Agent skill

Fortigate Firewall Audit

by LeoYeAI in LeoYeAI/openclaw-master-skills

FortiOS VDOM segmentation audit with UTM profile binding validation, FortiGuard service health assessment, SD-WAN security evaluation, and HA cluster posture check.

Apache-2.0Auto-check passedMarketing & SEO

Install Fortigate Firewall Audit

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill fortigate-firewall-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills fortigate-firewall-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/fortigate-firewall-audit .claude/skills/fortigate-firewall-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fortigate-firewall-audit
GitHub stars
2.2k
Token cost
~4.9k tokens
SKILL.md length
1,695 words
Files
4 (incl. references)
Skills in repo
1,235
Repo updated
First seen
Licence
Apache-2.0

At a glance

FortiOS VDOM segmentation audit with UTM profile binding validation, FortiGuard service health assessment, SD-WAN security evaluation, and HA cluster posture check.

  • Works in 6 steps: VDOM Architecture Inventory → Firewall Policy Rule-by-Rule Analysis → UTM Profile Binding Audit → …
  • Tasks that involve Marketing analytics
  • SKILL.md covers When to Use, Prerequisites, Procedure and Threshold Tables, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Fortigate Firewall Audit is an agent skill from LeoYeAI/openclaw-master-skills. FortiOS VDOM segmentation audit with UTM profile binding validation, FortiGuard service health assessment, SD-WAN security evaluation, and HA cluster posture check. Systematic per-VDOM policy analysis for FortiGate appliances and FortiGate-VM instances.

Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/cli-reference.md` and `references/policy-model.md`).

It sits in Marketing & SEO, covering Marketing analytics. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Marketing analytics

Example prompts

  • “Use the fortigate-firewall-audit skill to fortio VDOM segmentation audit with UTM profile binding validation, FortiGuard service health assessment…”
  • “/fortigate-firewall-audit”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. VDOM Architecture Inventory
  2. Firewall Policy Rule-by-Rule Analysis
  3. UTM Profile Binding Audit
  4. FortiGuard Service Validation
  5. SD-WAN SLA and Rule Security
  6. HA and Session Sync Audit

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fortigate Firewall Audit loads about 4.9k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 1,695 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its Apache-2.0 licence (© LeoYeAI). 1,695 words, ~4,922 tokens.

Download SKILL.mdSave it as .claude/skills/fortigate-firewall-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
fortigate-firewall-audit
description
FortiOS VDOM segmentation audit with UTM profile binding validation, FortiGuard service health assessment, SD-WAN security evaluation, and HA cluster posture check. Systematic per-VDOM policy analysis for FortiGate appliances and FortiGate-VM instances.
license
Apache-2.0
metadata.safety
read-only
metadata.author
network-security-skills-suite
metadata.version
1.0.0
metadata.openclaw
{"emoji":"🛡️","safetyTier":"read-only","requires":{"bins":["ssh"],"env":[]},"tags":["fortinet","fortigate","firewall"],"mcpDependencies":[],"egressEndpoints"…

FortiGate Firewall Security Policy Audit

Policy-audit-driven analysis of FortiGate/FortiOS firewall policies. Unlike generic firewall checklists that check for open ports and default-deny, this skill evaluates the FortiOS-specific security architecture: Virtual Domain (VDOM) segmentation, UTM profile binding on every allow policy, FortiGuard signature freshness, and SD-WAN SLA-based traffic steering security implications.

Covers FortiOS 7.x+ on FortiGate hardware appliances and FortiGate-VM virtual instances. For FortiManager-managed deployments, the audit addresses ADOM hierarchy and policy package consistency. Reference references/policy-model.md for the full VDOM/UTM inspection chain and references/cli-reference.md for read-only CLI commands.

