Agent skill

Firewall Config

by sickn33 in sickn33/agentic-awesome-skills

Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check: notesSecurity

Install Firewall Config

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill firewall-config -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills firewall-config --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/firewall-config .claude/skills/firewall-config && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
firewall-config
GitHub stars
47k
Used in
2 other repos
Token cost
~3.2k tokens
SKILL.md length
362 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills.

  • Securing network perimeters
  • SKILL.md covers When to Use This Skill, Prerequisites, iptables and UFW (Uncomplicated Firewall), plus 7 more sections
  • Calls aws
  • Implementing security zones

What it does

Firewall Config is an agent skill from sickn33/agentic-awesome-skills. Configure iptables, nftables, and cloud firewalls. Implement network segmentation and traffic filtering. Use when securing network perimeters or implementing security zones.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not…

It sits in Security, covering Network security. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Securing network perimeters
  • Implementing security zones

Example prompts

  • “/firewall-config”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Firewall Config loads about 3.2k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 362 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:38
    - Root or sudo access on Linux hosts

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 362 words, ~3,172 tokens.

Download SKILL.mdSave it as .claude/skills/firewall-config/SKILL.md (or your agent's skills folder).
name
firewall-config
description
Configure iptables, nftables, and cloud firewalls. Implement network segmentation and traffic filtering. Use when securing network perimeters or implementing security zones.
compatibility
Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.
category
security
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

Firewall Configuration

Configure host-based and cloud firewalls for network security.

When to Use This Skill

Use this skill when:

  • Setting up a new server and need to restrict network access
  • Implementing network segmentation between application tiers
  • Configuring cloud security groups for AWS, GCP, or Azure resources
  • Migrating from iptables to nftables
  • Auditing existing firewall rules for compliance
  • Responding to a security incident requiring emergency network blocks

Prerequisites

  • Root or sudo access on Linux hosts
  • AWS CLI configured for cloud security groups
  • Understanding of TCP/IP, ports, and protocols
  • Network diagram showing required traffic flows

iptables

Basic Setup with Default Deny
bash
# Flush existing rules
iptables -F
iptables -X
iptables -t nat -F
iptables -t mangle -F

# Default policies - deny all inbound, allow outbound
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT

# Allow established connections
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

# Allow loopback
iptables -A INPUT -i lo -j ACCEPT

# Drop invalid packets
iptables -A INPUT -m conntrack --ctstate INVALID -j DROP

# Allow SSH (restrict to management subnet)
iptables -A INPUT -p tcp --dport 22 -s 10.0.100.0/24 -j ACCEPT

# Allow HTTP/HTTPS from anywhere
iptables -A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT

# Allow ICMP (ping) with rate limiting
iptables -A INPUT -p icmp --icmp-type echo-request -m limit --limit 1/s --limit-burst 4 -j ACCEPT

# Log dropped packets (rate limited to avoid log flooding)
iptables -A INPUT -m limit --limit 5/min -j LOG --log-prefix "IPTABLES-DROP: " --log-level 4

# Save rules (Debian/Ubuntu)
iptables-save > /etc/iptables/rules.v4
ip6tables-save > /etc/iptables/rules.v6
Anti-DDoS Rules
bash
# SYN flood protection
iptables -A INPUT -p tcp --syn -m limit --limit 25/s --limit-burst 50 -j ACCEPT
iptables -A INPUT -p tcp --syn -j DROP

# Limit new connections per source IP
iptables -A INPUT -p tcp --dport 80 -m connlimit --connlimit-above 50 -j REJECT

# Block port scanning (detect TCP flags abuse)
iptables -A INPUT -p tcp --tcp-flags ALL NONE -j DROP
iptables -A INPUT -p tcp --tcp-flags ALL ALL -j DROP
iptables -A INPUT -p tcp --tcp-flags ALL FIN,URG,PSH -j DROP
iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j DROP
iptables -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP
Application-Specific Rules
bash
# Web server with database backend
# Allow app servers to reach database (port 5432)
iptables -A INPUT -p tcp --dport 5432 -s 10.0.1.0/24 -j ACCEPT

