Agent skill

Cisco Firewall Audit

by LeoYeAI in LeoYeAI/openclaw-master-skills

Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment…

Apache-2.0Auto-check passedBackend & APIs

Install Cisco Firewall Audit

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills cisco-firewall-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cisco-firewall-audit .claude/skills/cisco-firewall-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cisco-firewall-audit
GitHub stars
2.2k
Token cost
~4.8k tokens
SKILL.md length
1,866 words
Files
4 (incl. references)
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0

At a glance

Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment…

  • Works in 6 steps: Platform Identification and Architecture… → Access Policy Analysis → NAT Policy Audit → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers When to Use, Prerequisites, Procedure and Threshold Tables, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cisco Firewall Audit is an agent skill from LeoYeAI/openclaw-master-skills. Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment, VPN configuration review, and logging completeness verification.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/cli-reference.md` and `references/policy-model.md`).

It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Authorization and RBAC

Example prompts

  • “/cisco-firewall-audit”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Platform Identification and Architecture Inventory
  2. Access Policy Analysis
  3. NAT Policy Audit
  4. Inspection and IPS Assessment
  5. VPN and Remote Access Audit
  6. Logging and Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cisco Firewall Audit loads about 4.8k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 71 tokens; SKILL.md has 1,866 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 1,866 words, ~4,811 tokens.

Download SKILL.mdSave it as .claude/skills/cisco-firewall-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
cisco-firewall-audit
description
Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment, VPN configuration review, and logging completeness verification.
license
Apache-2.0
metadata.safety
read-only
metadata.author
network-security-skills-suite
metadata.version
1.0.0
metadata.openclaw
{"emoji":"🛡️","safetyTier":"read-only","requires":{"bins":["ssh"],"env":[]},"tags":["cisco","asa","ftd","firewall"],"mcpDependencies":[],"egressEndpoints":[]}

Cisco ASA / FTD Firewall Security Policy Audit

Policy-audit-driven analysis covering both Cisco ASA (classic) and Firepower Threat Defense (FTD). Unlike generic firewall checklists that check for open ports and default-deny, this skill evaluates the platform-specific security architecture: ASA security levels with interface-bound ACLs and Modular Policy Framework, or FTD Access Control Policy with Snort IPS integration and Firepower Management Center (FMC) orchestration.

Where platforms diverge, sections use [ASA] and [FTD] labels. Shared concepts apply to both platforms unlabeled. Covers ASA 9.x+ and FTD 6.x+ / 7.x+ managed by FMC or FDM. Reference references/policy-model.md for the ASA security-level model and FTD ACP evaluation chain, and references/cli-reference.md for dual-platform read-only commands.

When to Use

  • ACL review after rule changes or migration from ASA to FTD
  • Annual or quarterly compliance audit requiring per-rule justification
  • Post-incident rule assessment to identify how traffic was permitted
  • [ASA] Security level and interface ACL gap analysis
  • [ASA] Modular Policy Framework audit — verifying inspection maps
  • [FTD] Access Control Policy rule ordering and IPS coverage review
  • [FTD] Snort IPS policy tuning assessment — false positive vs detection gap balance
  • NAT policy validation after network re-addressing or migration
  • VPN configuration security review — site-to-site and remote access
  • Failover / HA posture verification
  • Pre-migration baseline before ASA-to-FTD conversion

Prerequisites

  • [ASA] Privilege level 5+ (read-only show commands) or ASDM read-only access
  • [FTD] Read-only analyst access to FMC web UI or FMC REST API; Expert shell access for Snort-level diagnostics
  • Understanding of the interface topology — which interfaces exist, their security levels ([ASA]), and network segment assignments
  • Knowledge of expected access policies per interface pair or zone
  • For multi-context ASA: access to system and each security context
  • [FTD] Knowledge of IPS policy baseline — which Snort ruleset and network analysis policy are expected
  • Active configuration — audit evaluates the running configuration, not pending changes

Procedure

Follow this audit flow sequentially. Each step builds on prior findings. The procedure moves from platform identification through access policy, NAT, inspection/IPS, VPN, and logging.

Step 1: Platform Identification and Architecture Inventory

Determine the platform and collect architectural baseline.

show version

Identify: ASA vs FTD, software version, hardware platform (ASA 5500-X, Firepower 1000/2100/4100/9300, virtual), licensed features.

[ASA] Inventory interfaces, security levels, and context mode:

show interface ip brief
show nameif
show mode

Security levels (0–100) determine implicit traffic flow: traffic from a higher security level to a lower is permitted by default (unless ACLs override); lower-to-higher is denied by default. Record each interface name, security level, and IP address.