When to Use

  • Post-change policy review after rule additions or VDOM topology changes
  • VDOM segmentation audit verifying inter-VDOM link isolation and per-VDOM policy independence
  • UTM profile coverage assessment — finding allow policies without antivirus, IPS, or web-filter inspection
  • SD-WAN security evaluation — confirming SLA violations do not steer traffic around security controls
  • FortiGuard license and connectivity validation — ensuring signature databases are current
  • HA cluster security posture check — verifying firmware parity, config sync, and session-sync settings
  • Quarterly or annual compliance audit requiring per-policy justification
  • Pre-upgrade baseline before FortiOS major version changes

Prerequisites

  • Read-only administrative access to FortiOS CLI (or diagnose-level privilege for runtime state)
  • Understanding of the VDOM topology — which VDOMs exist, their function (management, traffic, DMZ), and expected inter-VDOM links
  • Knowledge of expected UTM profile assignments per policy category (internet-bound, inter-zone, intrazone)
  • For FortiManager-managed environments: access to the ADOM with visibility into policy packages
  • Awareness of SD-WAN configuration — SLA targets, member interfaces, and health-check definitions
  • Running configuration committed — audit evaluates the active configuration, not pending changes

Procedure

Follow this audit flow sequentially. Each step builds on prior findings. The procedure moves from VDOM architecture inventory through per-VDOM rule-level analysis to UTM coverage, FortiGuard health, SD-WAN security, and HA posture.

Step 1: VDOM Architecture Inventory

Collect all VDOMs and their roles.

config vdom
edit root
end
get system status

On a multi-VDOM system, list all VDOMs:

diagnose sys vd list

For each VDOM, record: name, type (traffic/management/admin), assigned interfaces (physical and virtual), inter-VDOM link pairs, and VDOM resource limits (session count, CPU quota). Identify the management VDOM — this is where FortiGuard updates, logging, and administrative access are configured.

Check inter-VDOM links:

show system vdom-link

Inter-VDOM links function as virtual interfaces connecting two VDOMs. Traffic crossing a VDOM link is subject to the receiving VDOM's firewall policies — verify that inter-VDOM traffic is not bypassing inspection.

Verify VDOM resource limits to detect unbounded VDOMs that could starve other VDOMs during volumetric events:

config global
get system vdom-property

Flag any VDOM without explicit resource limits in a multi-VDOM deployment.

Step 2: Firewall Policy Rule-by-Rule Analysis

For each VDOM, retrieve the full policy table:

config vdom
edit <vdom-name>
show firewall policy

FortiOS evaluates firewall policies top-down by sequence number within each VDOM. The first matching policy is applied. Evaluate each policy against these criteria:

  • Overly permissive policies: Policies with srcaddr "all", dstaddr "all", service "ALL", and action accept are Critical findings — they accept all traffic on all ports with no restriction.
  • Missing UTM profiles: Allow policies without antivirus, web-filter, application-control, or IPS profile binding pass traffic uninspected. Check utm-status, av-profile, webfilter-profile, application-list, and ips-sensor on each allow policy.
  • Disabled policies: Policies with status disable still occupy sequence numbers and create audit confusion. Flag for cleanup.
  • Schedule-based policies: Policies with schedule other than always may create time-window security gaps. Verify schedules align with intended access windows.
  • Implicit deny: FortiOS has an implicit deny (policy ID 0) at the bottom of each VDOM's policy table. Verify it is logging traffic for visibility into denied connections.

Check for unused policies using hit count data:

diagnose firewall iprope show 100004 <policy-id>

Policies with zero hits over 90+ days are cleanup candidates.

Step 3: UTM Profile Binding Audit

For each allow policy in every VDOM, verify that UTM inspection profiles are bound. The goal is zero allow policies without threat inspection.

Check each allow policy for these profile bindings:

  • Antivirus (av-profile): File-based malware scanning. Required on all internet-bound and inter-zone policies.
  • Web Filter (webfilter-profile): URL categorization and blocking. Required on all policies permitting HTTP/HTTPS.
  • Application Control (application-list): Application identification and enforcement. FortiOS equivalent of App-ID.
  • IPS (ips-sensor): Intrusion prevention signatures. Required on all allow policies carrying untrusted traffic.
  • Email Filter (emailfilter-profile): Anti-spam for SMTP/IMAP/POP3. Required on email-carrying policies.
  • DLP Sensor (dlp-sensor): Data loss prevention pattern matching. Required where sensitive data egress risk exists.
  • SSL Inspection (ssl-ssh-profile): Determines whether encrypted traffic is decrypted for UTM inspection. Without SSL inspection set to deep-inspection, AV and IPS see only connection metadata on HTTPS.

Summarize coverage: count allow policies with full UTM binding versus allow policies with partial or no UTM profiles. Calculate the UTM coverage ratio.