# Allow monitoring (Prometheus node exporter)
iptables -A INPUT -p tcp --dport 9100 -s 10.0.200.0/24 -j ACCEPT

# DNS resolution
iptables -A INPUT -p udp --sport 53 -j ACCEPT
iptables -A INPUT -p tcp --sport 53 -j ACCEPT

# NTP
iptables -A INPUT -p udp --sport 123 -j ACCEPT

# Block specific IP (incident response)
iptables -I INPUT 1 -s 203.0.113.50 -j DROP

UFW (Uncomplicated Firewall)

bash
# Enable UFW with default deny
ufw default deny incoming
ufw default allow outgoing
ufw enable

# Allow SSH from management network
ufw allow from 10.0.100.0/24 to any port 22 proto tcp

# Allow HTTP/HTTPS
ufw allow 80/tcp
ufw allow 443/tcp

# Allow specific application profile
ufw allow 'Nginx Full'

# Rate limit SSH (max 6 connections in 30 seconds)
ufw limit ssh

# Allow port range
ufw allow 8000:8080/tcp

# Deny specific IP
ufw deny from 203.0.113.50

# Check status
ufw status verbose
ufw status numbered

# Delete a rule by number
ufw delete 3

# Application profiles
ufw app list
ufw app info 'Nginx Full'

nftables

Complete Server Configuration
bash
#!/usr/sbin/nft -f
flush ruleset

# Define variables
define LAN = 10.0.0.0/16
define MGMT = 10.0.100.0/24
define MONITOR = 10.0.200.0/24

table inet filter {
  # Rate limiting set
  set rate_limit {
    type ipv4_addr
    flags dynamic,timeout
    timeout 1m
  }

  chain input {
    type filter hook input priority 0; policy drop;

    # Connection tracking
    ct state established,related accept
    ct state invalid drop

    # Loopback
    iif "lo" accept

    # ICMP and ICMPv6
    ip protocol icmp icmp type { echo-request, destination-unreachable, time-exceeded } limit rate 10/second accept
    ip6 nexthdr icmpv6 icmpv6 type { echo-request, nd-neighbor-solicit, nd-router-advert } accept

    # SSH from management only
    tcp dport 22 ip saddr $MGMT accept

    # HTTP/HTTPS from anywhere
    tcp dport { 80, 443 } accept

    # Prometheus metrics from monitoring subnet
    tcp dport 9100 ip saddr $MONITOR accept

    # Rate limit new connections
    tcp flags syn limit rate over 25/second burst 50 packets drop

    # Log dropped traffic
    log prefix "nft-drop: " level warn limit rate 5/minute
  }

  chain forward {
    type filter hook forward priority 0; policy drop;
  }

  chain output {
    type filter hook output priority 0; policy accept;

    # Optional: restrict outbound to known destinations
    # tcp dport { 80, 443, 53 } accept
    # udp dport { 53, 123 } accept
    # ct state established,related accept
    # drop
  }
}

# NAT table for port forwarding
table ip nat {
  chain prerouting {
    type nat hook prerouting priority -100;
    # Forward port 8080 to internal app server
    tcp dport 8080 dnat to 10.0.1.10:8080
  }

  chain postrouting {
    type nat hook postrouting priority 100;
    oifname "eth0" masquerade
  }
}
nftables Management Commands
bash
# Load configuration
nft -f /etc/nftables.conf

# List all rules
nft list ruleset

# List specific table
nft list table inet filter

# Add a rule dynamically
nft add rule inet filter input tcp dport 8443 accept

# Insert rule at position
nft insert rule inet filter input position 5 ip saddr 10.0.50.0/24 tcp dport 3306 accept

# Delete a rule by handle
nft -a list chain inet filter input  # show handles
nft delete rule inet filter input handle 15

# Monitor in real time
nft monitor

AWS Security Groups

Terraform Configuration
hcl
# Web tier security group
resource "aws_security_group" "web" {
  name_prefix = "web-sg-"
  vpc_id      = aws_vpc.main.id
  description = "Security group for web servers"

  ingress {
    description = "HTTPS from internet"
    from_port   = 443
    to_port     = 443
    protocol    = "tcp"
    cidr_blocks = ["0.0.0.0/0"]
  }

  ingress {
    description = "HTTP redirect"
    from_port   = 80
    to_port     = 80
    protocol    = "tcp"
    cidr_blocks = ["0.0.0.0/0"]
  }

  egress {
    description = "All outbound"
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }

  tags = {
    Name        = "web-sg"
    Environment = "production"
    ManagedBy   = "terraform"
  }
}

