About this project

fwskillsshare is a collection of 31 agent skills aimed at firewall and network-security engineers. Each skill is plain markdown (plus an agents/openai.yaml, and Python helpers in two deployment skills) that gets loaded into a coding agent's context so it follows vendor-checked syntax instead of inventing plausible-looking configuration. The README is explicit that skills are instructions the agent will act on, that pasted configs should be treated as untrusted input, and that secrets in firewall configs should not be sent to a hosted model provider unless that is a deliberate decision. The skills fall into five families. Config parsers normalize Cisco ASA/FTD, Cisco Firepower (FMC/FDM JSON), FortiGate/FortiOS, Palo Alto PAN-OS/Panorama and Juniper SRX/Junos configurations into one vendor-neutral intermediate JSON schema covering zones, objects, policies, NAT, routing, VPN and HA, with a canonical L7 application map and confidence scores. Cross-vendor tooling then works on that schema: a best-practices audit (any-any rules, shadowed or orphaned rules, missing deny/logging, exposed plaintext services, weak crypto, device-plane hardening), a config conversion skill with a per-section fidelity report, and a meaning-based config diff for drift, HA parity or migration validation. SRX operational playbooks cover policy, NAT, multi-node high availability, ADVPN, AutoVPN full tunnel, static IPsec hub-and-spoke, chassis cluster on Proxmox VE, MPLS L3VPN in flow mode, dynamic IP feeds, license and signature maintenance, initial setup, IPS triage and syslog/SIEM logging. Several are pinned to syntax validated on real hardware, including specific Junos commit errors and ADVPN certificate-authentication failures. Seven compliance playbooks map firewall capability to control evidence for PCI DSS v4.0.1, HIPAA, CMMC/NIST SP 800-171, CIS Controls v8/v8.1, ISO/IEC 27001:2022, SOC 2 and the DISA SRX STIG. The README stresses that a firewall supports evidence for a control and is never itself certified, and that compliance is assessed for the environment and program. A deployment family covers HPE Aruba ClearPass Policy Manager 6.14, Juniper Security Director On-Prem 25/26 and Juniper cSRX, all as Proxmox VE guests, with sizing, first-boot and validation guidance. Installation is via an interactive or flag-driven install.sh that copies skills into Claude Code, Codex or Hermes skill directories; skills are copied rather than linked, so re-running the installer is needed for updates. The project states that 26 of 31 skills have passed independent technical review, with three shipping as drafts and two not yet through the two-stage review. It is an unofficial community project, not affiliated with any of the named vendors, and is MIT licensed.