Check the inspection mode per VDOM:

config vdom
edit <vdom-name>
get system settings | grep inspection-mode

Flow-based mode applies all UTM in a single pass (faster, less thorough). Proxy-based mode buffers and inspects fully (more thorough, more resource intensive). The mode affects which UTM features are available and their efficacy.

Step 4: FortiGuard Service Validation

FortiGuard provides the signature databases that UTM profiles depend on. Stale signatures reduce detection efficacy.

get system fortiguard-service status
diagnose autoupdate versions

Verify the following signature databases are current:

DatabaseMaximum Acceptable AgeCheck Command
Antivirus definitions24 hours`diagnose autoupdate versions
IPS signatures7 days`diagnose autoupdate versions
Web filter database7 daysget webfilter status
Application control DB7 days`diagnose autoupdate versions
Anti-spam database7 days`diagnose autoupdate versions

Check FortiGuard connectivity:

diagnose debug rating
execute ping service.fortiguard.net

If FortiGuard is unreachable, all cloud-dependent features (web filter rating queries, FortiSandbox cloud, outbreak prevention) operate in degraded mode using cached data only.

Verify the update schedule:

show system autoupdate schedule

Best practice is scheduled updates every 1–4 hours for AV and daily for IPS/App-Control. Manual-only updates are a finding.

Step 5: SD-WAN SLA and Rule Security

If SD-WAN is configured, evaluate security implications of traffic steering.

config vdom
edit <vdom-name>
show system sdwan

Review SD-WAN components:

  • SLA targets and health checks: Examine each health check definition (protocol, server, threshold). Verify health-check servers are reachable and meaningful for the SLA metric (latency, jitter, packet loss).
diagnose sys sdwan health-check
  • SD-WAN rules: Each rule maps traffic to preferred WAN members based on SLA status. Review rule priorities and the tie-break method.
diagnose sys sdwan service
  • Fail-open behavior: When all SLA members fail, SD-WAN rules may fall through to standard routing. Determine whether this fallback path still traverses security inspection. A fail-open that routes around a security VDOM or UTM-inspecting policy is a Critical finding.

  • SD-WAN + firewall policy interaction: SD-WAN selects the egress interface, but firewall policies still control access. Verify that firewall policies cover all SD-WAN member interfaces. A policy that references a specific interface may not match when SD-WAN steers traffic to an alternate member.

Show full SKILL.md (639 more words)Show less
Step 6: HA and Session Sync Audit

Evaluate HA cluster security posture.

get system ha status
diagnose sys ha checksum cluster

Check the following:

  • HA mode: Active-passive (recommended for stateful firewalls) vs active-active (requires careful session-sync configuration). Record the mode and verify it matches design intent.
  • Firmware parity: Both cluster members must run the same FortiOS version. Version mismatch can cause session-sync failures and policy inconsistencies.
diagnose sys ha checksum cluster

Compare configuration checksums between members. Mismatched checksums indicate configuration drift — a security risk when policies differ between HA members.

  • Session sync configuration: Verify which session types are synchronized (TCP, UDP, ICMP, expectation sessions). Unsynchronized sessions drop during failover.
show system ha

Check session-pickup and session-pickup-connectionless settings.

  • HA heartbeat security: Verify heartbeat interfaces use encryption and authentication. Unencrypted heartbeats on shared network segments are vulnerable to spoofing.
  • HA management interface: Verify dedicated management access is configured for each cluster member (ha-mgmt-interfaces) to ensure both nodes remain independently accessible.