For multi-context ASA:

show context
changeto context <name>
show interface ip brief

[FTD] Identify management model and registered devices:

show managers

FTD managed by FMC: policy is pushed from FMC — audit via FMC UI/API. FTD managed by FDM (local): policy configured on-device — audit via FDM web UI or REST API.

Check failover/HA status on both platforms:

show failover
show failover state

Record active/standby status, failover interface, and last failover time.

Step 2: Access Policy Analysis

[ASA] ACL-based access control:

show access-list
show running-config access-list
show running-config access-group

ASA uses interface-bound ACLs. Each ACL is applied inbound or outbound on an interface via access-group. Evaluate:

  • ACL evaluation order: Top-down within each ACL. First matching ACE (Access Control Entry) is applied. Implicit deny at the bottom.
  • Global ACL: If configured, applies to all interfaces. Interface ACLs are evaluated before the global ACL.
  • Overly permissive ACEs: permit ip any any or permit tcp any any entries are Critical findings — they permit all traffic of that protocol.
  • Unused ACEs: ACEs with zero hit counts (check show access-list output for hitcnt=0) over 90+ days are cleanup candidates.
  • EtherType ACLs: Used on transparent firewall interfaces. Review for overly broad EtherType permits.
show access-list <acl-name> brief

[FTD] Access Control Policy (ACP):

Access the ACP via FMC UI or REST API. The ACP evaluates traffic through a defined chain (see references/policy-model.md). Evaluate:

  • Prefilter policy: Hardware-level rules that bypass Snort. Overly broad prefilter Trust rules skip all inspection.
  • SSL policy: Determines which TLS flows are decrypted for inspection.
  • Access Control rules: Top-down evaluation. Actions: Allow (with or without IPS), Trust (bypass Snort), Block, Monitor.
    • Rules with Action=Allow and no Intrusion Policy pass traffic without IPS inspection.
    • Rules with Action=Trust bypass all further inspection including IPS and file/malware — use only for verified trusted flows.
  • Default action: Applied when no rule matches. Should be Block with logging, not Allow.
  • Intrusion Policy binding: Each Allow rule can bind an Intrusion Policy (Snort ruleset). Rules without one pass traffic uninspected.
system support diagnostic-cli
show access-control-config
Step 3: NAT Policy Audit

[ASA] NAT order of operations:

show nat
show nat detail
show running-config nat
show xlate

ASA NAT evaluates in three sections:

  • Section 1 (Manual NAT / Twice NAT): Explicit rules, top-down. Highest priority. Used for fine-grained control.
  • Section 2 (Auto NAT / Object NAT): Per-object NAT definitions. Evaluated after Section 1. Ordering: static rules first, then dynamic.
  • Section 3 (Manual NAT after-auto): Low-priority manual rules evaluated after auto NAT. Used for catch-all translations.

Check for NAT rule conflicts — a Section 1 rule that matches the same traffic as a Section 2 object NAT always wins. Verify that static NAT entries for published servers have corresponding ACL entries restricting access.

[FTD] NAT rules in FMC:

FTD NAT follows the same three-section model as ASA but is configured via FMC. Review NAT rules in the FMC NAT policy. Verify:

  • Manual NAT rules take precedence over auto NAT
  • NAT rules align with ACP rules — ensure translated addresses match ACP source/destination references
  • No unnecessary identity NAT rules consuming processing

Cross-reference NAT entries with access policy on both platforms — static NAT that exposes internal servers must have restrictive access rules.

Step 4: Inspection and IPS Assessment

[ASA] Modular Policy Framework (MPF):

show running-config class-map
show running-config policy-map
show running-config service-policy
show service-policy

ASA inspection uses MPF: class-maps define traffic → policy-maps bind inspections → service-policies apply to interfaces. Evaluate:

  • Default inspection: ASA enables inspection for common protocols (HTTP, DNS, FTP, etc.) via the global_policy. Verify the global policy is applied (service-policy global_policy global).
  • Custom inspections: Additional class-maps/policy-maps for specific traffic patterns. Verify they are applied to correct interfaces.
  • Missing inspections: Traffic not matching any class-map in the service-policy receives no application-layer inspection — only ACL enforcement.
  • Connection limits: MPF can set connection limits and timeouts. Review for overly permissive or missing connection limits on internet-facing interfaces.

