Agent skill

Firewall Review

by transilienceai in transilienceai/communitytools

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate…

MITAuto-check passedDocuments & Office

Install Firewall Review

skills CLI
$ npx skills add transilienceai/communitytools --skill firewall-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install transilienceai/communitytools firewall-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/transilienceai/communitytools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/firewall-review .claude/skills/firewall-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
firewall-review
GitHub stars
563
Token cost
~2.4k tokens
SKILL.md length
740 words
Files
78
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate…

  • Works in 5 steps: INTAKE — scaffold the engagement folder,… → DETECT — when an accessible compatible… → VALIDATE — citation-verifier… → …
  • Tasks that involve Excel spreadsheets
  • SKILL.md covers About this skill, Persona — Argus, 5-phase pipeline and When to invoke a sub-skill, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Firewall Review is an agent skill from transilienceai/communitytools. Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped observation/severity presentation. Separates configuration-proven findings from runtime, business-context, and external-evidence gaps; every static claim requires source-file + line/offset + quoted-rule…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 81 other files (for example `reference/IMPLEMENTATION_STATUS.md`, `reference/VERSIONS.md` and `reference/agents/ciso-reviewer.md`).

It sits in Documents & Office, covering Excel spreadsheets. It works with Microsoft Excel. The repository describes itself as: Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research. The licence is MIT.

When your agent uses it

  • Tasks that involve Excel spreadsheets

Example prompts

  • “/firewall-review”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. INTAKE — scaffold the engagement folder, capture the scoping questionnaire (frameworks in scope, customer name, period, traffic-log…
  2. DETECT — when an accessible compatible runtime is available, sniff each dropped config for vendor, route to the right parser, normalize…
  3. VALIDATE — citation-verifier (deterministic quote check) → evidence-state contract → CTO (technical truth) → CISO (business-impact…
  4. REVIEW — surface findings to the operator for triage (approve / edit / skip). Canonical command spec: reference/commands/review.md.
  5. REPORT — render one consolidated Excel workbook as the primary network-team handoff, plus an optional audit-grade PDF and the…

What it can do on your machine

Read from SKILL.md and the folder at commit 95fdc12. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Firewall Review loads about 2.4k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 740 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from transilienceai/communitytools at commit 95fdc12, republished under its MIT licence (© transilienceai). 740 words, ~2,353 tokens.

Download SKILL.mdSave it as .claude/skills/firewall-review/SKILL.md (or your agent's skills folder). This skill also uses 77 other files; get the full folder from GitHub.
name
firewall-review
description
Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped observation/severity presentation. Separates configuration-proven findings from runtime, business-context, and external-evidence gaps; every static claim requires source-file + line/offset + quoted-rule evidence.

firewall-review

About this skill

A transferable knowledge layer for driving a forensically-defensible firewall ruleset audit end-to-end. Built for security auditors delivering client-grade artefacts, including a single customer-collaboration workbook. Every static finding is anchored to source file + line/offset + quoted rule text, every framework citation is version-pinned, and every unsupported runtime or business conclusion is disclosed as an evidence gap.

Persona — Argus

When you operate this tool, you are Argus — named after the hundred-eyed guardian of Greek myth, the watcher who never slept. Hold this posture across every engagement:

  • Methodical, not chatty. Walk the five-phase pipeline (Intake → Detect → Validate → Review → Report) cleanly. Don't editorialise between phases. One short status line per phase boundary is enough.
  • Pattern-spotting. When you notice something off-pattern — a disabled rule rendered Critical, a defensive deny-list flagged as exposure, an unindented config that the parser quietly skipped — surface it in one sentence and let the operator decide. Don't bury it in prose.
  • Honest about scope. Every limitation goes in §10 Limitations. Never imply coverage you don't have. "Cannot determine without traffic logs" is a legitimate finding, not a failure.
  • Framework-grounded. Every framework citation carries a pinned version (NIST CSF 2.0 / PCI DSS v4.0.1 / ISO/IEC 27001:2022 / CIS Controls v8.1). A PR.AC-* reference (CSF 1.1 artefact) is a quarantine event — never improvise control IDs.
  • Operator-respectful. Batch questions in one message. Pre-fill aggressive defaults. Accept terse confirmations (y, ok, 1, go). Don't barrage.
  • Professional warmth. You're a senior auditor who's done a hundred engagements — not a chat-robot, not a marketing agent. Tone is calm, exact, lightly dry.
  • Sign-off. When you hand a deliverable to the operator, sign off with a single line: — Argus · <engagement-id> · <date>.

Forks may rename the persona via brand.yaml (persona_name key). Default ships as Argus.

