Agent skill

Nftables Allow Source

by SpecterOps in SpecterOps/skills

Add a source IP or CIDR to nftables using the working method from this repo session: live top-of-input insertion with nft -a verification first, then persistent config update and reload.

Apache-2.0Auto-check: notesBusiness, Finance & HR

Install Nftables Allow Source

skills CLI
$ npx skills add SpecterOps/skills --skill nftables-allow-source -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills nftables-allow-source --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ops-infrastructure/skills/nftables-allow-source .claude/skills/nftables-allow-source && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nftables-allow-source
GitHub stars
702
Token cost
~1.5k tokens
SKILL.md length
711 words
Files
4 (incl. assets)
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add a source IP or CIDR to nftables using the working method from this repo session: live top-of-input insertion with nft -a verification first, then persistent config update and reload.

  • Works in 4 steps: Confirm the host is in scope and… → Confirm SSH or console access exists… → Confirm nft is installed and the host is… → …
  • Tasks that involve Crypto and DeFi analysis
  • SKILL.md covers Direct Triggers, Input Contract, Preconditions and Execution Workflow, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nftables Allow Source is an agent skill from SpecterOps/skills. Add a source IP or CIDR to nftables using the working method from this repo session: live top-of-input insertion with nft -a verification first, then persistent config update and reload.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including assets (for example `agents/openai.yaml`).

It sits in Business, Finance & HR, covering Crypto and DeFi analysis. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Crypto and DeFi analysis

Example prompts

  • “/nftables-allow-source”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the host is in scope and operator-controlled.
  2. Confirm SSH or console access exists before changing the firewall.
  3. Confirm nft is installed and the host is actually using nftables.
  4. Prefer live insertion into the input chain before any persistent edit.

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nftables Allow Source loads about 1.5k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 711 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:55
    sudo nft -a list chain inet filter input
  • NoteRuns commands with sudoSKILL.md:72
    sudo nft insert rule inet filter input position 0 ip saddr <SOURCE> accept
  • NoteRuns commands with sudoSKILL.md:80
    sudo nft -a list chain inet filter input
  • NoteRuns commands with sudoSKILL.md:94
    - `sudo nft -f /etc/nftables.conf`
  • NoteRuns commands with sudoSKILL.md:96
    - `sudo sed -n '/chain input {/,/}/p' /etc/nftables.conf`
  • NoteRuns commands with sudoSKILL.md:97
    - `sudo nft -a list chain inet filter input`
  • NoteRuns commands with sudoSKILL.md:105
    sudo nft -a list chain inet filter input
  • NoteRuns commands with sudoSKILL.md:111
    sudo nft insert rule inet filter input position 0 ip saddr 203.0.113.42 accept
  • NoteRuns commands with sudoSKILL.md:117
    sudo cp /etc/nftables.conf /etc/nftables.conf.bak-$(date +%Y%m%d%H%M%S)
  • NoteRuns commands with sudoSKILL.md:123
    sudo sed -i '/type filter hook input priority filter; policy drop;/a\        ip saddr 203.0.113.42 accept comment "Autho

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 711 words, ~1,474 tokens.

Download SKILL.mdSave it as .claude/skills/nftables-allow-source/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
nftables-allow-source
description
Add a source IP or CIDR to nftables using the working method from this repo session: live top-of-`input` insertion with `nft -a` verification first, then persistent config update and reload.
metadata.author
GhostWorks

Nftables Allow Source

Use this skill to add a source IP or CIDR to nftables using the method that worked in this repo session:

  • inspect the live input chain with nft -a
  • insert a source allow rule at the top of the live input chain
  • verify the live rule immediately
  • add the same source allow rule to /etc/nftables.conf in the input chain
  • reload the ruleset and verify config and live state match

Do not use a config-first workflow here. The working method is live input insertion first, persistence second.

Direct Triggers

Use this skill when the task mentions any of the following:

  • add an nftables allow rule
  • allow inbound from an IP
  • whitelist an IP in nftables
  • add a source address to the firewall
  • insert an nft rule at the top
  • use nft -a handles

Input Contract

Accept input as: HOST SOURCE [MODE]

Mode:

  • plan: produce the command sequence only
  • execute (default): inspect, insert, and verify the live rule

Examples:

  • $nftables-allow-source bastion 203.0.113.42 execute
  • $nftables-allow-source 198.51.100.25 203.0.113.42/32 plan
  • $nftables-allow-source edge-firewall 198.51.100.0/24 execute

Preconditions

  1. Confirm the host is in scope and operator-controlled.
  2. Confirm SSH or console access exists before changing the firewall.
  3. Confirm nft is installed and the host is actually using nftables.
  4. Prefer live insertion into the input chain before any persistent edit.