Threshold Tables

Policy Rule Severity Classification
FindingSeverityRationale
srcaddr "all" + dstaddr "all" + service "ALL" + action acceptCriticalFully open policy — no restriction on source, destination, or service
Allow policy without any UTM profile (no AV, IPS, web-filter)CriticalTraffic passes without threat inspection
FortiGuard unreachable — all signatures staleCriticalUTM profiles active but signatures outdated; detection efficacy severely degraded
SD-WAN fail-open bypasses security inspection pathCriticalSLA failure routes traffic around UTM inspection
Allow policy with service "ALL" (specific src/dst)HighPermits all services — evaluate whether specific services can be defined
FortiGuard signatures >7 days oldHighDetection gap for new threats discovered in the past week
VDOM without resource limits in multi-VDOM deploymentHighUnbounded VDOM can starve other VDOMs during volumetric events
HA configuration checksum mismatch between membersHighPolicy or configuration drift — active and standby may enforce different rules
HA firmware version mismatchHighSession sync and feature parity issues during failover
Allow policy with partial UTM (missing IPS or AV)MediumSome inspection, but exploit or malware detection gap
Disabled policies in production VDOMMediumAudit confusion; stale configuration; cleanup recommended
SSL inspection not set to deep-inspection on internet-bound policyMediumUTM sees only metadata on encrypted traffic — AV/IPS efficacy reduced
Schedule-based policy creates off-hours security gapMediumAccess permitted during window only, but gap during that window is intentional risk
Inter-VDOM link without receiving-side policyMediumTraffic may traverse VDOM boundary without inspection
Policies with zero hits >90 daysLowUnused rules — cleanup candidates
UTM Coverage Maturity
UTM Coverage RatioMaturityGuidance
>90% allow policies with full UTMMatureMaintain; review remaining gaps quarterly
60–90% allow policies with UTMDevelopingPrioritize internet-bound and inter-zone policies for UTM binding
<60% allow policies with UTMImmatureSystematic UTM profile binding campaign needed

Decision Trees

UTM Gap Remediation
Allow policy without UTM profiles
├── What traffic does this policy carry?
│   ├── Internet-bound → CRITICAL: Bind full UTM (AV+IPS+WebFilter+AppCtrl+SSL deep-inspection)
│   ├── Inter-VDOM or inter-zone → HIGH: Bind AV+IPS+AppCtrl minimum
│   ├── Intra-zone management → MEDIUM: Bind IPS+AppCtrl; AV optional
│   └── Monitoring/logging only → LOW: Evaluate if allow is needed
│
├── SSL inspection mode?
│   ├── certificate-inspection → UTM limited to metadata on HTTPS
│   │   └── Evaluate switching to deep-inspection for this policy
│   ├── deep-inspection → Full UTM efficacy on encrypted traffic
│   └── none → Only unencrypted traffic inspected
│       └── Add ssl-ssh-profile before UTM profiles
│
└── Inspection mode (VDOM-level)?
    ├── flow-based → Single-pass; good performance, some UTM features limited
    └── proxy-based → Full buffered inspection; verify resource impact
        └── Check CPU/memory: diagnose sys top
VDOM Consolidation Assessment
Multi-VDOM deployment evaluation
├── How many VDOMs are configured?
│   ├── >10 VDOMs → Evaluate consolidation; management complexity increases risk
│   ├── 3–10 VDOMs → Typical; verify each serves a distinct security function
│   └── 1–2 VDOMs → Minimal; verify VDOM is needed vs single-VDOM mode
│
├── Do all VDOMs have active policies?
│   ├── Empty or minimal policy VDOMs → Candidates for consolidation or removal
│   └── Active policy VDOMs → Verify traffic segmentation justification
│
├── Are inter-VDOM links necessary?
│   ├── Inter-VDOM traffic inspected by receiving VDOM → Correct architecture
│   └── Inter-VDOM traffic not inspected → Finding: add policies on VDOM links
│
└── Resource contention?
    ├── VDOM resource limits configured → Check utilization vs limits
    └── No limits → Set limits per VDOM to prevent starvation
SD-WAN Fail-Open Risk Evaluation
SD-WAN SLA failure scenario
├── All SLA members for a rule fail
│   ├── Rule has dst = security VDOM or UTM-inspecting path?
│   │   ├── Yes → Traffic falls to routing table
│   │   │   ├── Routing table path includes UTM inspection? → Acceptable
│   │   │   └── Routing table path bypasses UTM? → CRITICAL: fail-open gap
│   │   └── No → Standard egress; verify firewall policy still matches
│   │
│   └── SLA health-check server unreachable (false positive)?
│       ├── Single health-check server → HIGH: Add redundant check servers
│       └── Multiple servers, all down → Likely real outage; verify failover
│
└── Partial SLA failure (some members down)
    ├── Traffic steers to remaining members → Verify capacity
    └── Remaining member is a lower-security path → Evaluate risk

Report Template

FORTIGATE SECURITY POLICY AUDIT REPORT
========================================
Device: [hostname]
FortiOS Version: [version]
Platform: [FortiGate model / FortiGate-VM]
VDOM Mode: [multi-vdom / split-vdom / disabled]
Management: [standalone / FortiManager ADOM name]
Audit Date: [timestamp]
Performed By: [operator/agent]