# App tier - only accepts traffic from web tier
resource "aws_security_group" "app" {
  name_prefix = "app-sg-"
  vpc_id      = aws_vpc.main.id
  description = "Security group for application servers"

  ingress {
    description     = "HTTP from web tier"
    from_port       = 8080
    to_port         = 8080
    protocol        = "tcp"
    security_groups = [aws_security_group.web.id]
  }

  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }
}

# Database tier - only accepts from app tier
resource "aws_security_group" "db" {
  name_prefix = "db-sg-"
  vpc_id      = aws_vpc.main.id
  description = "Security group for database servers"

  ingress {
    description     = "PostgreSQL from app tier"
    from_port       = 5432
    to_port         = 5432
    protocol        = "tcp"
    security_groups = [aws_security_group.app.id]
  }

  egress {
    from_port   = 0
    to_port     = 0
    protocol    = "-1"
    cidr_blocks = ["0.0.0.0/0"]
  }
}
AWS CLI Commands
bash
# Create security group
aws ec2 create-security-group \
  --group-name web-sg \
  --description "Web server SG" \
  --vpc-id vpc-0abc123

# Add inbound rule
aws ec2 authorize-security-group-ingress \
  --group-id sg-0abc123 \
  --protocol tcp --port 443 \
  --cidr 0.0.0.0/0

# Add rule referencing another security group
aws ec2 authorize-security-group-ingress \
  --group-id sg-0db456 \
  --protocol tcp --port 5432 \
  --source-group sg-0app789

# Remove a rule
aws ec2 revoke-security-group-ingress \
  --group-id sg-0abc123 \
  --protocol tcp --port 22 \
  --cidr 0.0.0.0/0

# Describe rules
aws ec2 describe-security-group-rules \
  --filters Name=group-id,Values=sg-0abc123

Firewall Rule Audit Script

bash
#!/bin/bash
# firewall-audit.sh - Audit current firewall rules for common issues

echo "=== Firewall Audit Report ==="
echo "Date: $(date -u +%Y-%m-%dT%H:%M:%SZ)"
echo "Host: $(hostname)"
echo ""

# Check if firewall is active
if command -v nft &>/dev/null; then
    echo "--- nftables rules ---"
    nft list ruleset
elif command -v iptables &>/dev/null; then
    echo "--- iptables rules ---"
    iptables -L -n -v --line-numbers
fi

echo ""
echo "--- Open ports ---"
ss -tlnp

echo ""
echo "--- Potential issues ---"

# Check for overly permissive rules
if iptables -L INPUT -n 2>/dev/null | grep -q "0.0.0.0/0.*dpt:22"; then
    echo "WARNING: SSH (port 22) open to 0.0.0.0/0 - restrict to management subnet"
fi

if iptables -L INPUT -n 2>/dev/null | grep -q "0.0.0.0/0.*dpt:3306"; then
    echo "CRITICAL: MySQL (port 3306) open to 0.0.0.0/0"
fi

if iptables -L INPUT -n 2>/dev/null | grep -q "0.0.0.0/0.*dpt:5432"; then
    echo "CRITICAL: PostgreSQL (port 5432) open to 0.0.0.0/0"
fi

# Check default policies
DEFAULT_INPUT=$(iptables -L INPUT 2>/dev/null | head -1 | grep -oP 'policy \K\w+')
if [ "$DEFAULT_INPUT" = "ACCEPT" ]; then
    echo "CRITICAL: Default INPUT policy is ACCEPT - should be DROP"
fi

Troubleshooting

ProblemCauseSolution
Locked out of SSHRule order or default deny applied before allowUse out-of-band console access; add SSH allow rule first
Rules lost after rebootRules not persistedInstall iptables-persistent or save to /etc/nftables.conf
Docker bypasses iptablesDocker modifies iptables FORWARD chainUse DOCKER-USER chain for custom rules; set "iptables": false in daemon.json
nftables and iptables conflictBoth running simultaneouslyMigrate fully to nftables; remove iptables packages
AWS SG rule limit reachedMax 60 inbound rules per SGUse prefix lists or consolidate CIDR ranges
Legitimate traffic blockedRule ordering issuePlace more specific allow rules before general deny rules
Show full SKILL.md (133 more words)Show less