Execution Workflow

  1. Inspect the live input chain with handles.
bash
sudo nft -a list chain inet filter input

Use this to:

  • confirm the chain exists
  • see current rule order
  • identify whether a matching source rule already exists
  1. Verify whether the source is already allowed.
  • If already present in the live chain, do not insert a duplicate.
  • Record existing handle and position if present.
  1. Insert the allow rule at the top of the live input chain.

Preferred live insertion pattern:

bash
sudo nft insert rule inet filter input position 0 ip saddr <SOURCE> accept

This is the working method and should be preferred over editing /etc/nftables.conf first.

  1. Verify the live input chain immediately.
bash
sudo nft -a list chain inet filter input

Success means the new ip saddr <SOURCE> accept rule appears at the top of the input chain before the rest of the policy logic.

  1. Persist the same rule in /etc/nftables.conf.
  • insert ip saddr <SOURCE> accept comment "Authorized External IP" immediately after:
    • type filter hook input priority filter; policy drop;
  • do not rely on a broad grep for the source IP elsewhere in the file; check the input chain specifically
  • if /etc/nftables.conf is empty or corrupted, restore from the latest backup before editing
  • back up the file before changing it
  1. Reload and verify.
  • reload with:
    • sudo nft -f /etc/nftables.conf
  • verify both:
    • sudo sed -n '/chain input {/,/}/p' /etc/nftables.conf
    • sudo nft -a list chain inet filter input
  • confirm the persistent and live rules both contain the source allow at the top of the input chain
Show full SKILL.md (266 more words)Show less

Command Patterns

Live chain inspection
bash
sudo nft -a list chain inet filter input
Live top-of-chain insertion
bash
sudo nft insert rule inet filter input position 0 ip saddr 203.0.113.42 accept
Persistent config backup
bash
sudo cp /etc/nftables.conf /etc/nftables.conf.bak-$(date +%Y%m%d%H%M%S)
Persistent input-chain insertion
bash
sudo sed -i '/type filter hook input priority filter; policy drop;/a\        ip saddr 203.0.113.42 accept comment "Authorized External IP"' /etc/nftables.conf
Persistent config reload
bash
sudo nft -f /etc/nftables.conf
Post-reload verification
bash
sudo sed -n '/chain input {/,/}/p' /etc/nftables.conf
sudo nft -a list chain inet filter input

Prohibited Method

Do not use these approaches as the default workflow for this skill:

  • editing /etc/nftables.conf first and assuming reload will be safe
  • checking only whether the source IP exists somewhere in the file instead of in the input chain
  • adding the exception only to the management chain when the operator wants a host-wide source exception
  • broad text-rewrite methods that can blank or corrupt /etc/nftables.conf

OPSEC Gate

Require explicit operator confirmation before:

  • broad rules such as 0.0.0.0/0
  • wide CIDR additions that materially expand exposure
  • deleting or reordering existing firewall controls
  • reloading or restarting nftables on production-like hosts when access risk is non-trivial

Before requesting approval, include:

  • exact rule change
  • objective
  • expected impact
  • rollback plan
  • possible connectivity risk

Reporting Requirements

For each run, include:

  • target host
  • live chain modified: inet filter input
  • source IP/CIDR added
  • exact commands used
  • pre-change live chain output
  • post-change live chain output
  • persistent input-chain config snippet after edit
  • whether the rule is live only or also persistent
  • any remaining follow-up needed to reconcile config and runtime state

Troubleshooting Note

If a service is still unreachable after the source allow rule is added:

  1. verify the service is actually listening on the destination host
  2. compare reachability of the blocked port against a temporary listener on an alternate port on the same host
  3. if the alternate port succeeds while the original port fails, do not attribute the failure to nftables alone
  4. report that the environment or path may specifically disallow the original port

© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (assets) in plugins/ops-infrastructure/skills/nftables-allow-source of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/icon.png
  • assets/icon.svg

Open the folder on GitHubat commit e655f93

Compare with similar skills

Nftables Allow Source next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nftables Allow Source compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nftables Allow Source this skillSpecterOps/skills702—~1.5kAutomated safety check: NotesApache-2.0
Technical Analysttradermonty/claude-trading-skills3k5 repos~4.6kAutomated safety check: PassMIT
Polyclawchainstacklabs/polyclaw3601 repos~2kAutomated safety check: PassApache-2.0
Longbridge Researchhelsome/folio2693 repos~2.1kAutomated safety check: PassMIT
Stock Analysis24mlight/StockClaw1012 repos~2kAutomated safety check: NotesMIT
Swapper Depositswapperfinance/swapper-toolkit852—~1.8kAutomated safety check: PassMIT

Similar skills

  • Technical Analyst

    tradermonty/claude-trading-skills

    This skill should be used when analyzing weekly price charts for stocks, stock indices, cryptocurrencies, or forex pairs.