[FTD] Snort IPS and File/Malware policies:

  • Intrusion Policy: Each ACP Allow rule can reference an Intrusion Policy that determines the Snort ruleset. Check that internet-facing Allow rules bind an Intrusion Policy.
  • Snort rule sets: Verify the base policy (Balanced Security and Connectivity, Connectivity Over Security, Security Over Connectivity, Maximum Detection). For production environments, "Balanced Security and Connectivity" is the minimum recommended baseline.
  • Network Analysis Policy (NAP): Controls protocol decoder settings and preprocessor configuration. Misconfigured NAP can cause Snort detection gaps.
  • File and Malware Policy: Detects and blocks malware file transfers. Verify binding on rules permitting file-carrying protocols (HTTP, SMTP, FTP, SMB).
  • Snort deployment mode: Inline (can block) vs passive (alert only). Production deployments should use inline mode for active prevention.
system support diagnostic-cli
show snort statistics
Show full SKILL.md (774 more words)Show less
Step 5: VPN and Remote Access Audit

Evaluate VPN configuration security on both platforms.

show crypto ipsec sa
show crypto ikev2 sa
show vpn-sessiondb

Check:

  • Site-to-site tunnels: Verify IKE version (IKEv2 preferred over IKEv1), encryption algorithms (AES-256-GCM recommended; DES/3DES are findings), DH groups (group 14+ recommended; groups 1/2/5 are weak), and PFS settings.
  • Crypto maps / tunnel groups: [ASA] Review crypto map entries and tunnel group definitions. [FTD] Review site-to-site VPN topology in FMC.
  • AnyConnect / remote access VPN: If configured, evaluate:
    • Authentication method (certificate + MFA preferred over password-only)
    • Split tunneling settings (full tunnel recommended for security; split tunnel for performance — document the choice)
    • Connection profiles and group policies
    • Client certificate validation settings
    • Banner and session timeout configuration
show running-config tunnel-group
show running-config group-policy
  • IKE/IPSec SA lifetimes: Very long lifetimes (>24h IKE, >8h IPSec) increase exposure if keys are compromised.
Step 6: Logging and Monitoring

Evaluate logging configuration and coverage.

[ASA] Syslog configuration:

show logging
show running-config logging
  • Syslog severity: Verify logging level is set to at least "informational" (level 6) for security-relevant events. Level 5 (notifications) misses connection teardown events. Level 7 (debugging) generates excessive volume.
  • Syslog destinations: Verify syslog server(s) are configured and reachable. Check for encrypted syslog (TCP/TLS) for log integrity.
  • SNMP: If configured, verify community strings are not defaults and SNMP v3 is used for authentication/encryption.

[FTD] Firepower event logging:

  • Connection events: In FMC, verify connection logging is enabled on ACP rules. "Log at End of Connection" is standard; "Log at Beginning" adds volume but provides immediate visibility.
  • Intrusion events: Automatically logged by Snort when rules trigger. Verify events are forwarded to the SIEM.
  • eStreamer: The Firepower event streaming API for SIEM integration. Verify eStreamer client connectivity if in use.
  • Security Analytics / SecureX: If integrated, verify telemetry forwarding is active.
show logging
show running-config logging

Verify logging covers: denied connections (ACL denials), permitted connections (for audit trail), VPN events, failover events, and administrative access.

Threshold Tables

Policy Rule Severity Classification
FindingSeverityRationale
[ASA] permit ip any any in interface ACLCriticalPermits all IP traffic — no access restriction
[FTD] ACP default action set to AllowCriticalAll unmatched traffic permitted without inspection
[FTD] Prefilter Trust rule with broad match (any/any)CriticalTraffic bypasses all Snort inspection
[ASA] No global service-policy appliedHighNo application-layer inspection on any traffic
[FTD] Allow rule without Intrusion Policy bindingHighTraffic permitted without IPS inspection
[FTD] SSL policy not decrypting internet-bound trafficHighSnort inspects only metadata on encrypted flows
VPN using DES/3DES or DH group 1/2/5HighWeak cryptographic algorithms — vulnerable to attack
Static NAT with no restricting ACLHighPublished server accessible on all ports
Failover configured but standby not monitoringHighHA not providing redundancy
[FTD] Snort in passive mode (production)HighIPS detects but cannot block threats
[ASA] ACE with hitcnt=0 for >90 daysMediumUnused rule — cleanup candidate
[FTD] File/Malware policy not bound on file-carrying rulesMediumMalware detection gap on HTTP/SMTP/FTP
VPN split tunneling enabledMediumRemote user traffic may bypass corporate security controls
Logging severity below informational (level 6)MediumSecurity events not captured in logs
[ASA] Security levels equal with same-security-traffic disabledLowTraffic between equal interfaces blocked (may be intentional)
IPS / Inspection Maturity
CoverageMaturityGuidance
[FTD] All Allow rules have Intrusion + File/Malware policiesMatureMaintain; tune Snort rules quarterly
[FTD] Most Allow rules have Intrusion Policy, some gapsDevelopingBind Intrusion Policy to remaining Allow rules
[ASA] Global inspection policy active, custom maps definedDevelopingEvaluate FTD migration for deeper inspection
[ASA] Default global_policy only, no custom inspectionsImmatureAdd custom inspection maps for critical protocols