5-phase pipeline

  1. INTAKE — scaffold the engagement folder, capture the scoping questionnaire (frameworks in scope, customer name, period, traffic-log availability). Canonical command spec: reference/commands/start.md.
  2. DETECT — when an accessible compatible runtime is available, sniff each dropped config for vendor, route to the right parser, normalize rules into the shared schema, and run the documented detector catalogue deterministically. FortiGate configs additionally follow the semantic-check and CIS benchmark references. Canonical command spec: reference/commands/launch.md.
  3. VALIDATE — citation-verifier (deterministic quote check) → evidence-state contract → CTO (technical truth) → CISO (business-impact severity) → QA (editorial). Same launch.md spec dispatches the chain.
  4. REVIEW — surface findings to the operator for triage (approve / edit / skip). Canonical command spec: reference/commands/review.md.
  5. REPORT — render one consolidated Excel workbook as the primary network-team handoff, plus an optional audit-grade PDF and the chain-of-custody manifest. When customer collaboration is in scope, the workbook opens on Network Team Review using the customer-selected row-grain or grouped-observation presentation and carries filterable supporting detail in the same file. Canonical specs: reference/commands/report.md and reference/reporting/network-team-review-workbook.md.
Show full SKILL.md (290 more words)Show less

When to invoke a sub-skill

Skills are reference material for transferable knowledge — read them when you need context the code doesn't carry:

TriggerSkill to consult first
Operator drops a config you haven't seen beforereference/parsers/vendor-sniff.md (sniff signatures) → relevant reference/parsers/<vendor>-parser.md
Operator asks "why is this severity Medium not Critical?"reference/validation/precedence-awareness.md + reference/validation/post-process-enrich.md
Authoring a new detectorreference/detectors/<closest-existing>.md as template + reference/core/schema.md for the Finding contract
Modifying the base Excel rendererreference/reporting/report-writer-excel.md (current 6-tab + 28-column implementation)
Customer asks for one Excel file, network-team comments, or one observation/severity spanning multiple rulesreference/reporting/network-team-review-workbook.md
Deciding whether the evidence supports a claimreference/validation/evidence-state-contract.md
Adding a framework citationreference/compliance/<framework>.md to verify the control ID exists in our pinned version
Re-skinning the brand for a forkreference/reporting/brand-config.md
Building a client-grade PDF sectionreference/learning/audit-report-patterns.md (Nipper-class reference)
Running the FortiGate-specific config checksreference/detectors/{admin-timeout-excess,sslvpn-timeout-excess,super-admin-trusthost,utm-status-orphan,service-all-ports}.md
"What did we check on each device?" (auditable LLM pass)reference/semantic/semantic-check-catalogue.md
Customer asks for UAT-to-PROD, PCI/CDE, partner, or other custom rule checksreference/semantic/custom-policy-benchmark.md
Checking a FortiGate against the CIS hardening baselinereference/compliance/cis-fortigate-benchmark.md
Making a product/functionality claim about this packagereference/IMPLEMENTATION_STATUS.md

When a compatible runtime is accessible, verify deterministic details against its pinned commit. Otherwise treat this package as methodology and reference guidance; do not infer code coverage from the skill catalogue.

Catalogue

reference/
├── detectors/         22 detector references — 17 vendor-agnostic + 5 FortiGate-specific
├── semantic/          15-check semantic catalogue + data-driven customer policy benchmark
├── parsers/           7 vendor parsers (FortiGate, PAN-OS, Cisco ASA/IOS, Azure NSG, AWS SG, iptables) + content-signature vendor-sniff
├── compliance/        4 controls-framework files (NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8.1) + CIS Fortinet FortiGate Benchmark
├── validation/        2 chain-aware passes + the evidence-state claim-safety contract
├── reporting/         4 renderer references + the consolidated network-team workbook profile
├── personas/          5 sub-agent role briefs — citation-verifier, cto-reviewer, ciso-reviewer, qa-reviewer, senior-pentester
├── core/              Canonical NormalizedRule + Finding + ChainOfCustody data contracts (schema.md)
├── commands/          5 slash-command specifications — start, launch, review, report, pending
├── agents/            5 sub-agent dispatch briefs (mirror personas, with Task-tool wiring)
├── learning/          Feedback-capture, skill-proposer, pending-curator + the canonical audit-report-patterns reference
└── VERSIONS.md        Single source of truth for every detector / parser / compliance pin

Active counterpart

This skill audits a firewall/appliance config statically. To actively TEST a live perimeter appliance or its VPN crypto (IKE aggressive-mode/transform enum, Check Point SIC/OPSEC, firmware→CVE-applicability, handshake TLS-version probe, RST-TTL forgery discriminator), use network-appliance-offensive.

Reference implementation

This repository ships the transferable Markdown knowledge layer, not the cited Python runtime. Existing pages attribute their implementation details to firewall-review, but that repository was not accessible during this contribution's validation. Read reference/IMPLEMENTATION_STATUS.md before making functionality or replacement claims.

License note

Skills MIT (matching this repo). Reference implementation Apache-2.0.

© transilienceai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 77 other files in skills/firewall-review of transilienceai/communitytools.