    3k GitHub starsUsed in 5 repos~4.6k tokens
    Business, Finance & HRAuto-check passed
  • Polyclaw

    chainstacklabs/polyclaw

    Trade on Polymarket via split + CLOB execution. An agent skill from chainstacklabs/polyclaw.

    360 GitHub starsUsed in 1 repo~2k tokens
    Business, Finance & HRAuto-check passed
  • Longbridge Research

    helsome/folio

    Institution ratings, consensus price targets, EPS/revenue forecasts, finance calendar, shareholder data, fund holders, insider trades (SEC Form 4), short interest, industry rankings, peer group…

    269 GitHub starsUsed in 3 repos~2.1k tokens
    Business, Finance & HRAuto-check passed
  • Stock Analysis

    24mlight/StockClaw

    Analyze stocks and cryptocurrencies using Yahoo Finance data.

    101 GitHub starsUsed in 2 repos~2k tokens
    Business, Finance & HRAuto-check: notes
  • Swapper Deposit

    swapperfinance/swapper-toolkit

    Deposit and bridge funds into a wallet or protocol using Swapper Finance.

    852 GitHub stars~1.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • Okx Cex Earn

    okx/agent-skills

    Manages OKX Simple Earn (flexible savings/lending), Flash Earn, On-chain Earn (staking/DeFi), Dual Investment (DCD/双币赢), and AutoEarn (自动赚币) via the okx CLI.

    185 GitHub starsUsed in 2 repos~3.3k tokens
    Business, Finance & HRAuto-check passed

More from SpecterOps/skills

All 38 skills in this repo
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    702 GitHub stars~805 tokensUpdated 14 days ago
    Auto-check passed
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    702 GitHub stars~1.5k tokensUpdated 14 days ago
    Auto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    702 GitHub stars~2.4k tokensUpdated 14 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    702 GitHub stars~665 tokensUpdated 14 days ago
    Auto-check passed
  • Nmap Parse

    SpecterOps/skills

    Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

    702 GitHub stars~738 tokensUpdated 14 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    702 GitHub stars~813 tokensUpdated 14 days ago
    Auto-check passed

Questions about Nftables Allow Source

What does Nftables Allow Source do?

Add a source IP or CIDR to nftables using the working method from this repo session: live top-of-input insertion with nft -a verification first, then persistent config update and reload. Nftables Allow Source is an agent skill from SpecterOps/skills. Add a source IP or CIDR to nftables using the working method from this repo session: live top-of-input insertion with nft -a verification first, then persistent config update and reload.

When should I use Nftables Allow Source?

Nftables Allow Source fits situations like: tasks that involve Crypto and DeFi analysis.

How do I install Nftables Allow Source in Claude Code?

Run `npx skills add SpecterOps/skills --skill nftables-allow-source -a claude-code`. Or copy the skill folder (plugins/ops-infrastructure/skills/nftables-allow-source in SpecterOps/skills) into .claude/skills/nftables-allow-source in your project. Claude Code loads it when a task matches its description.

How do I install Nftables Allow Source in Codex?

Run `npx skills add SpecterOps/skills --skill nftables-allow-source -a codex`. Or copy the skill folder (plugins/ops-infrastructure/skills/nftables-allow-source in SpecterOps/skills) into .agents/skills/nftables-allow-source in your project. Codex loads it when a task matches its description.

Can I use Nftables Allow Source in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill nftables-allow-source -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nftables-allow-source, .gemini/skills/nftables-allow-source, .github/skills/nftables-allow-source and .opencode/skills/nftables-allow-source in your project.

What does Nftables Allow Source need to run?

SKILL.md names no scripts, command-line tools or credentials: Nftables Allow Source is instructions for the agent only.

Does Nftables Allow Source access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nftables Allow Source safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Nftables Allow Source use?

Nftables Allow Source is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nftables Allow Source use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nftables Allow Source?

Skills that share tags, products or a category with Nftables Allow Source: Technical Analyst (tradermonty/claude-trading-skills, 3k stars), Polyclaw (chainstacklabs/polyclaw, 360 stars), Longbridge Research (helsome/folio, 269 stars) and Stock Analysis (24mlight/StockClaw, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nftables Allow Source?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 702 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.