VDOM ARCHITECTURE:
- VDOMs configured: [count]
- Management VDOM: [name]
- Inter-VDOM links: [count] ([list pairs])
- VDOMs with resource limits: [n] / [total]

PER-VDOM POLICY SUMMARY:
VDOM: [name]
  - Total firewall policies: [count]
  - Accept policies: [n] | Deny policies: [n]
  - Policies with full UTM profiles: [n] / [accept count]
  - Inspection mode: [flow-based / proxy-based]
  - SSL inspection (deep): [n] policies
  [Repeat for each VDOM]

FORTIGUARD STATUS:
- Connectivity: [connected / unreachable]
- AV signatures: [version] ([age])
- IPS signatures: [version] ([age])
- Web filter DB: [version] ([age])
- Application control DB: [version] ([age])
- Update schedule: [interval]

SD-WAN STATUS:
- SD-WAN enabled: [yes/no]
- SLA health checks: [count] ([all passing / N failing])
- Fail-open risk: [none identified / risk details]

HA STATUS:
- HA mode: [active-passive / active-active / standalone]
- Firmware parity: [matched / mismatched — versions]
- Config checksum: [matched / mismatched]
- Session sync: [enabled / disabled]

FINDINGS:
1. [Severity] [Category] — [Description]
   VDOM: [vdom-name]
   Policy ID: [id] (Seq: [sequence])
   Interfaces: [srcintf] → [dstintf]
   Issue: [specific problem]
   Current Config: [relevant policy fields]
   Recommendation: [specific remediation]

UTM COVERAGE:
- Per-VDOM coverage ratios: [list each VDOM: n/total (%)]
- Policies missing AV: [count]
- Policies missing IPS: [count]
- Policies missing web-filter: [count]
- Policies missing application-control: [count]

RECOMMENDATIONS:
- [Prioritized action list by severity]

NEXT AUDIT: [CRITICAL findings: 30d, HIGH: 90d, clean: 180d]

Troubleshooting

Large Multi-VDOM Deployments

Auditing more than 10 VDOMs manually is impractical. Export per-VDOM policy tables via the FortiOS REST API (/api/v2/cmdb/firewall/policy?vdom=<name>) for programmatic analysis. Prioritize VDOMs carrying internet-bound or inter-zone traffic — management VDOMs are lower risk.

FortiManager Policy Packages

In FortiManager-managed deployments, audit the installed policy on the FortiGate (via show firewall policy), not just the FortiManager package — local policies and installation state may differ. Use diagnose fortimanager policy-check to identify discrepancies.

UTM Performance Impact

Before binding UTM profiles on high-throughput policies, assess headroom:

get system performance status
diagnose sys top 2 20

FortiGate models have rated throughput for NGFW and Threat Protection profiles. Ensure traffic volume is within rated capacity. If constrained, prioritize UTM on internet-bound policies and use flow-based inspection.

Firmware Upgrade Impact on Policies

FortiOS major upgrades may change UTM profile schema or deprecate features. Export the policy baseline before upgrading, then post-upgrade verify: UTM profile bindings preserved, policy sequence intact, SD-WAN rules migrated, and HA cluster upgraded in sequence (secondary first).

Split-VDOM Mode vs Multi-VDOM Mode

Split-VDOM provides two VDOMs (root + FG-traffic); full multi-VDOM allows custom count. Audit whether split-VDOM segmentation is sufficient for compliance requirements. Changing VDOM mode requires a reboot.

© LeoYeAI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/fortigate-firewall-audit of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • _meta.json
  • references/cli-reference.md
  • references/policy-model.md

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Fortigate Firewall Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fortigate Firewall Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fortigate Firewall Audit this skillLeoYeAI/openclaw-master-skills2.2k—~4.9kAutomated safety check: PassApache-2.0
Google SEO APIsAgriciDaniel/claude-seo19k1 repos~4.2kAutomated safety check: PassMIT
AnalyticsNexus-JPF/note-companion8707 repos~2.2kAutomated safety check: PassMIT
GEO Monthly Delta Reportzubair-trabzada/geo-seo-claude11k—~2.4kAutomated safety check: NotesMIT
Conversion Signal QAaaron-he-zhu/aaron-marketing-skills2.9k2 repos~2.4kAutomated safety check: PassApache-2.0
LLM Mention Trackingunifapi-agent/agents589—~1.8kAutomated safety check: PassMIT

Similar skills

  • Google SEO APIs

    AgriciDaniel/claude-seo

    Pulls real Google data for SEO work: Search Console, PageSpeed Insights, CrUX field data, the Indexing API and GA4 organic traffic, through /seo google commands.