Decision Trees

Access Policy Gap Remediation
Overly permissive access rule identified
├── Platform?
│   ├── [ASA] permit ip any any in ACL
│   │   ├── Is ACL applied to an interface?
│   │   │   ├── Yes → CRITICAL: All traffic permitted on that interface
│   │   │   │   └── Analyze connections: show conn [interface]
│   │   │   │       → Replace with specific permit entries
│   │   │   └── No → ACL exists but not applied; verify intent
│   │   └── Global ACL?
│   │       └── Applies to all interfaces → assess scope of exposure
│   │
│   └── [FTD] Allow rule without Intrusion Policy
│       ├── What traffic does the rule match?
│       │   ├── Internet-bound → Bind Intrusion Policy (Balanced minimum)
│       │   │   └── Also bind File/Malware policy
│       │   ├── Inter-zone → Bind Intrusion Policy
│       │   └── Trusted internal → Evaluate risk; bind at minimum
│       │
│       └── Is it a Trust rule?
│           ├── Yes → Bypasses ALL inspection
│           │   └── Verify traffic is truly trusted (e.g., backup)
│           │       └── Consider changing to Allow + Intrusion Policy
│           └── No (Allow) → Add Intrusion Policy binding
│
└── Action = Trust vs Allow?
    ├── Trust → Zero inspection; use sparingly
    └── Allow → Inspection possible; bind policies
NAT Conflict Resolution
NAT rule conflict suspected
├── [ASA] Which section is each rule in?
│   ├── Section 1 (Manual) vs Section 2 (Auto) → Section 1 always wins
│   ├── Both in Section 2 → Static evaluates before dynamic; check overlap
│   └── Section 1 vs Section 3 → Section 1 wins; Section 3 may be unreachable
│
├── [FTD] Same three-section model via FMC
│   └── Review NAT policy → identify ordering conflicts
│
└── Verify with packet tracer:
    packet-tracer input <iface> tcp <src> <sport> <dst> <dport>

Report Template

CISCO ASA / FTD SECURITY POLICY AUDIT REPORT
===============================================
Device: [hostname]
Platform: [ASA model / FTD model]
Software: [ASA version / FTD version]
Management: [ASDM / FMC hostname / FDM]
Mode: [routed / transparent] [single / multi-context]
Failover: [active-standby / active-active / standalone]
Audit Date: [timestamp]
Performed By: [operator/agent]

INTERFACE / ZONE SUMMARY:
[ASA]: Interfaces: [count] (security levels: [list]) | Multi-context: [yes/no]
[FTD]: Zones: [count] ([list]) | Managed by: [FMC/FDM]

ACCESS POLICY:
[ASA]: ACLs: [count] | ACEs total: [n] | hitcnt=0 (>90d): [n] | Global service-policy: [yes/no]
[FTD]: ACP rules: [n] (Allow:[n] Block:[n] Trust:[n])
       IPS-bound: [n]/[allow] | File/Malware-bound: [n]/[allow] | Default: [Block/Allow]

NAT: Section 1: [n] | Section 2: [n] | Section 3: [n] | Static: [n] | Conflicts: [n/none]

INSPECTION / IPS:
[ASA]: Service-policy: [applied/missing] | Inspected: [protocols]
[FTD]: IPS policy: [name] | Snort: [inline/passive] | SSL decrypt: [n rules/none]

VPN: Tunnels: [n] | IKE: [v1/v2] | Crypto: [algs] | AnyConnect: [yes/no] | Split: [yes/no]

FINDINGS:
1. [Severity] [Category] — [Description]
   Platform: [ASA/FTD] | Rule: [id] | Interface/Zone: [name]
   Issue: [problem] → Recommendation: [remediation]

RECOMMENDATIONS: [Prioritized by severity]
NEXT AUDIT: [CRITICAL: 30d, HIGH: 90d, clean: 180d]

Troubleshooting

ASA-to-FTD Migration Assessment

When evaluating an ASA for migration to FTD, document: ACL count, NAT rules, MPF inspections, VPN configurations (crypto maps don't migrate directly), and multi-context usage (FTD does not support multi-context). The Cisco Firepower Migration Tool provides a baseline but audit the migrated policy for accuracy — automated migration often produces suboptimal rule ordering.