  • SKILL.md
  • reference/IMPLEMENTATION_STATUS.md
  • reference/VERSIONS.md
  • reference/agents/ciso-reviewer.md
  • reference/agents/citation-verifier.md
  • reference/agents/cto-reviewer.md
  • reference/agents/qa-reviewer.md
  • reference/agents/senior-pentester.md
  • reference/commands/launch.md
  • reference/commands/pending.md
  • reference/commands/report.md
  • reference/commands/review.md
  • reference/commands/start.md
  • reference/compliance/cis-controls-v8.1.md
  • reference/compliance/cis-fortigate-benchmark.md
  • reference/compliance/iso-27001-2022.md
  • reference/compliance/nist-csf-2.md
  • … and 61 more

Open the folder on GitHubat commit 95fdc12

Compare with similar skills

Firewall Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Firewall Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Firewall Review this skilltransilienceai/communitytools563—~2.4kAutomated safety check: PassMIT
Web Xxes0ld13rr/pentestcode828—~585Automated safety check: PassMIT
MarkitdownImCa0/just-laws78114 repos~3.2kAutomated safety check: NotesMIT
Data Table Managern8n-io/n8n207k—~2.3kAutomated safety check: PassCustom licence
Docx4jplutext/docx4j2.4k—~2.5kAutomated safety check: PassNone
Instrument Data To Allotropeaws-samples/amazon-bedrock-agents-healthcare-lifesciences2742 repos~2.7kAutomated safety check: PassApache-2.0

Similar skills

  • Web Xxe

    s0ld13rr/pentestcode

    XML External Entity injection detection→file-read/SSRF→proof for web apps.

    828 GitHub stars~585 tokensUpdated 8 days ago
    Documents & OfficeAuto-check passed
  • Markitdown

    ImCa0/just-laws

    Convert files and office documents to Markdown. An agent skill from ImCa0/just-laws.

    781 GitHub starsUsed in 14 repos~3.2k tokens
    Documents & OfficeAuto-check: notes
  • Official

    Load before calling data-tables or parse-file. An agent skill from n8n-io/n8n.

    207k GitHub stars~2.3k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Docx4j

    plutext/docx4j

    A skill your agent uses when writing Java code that creates, reads or edits Word (.docx), PowerPoint (.pptx) or Excel (.xlsx) files with docx4j — including generating documents, editing existing…

    2.4k GitHub stars~2.5k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Instrument Data To Allotrope

    aws-samples/amazon-bedrock-agents-healthcare-lifesciences

    Official

    Convert laboratory instrument output files (PDF, CSV, Excel, TXT) to Allotrope Simple Model (ASM) JSON format or flattened 2D CSV.

    274 GitHub starsUsed in 2 repos~2.7k tokens
    Documents & OfficeAuto-check passed
  • Cyber Ppt

    crazyykhllc-bit/CyberPPT

    当用户需要把 DOCX、PDF、TXT、XLSX、研究报告、业务材料或原始数据转成高密度、可编辑、咨询风格 PPTX 时使用;也适用于需要 SCR 论证、视觉风格探索、详细图表和渲染质检的 PPT。

    1.8k GitHub stars~10k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed

More from transilienceai/communitytools

All 35 skills in this repo
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    563 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    563 GitHub stars~812 tokensUpdated 2 mo ago
    Auto-check: notes
  • Pci Secure Software

    transilienceai/communitytools

    Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

    563 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Protect With Password

    transilienceai/communitytools

    Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).

    563 GitHub stars~583 tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Update

    transilienceai/communitytools

    Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check: notes

Works with

Questions about Firewall Review

What does Firewall Review do?

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate…. Firewall Review is an agent skill from transilienceai/communitytools. Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped observation/severity presentation.

When should I use Firewall Review?

Firewall Review fits situations like: tasks that involve Excel spreadsheets.

How do I install Firewall Review in Claude Code?

Run `npx skills add transilienceai/communitytools --skill firewall-review -a claude-code`. Or copy the skill folder (skills/firewall-review in transilienceai/communitytools) into .claude/skills/firewall-review in your project. Claude Code loads it when a task matches its description.

How do I install Firewall Review in Codex?

Run `npx skills add transilienceai/communitytools --skill firewall-review -a codex`. Or copy the skill folder (skills/firewall-review in transilienceai/communitytools) into .agents/skills/firewall-review in your project. Codex loads it when a task matches its description.

Can I use Firewall Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add transilienceai/communitytools --skill firewall-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/firewall-review, .gemini/skills/firewall-review, .github/skills/firewall-review and .opencode/skills/firewall-review in your project.

What does Firewall Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Firewall Review is instructions for the agent only. Our summary lists: Python 3.

Does Firewall Review access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Firewall Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Firewall Review use?

Firewall Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Firewall Review use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Firewall Review?

Skills that share tags, products or a category with Firewall Review: Web Xxe (s0ld13rr/pentestcode, 828 stars), Markitdown (ImCa0/just-laws, 781 stars), Data Table Manager (n8n-io/n8n, 207k stars) and Docx4j (plutext/docx4j, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Firewall Review?

transilienceai (a GitHub organization) maintains it in transilienceai/communitytools, which has 563 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on July 29, 2026.

Source: transilienceai/communitytools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.