    19k GitHub starsUsed in 1 repo~4.2k tokens
    Marketing & SEOAuto-check passed
  • Analytics

    Nexus-JPF/note-companion

    When the user wants to set up, improve, or audit analytics tracking and measurement.

    870 GitHub starsUsed in 7 repos~2.2k tokens
    Marketing & SEOAuto-check passed
  • GEO Monthly Delta Report

    zubair-trabzada/geo-seo-claude

    Compares a baseline and a current GEO audit for a client, calculates score changes and action item progress, and writes a monthly progress report.

    11k GitHub stars~2.4k tokensUpdated today
    Marketing & SEOAuto-check: notes
  • Conversion Signal QA

    aaron-he-zhu/aaron-marketing-skills

    A skill your agent uses when the user asks to "QA my conversion tracking before launch", "check my UTMs / pixel / event firing", "set up a tracking pre-flight", or "set the dedup rule so Meta and…

    2.9k GitHub starsUsed in 2 repos~2.4k tokens
    Marketing & SEOAuto-check passed
  • LLM Mention Tracking

    unifapi-agent/agents

    When the user wants to track how often their brand or domain gets mentioned across ChatGPT and AI search engines over a set of prompts, and how that share of voice compares to named competitors over…

    589 GitHub stars~1.8k tokensUpdated 1 mo ago
    Marketing & SEOAuto-check passed
  • Google Analytics 4 Analysis

    LichAmnesia/lich-skills

    Pulls Google Analytics 4 data through the Data API with TypeScript scripts and turns it into a daily SEO report or prioritized traffic and bounce-rate recommendations.

    234 GitHub stars~2k tokensUpdated 4 mo ago
    Marketing & SEOAuto-check: notes

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Fortigate Firewall Audit

What does Fortigate Firewall Audit do?

FortiOS VDOM segmentation audit with UTM profile binding validation, FortiGuard service health assessment, SD-WAN security evaluation, and HA cluster posture check. Fortigate Firewall Audit is an agent skill from LeoYeAI/openclaw-master-skills. FortiOS VDOM segmentation audit with UTM profile binding validation, FortiGuard service health assessment, SD-WAN security evaluation, and HA cluster posture check.

When should I use Fortigate Firewall Audit?

Fortigate Firewall Audit fits situations like: tasks that involve Marketing analytics.

How do I install Fortigate Firewall Audit in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill fortigate-firewall-audit -a claude-code`. Or copy the skill folder (skills/fortigate-firewall-audit in LeoYeAI/openclaw-master-skills) into .claude/skills/fortigate-firewall-audit in your project. Claude Code loads it when a task matches its description.

How do I install Fortigate Firewall Audit in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill fortigate-firewall-audit -a codex`. Or copy the skill folder (skills/fortigate-firewall-audit in LeoYeAI/openclaw-master-skills) into .agents/skills/fortigate-firewall-audit in your project. Codex loads it when a task matches its description.

Can I use Fortigate Firewall Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill fortigate-firewall-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fortigate-firewall-audit, .gemini/skills/fortigate-firewall-audit, .github/skills/fortigate-firewall-audit and .opencode/skills/fortigate-firewall-audit in your project.

What does Fortigate Firewall Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Fortigate Firewall Audit is instructions for the agent only.

Does Fortigate Firewall Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fortigate Firewall Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fortigate Firewall Audit use?

Fortigate Firewall Audit is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fortigate Firewall Audit use?

About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.2k tokens, read only when the agent opens those files.

What are the alternatives to Fortigate Firewall Audit?

Skills that share tags, products or a category with Fortigate Firewall Audit: Google SEO APIs (AgriciDaniel/claude-seo, 19k stars), Analytics (Nexus-JPF/note-companion, 870 stars), GEO Monthly Delta Report (zubair-trabzada/geo-seo-claude, 11k stars) and Conversion Signal QA (aaron-he-zhu/aaron-marketing-skills, 2.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fortigate Firewall Audit?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.