Best Practices

  • Default deny policy on all chains
  • Minimal rule sets - only open what is required
  • Regular rule audits (monthly minimum)
  • Log denied traffic for security monitoring
  • Document all rules with descriptions and ticket references
  • Use connection tracking for stateful inspection
  • Rate limit inbound connections to prevent DDoS
  • Separate management traffic from application traffic
  • Test rule changes in staging before production
  • Keep persistent backups of working rule sets
  • linux-hardening (linux-hardening) - System security
  • aws-vpc (aws-vpc) - AWS networking
  • zero-trust (zero-trust) - Identity-based access patterns
  • vpn-setup (vpn-setup) - Secure tunnel configuration

Limitations

  • Apply guidance only within authorized scope; test destructive steps in non-production first.
  • Docs-only import: upstream scripts and templates not bundled.
Example
bash
# Read-only first: inventory before any active step.
which <tool> && <tool> --help | head -n 20

Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/firewall-config of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Firewall Config next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Firewall Config compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Firewall Config this skillsickn33/agentic-awesome-skills47k2 repos~3.2kAutomated safety check: NotesMIT
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
mTLS Configurationwshobson/agents40k9 repos~588Automated safety check: PassMIT
Google Cloud Waf Securitygoogle/skills21k1 repos~4.2kAutomated safety check: PassApache-2.0
Implementing File Integrity Monitoring With Aidemukul975/Anthropic-Cybersecurity-Skills34k—~642Automated safety check: NotesApache-2.0
Azure Network Security Designvinayaklatthe/microsoft-security-skills175—~1.8kAutomated safety check: PassMIT

Similar skills

  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • mTLS Configuration

    wshobson/agents

    Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging.

    40k GitHub starsUsed in 9 repos~588 tokens
    SecurityAuto-check passed
  • Official

    Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).

    21k GitHub starsUsed in 1 repo~4.2k tokens
    SecurityAuto-check passed
  • Implementing File Integrity Monitoring With Aide

    mukul975/Anthropic-Cybersecurity-Skills

    Configures AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring on Linux, covering baseline database creation, scheduled integrity checks via cron, change detection, and…

    34k GitHub stars~642 tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Azure Network Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…

    175 GitHub stars~1.8k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Network Security Setup

    Microck/ordinary-claude-skills

    Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables

    404 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check: notes

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Firewall Config

What does Firewall Config do?

Configure iptables, nftables, and cloud firewalls. An agent skill from sickn33/agentic-awesome-skills. Firewall Config is an agent skill from sickn33/agentic-awesome-skills. Configure iptables, nftables, and cloud firewalls.

When should I use Firewall Config?

Firewall Config fits situations like: securing network perimeters; implementing security zones.

How do I install Firewall Config in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill firewall-config -a claude-code`. Or copy the skill folder (skills/firewall-config in sickn33/agentic-awesome-skills) into .claude/skills/firewall-config in your project. Claude Code loads it when a task matches its description.

How do I install Firewall Config in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill firewall-config -a codex`. Or copy the skill folder (skills/firewall-config in sickn33/agentic-awesome-skills) into .agents/skills/firewall-config in your project. Codex loads it when a task matches its description.

Can I use Firewall Config in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill firewall-config -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/firewall-config, .gemini/skills/firewall-config, .github/skills/firewall-config and .opencode/skills/firewall-config in your project.

What does Firewall Config need to run?

Going by SKILL.md and its folder, Firewall Config needs the command-line tools its instructions call (aws). Our summary lists: Docker. Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled..

Does Firewall Config access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Firewall Config safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Firewall Config use?

Firewall Config is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Firewall Config use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Firewall Config?

Skills that share tags, products or a category with Firewall Config: Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), mTLS Configuration (wshobson/agents, 40k stars), Google Cloud Waf Security (google/skills, 21k stars) and Implementing File Integrity Monitoring With Aide (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Firewall Config?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.