Cisco Firewall Audit in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cisco-firewall-audit, .gemini/skills/cisco-firewall-audit, .github/skills/cisco-firewall-audit and .opencode/skills/cisco-firewall-audit in your project.
What does Cisco Firewall Audit need to run?
SKILL.md names no scripts, command-line tools or credentials: Cisco Firewall Audit is instructions for the agent only.
Does Cisco Firewall Audit access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Cisco Firewall Audit safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Cisco Firewall Audit use?
Cisco Firewall Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Cisco Firewall Audit use?
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.7k tokens, read only when the agent opens those files.
What are the alternatives to Cisco Firewall Audit?
Skills that share tags, products or a category with Cisco Firewall Audit: Implementing Device Posture Assessment In Zero Trust (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Audit Recon (ccashwell/evm-cortex, 131 stars), Executing Nist Rmf Authorization To Operate (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Sec Check (waynesutton/markdown-site, 627 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Cisco Firewall Audit?
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.