Multi-Context ASA Audits

Each security context is an independent firewall with its own interfaces, ACLs, NAT, and routing. Audit each context separately via changeto context <name>. Use show context in the system context to list all contexts and show resource allocation for per-context limits.

Large ACLs (>1000 ACEs)

Export the configuration (show running-config access-list) and parse programmatically. Prioritize by hit count — high-hit-count ACEs carry the most traffic. Zero-hit-count ACEs over 90 days are removal candidates.

FTD Diagnostic CLI

FTD runs Snort on top of an ASA-derived data plane. Use system support diagnostic-cli for ASA-style show commands. The canonical policy source is FMC — the diagnostic CLI shows deployed results.

Packet Tracer for Policy Verification

Both platforms support packet tracer for simulating traffic:

packet-tracer input <interface> tcp <src-ip> <src-port> <dst-ip> <dst-port>

Shows each processing phase: ACL/ACP evaluation, NAT translation, inspection, routing, and egress. Use to verify audit findings.

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/cisco-firewall-audit of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • _meta.json
  • references/cli-reference.md
  • references/policy-model.md

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Cisco Firewall Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cisco Firewall Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cisco Firewall Audit this skillLeoYeAI/openclaw-master-skills2.2k—~4.8kAutomated safety check: PassApache-2.0
Implementing Device Posture Assessment In Zero Trustmukul975/Anthropic-Cybersecurity-Skills34k—~4.1kAutomated safety check: PassApache-2.0
Audit Reconccashwell/evm-cortex131—~1.5kAutomated safety check: PassMIT
Executing Nist Rmf Authorization To Operatemukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Sec Checkwaynesutton/markdown-site627—~753Automated safety check: PassMIT
Security Threat Modelmajiayu000/spellbook287—~561Automated safety check: PassMIT

Similar skills

  • Implementing Device Posture Assessment In Zero Trust

    mukul975/Anthropic-Cybersecurity-Skills

    Implements device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies that…

    34k GitHub stars~4.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Audit Recon

    ccashwell/evm-cortex

    A skill your agent uses when performing initial audit reconnaissance.

    131 GitHub stars~1.5k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Executing Nist Rmf Authorization To Operate

    mukul975/Anthropic-Cybersecurity-Skills

    Drive a federal system through the NIST Risk Management Framework (SP 800-37 Rev 2) to an Authorization to Operate (ATO): Prepare, Categorize (FIPS 199), Select a control baseline (FIPS 200 / SP…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Sec Check

    waynesutton/markdown-site

    Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.

    627 GitHub stars~753 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Security Threat Model

    majiayu000/spellbook

    Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.

    287 GitHub stars~561 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Cx Platform Admin

    coralogix/cx-cli

    A skill your agent uses when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired…

    121 GitHub stars~1.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,200 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Cisco Firewall Audit

What does Cisco Firewall Audit do?

Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment…. Cisco Firewall Audit is an agent skill from LeoYeAI/openclaw-master-skills. Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment, VPN configuration review, and logging completeness verification.

When should I use Cisco Firewall Audit?

Cisco Firewall Audit fits situations like: tasks that involve Authorization and RBAC.

How do I install Cisco Firewall Audit in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a claude-code`. Or copy the skill folder (skills/cisco-firewall-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/cisco-firewall-audit in your project. Claude Code loads it when a task matches its description.

How do I install Cisco Firewall Audit in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a codex`. Or copy the skill folder (skills/cisco-firewall-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/cisco-firewall-audit in your project. Codex loads it when a task matches its description.

Can I use Cisco Firewall Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill cisco-firewall-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cisco-firewall-audit, .gemini/skills/cisco-firewall-audit, .github/skills/cisco-firewall-audit and .opencode/skills/cisco-firewall-audit in your project.

What does Cisco Firewall Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Cisco Firewall Audit is instructions for the agent only.

Does Cisco Firewall Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cisco Firewall Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cisco Firewall Audit use?

Cisco Firewall Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cisco Firewall Audit use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.7k tokens, read only when the agent opens those files.

What are the alternatives to Cisco Firewall Audit?

Skills that share tags, products or a category with Cisco Firewall Audit: Implementing Device Posture Assessment In Zero Trust (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Audit Recon (ccashwell/evm-cortex, 131 stars), Executing Nist Rmf Authorization To Operate (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Sec Check (waynesutton/markdown-site, 627 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cisco Firewall Audit?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.