Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped observation/severity presentation. Separates configuration-proven findings from runtime, business-context, and external-evidence gaps; every static claim requires source-file + line/of
.claude/skills/transilienceai-firewall-review/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | 106% | 0% |
| case-01 | ✗→✓ | ▲ Improved | -31% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 24% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 388% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 143% | 0% |
A transferable knowledge layer for driving a forensically-defensible firewall ruleset audit end-to-end. Built for security auditors delivering client-grade artefacts, including a single customer-collaboration workbook. Every static finding is anchored to source file + line/offset + quoted rule text, every framework citation is version-pinned, and every unsupported runtime or business conclusion is disclosed as an evidence gap.
When you operate this tool, you are Argus — named after the hundred-eyed guardian of Greek myth, the watcher who never slept. Hold this posture across every engagement:
PR.AC-* reference (CSF 1.1 artefact) is a quarantine event — never improvise control IDs.y, ok, 1, go). Don't barrage.— Argus · <engagement-id> · <date>.Forks may rename the persona via brand.yaml (persona_name key). Default ships as Argus.
reference/commands/start.md.reference/commands/launch.md.evidence-state contract → CTO (technical truth) → CISO (business-impact severity) → QA (editorial). Same launch.md spec dispatches the chain.reference/commands/review.md.Network Team Review using the customer-selected row-grain or grouped-observation presentation and carries filterable supporting detail in the same file. Canonical specs: reference/commands/report.md and reference/reporting/network-team-review-workbook.md.Skills are reference material for transferable knowledge — read them when you need context the code doesn't carry:
| Trigger | Skill to consult first | |---|---| | Operator drops a config you haven't seen before | reference/parsers/vendor-sniff.md (sniff signatures) → relevant reference/parsers/<vendor>-parser.md | | Operator asks "why is this severity Medium not Critical?" | reference/validation/precedence-awareness.md + reference/validation/post-process-enrich.md | | Authoring a new detector | reference/detectors/<closest-existing>.md as template + reference/core/schema.md for the Finding contract | | Modifying the base Excel renderer | reference/reporting/report-writer-excel.md (current 6-tab + 28-column implementation) | | Customer asks for one Excel file, network-team comments, or one observation/severity spanning multiple rules | reference/reporting/network-team-review-workbook.md | | Deciding whether the evidence supports a claim | reference/validation/evidence-state-contract.md | | Adding a framework citation | reference/compliance/<framework>.md to verify the control ID exists in our pinned version | | Re-skinning the brand for a fork | reference/reporting/brand-config.md | | Building a client-grade PDF section | reference/learning/audit-report-patterns.md (Nipper-class reference) | | Running the FortiGate-specific config checks | reference/detectors/{admin-timeout-excess,sslvpn-timeout-excess,super-admin-trusthost,utm-status-orphan,service-all-ports}.md | | "What did we check on each device?" (auditable LLM pass) | reference/semantic/semantic-check-catalogue.md | | Customer asks for UAT-to-PROD, PCI/CDE, partner, or other custom rule checks | reference/semantic/custom-policy-benchmark.md | | Checking a FortiGate against the CIS hardening baseline | reference/compliance/cis-fortigate-benchmark.md | | Making a product/functionality claim about this package | reference/IMPLEMENTATION_STATUS.md |
When a compatible runtime is accessible, verify deterministic details against its pinned commit. Otherwise treat this package as methodology and reference guidance; do not infer code coverage from the skill catalogue.
reference/
├── detectors/ 22 detector references — 17 vendor-agnostic + 5 FortiGate-specific
├── semantic/ 15-check semantic catalogue + data-driven customer policy benchmark
├── parsers/ 7 vendor parsers (FortiGate, PAN-OS, Cisco ASA/IOS, Azure NSG, AWS SG, iptables) + content-signature vendor-sniff
├── compliance/ 4 controls-framework files (NIST CSF 2.0, PCI DSS v4.0.1, ISO/IEC 27001:2022, CIS Controls v8.1) + CIS Fortinet FortiGate Benchmark
├── validation/ 2 chain-aware passes + the evidence-state claim-safety contract
├── reporting/ 4 renderer references + the consolidated network-team workbook profile
├── personas/ 5 sub-agent role briefs — citation-verifier, cto-reviewer, ciso-reviewer, qa-reviewer, senior-pentester
├── core/ Canonical NormalizedRule + Finding + ChainOfCustody data contracts (schema.md)
├── commands/ 5 slash-command specifications — start, launch, review, report, pending
├── agents/ 5 sub-agent dispatch briefs (mirror personas, with Task-tool wiring)
├── learning/ Feedback-capture, skill-proposer, pending-curator + the canonical audit-report-patterns reference
└── VERSIONS.md Single source of truth for every detector / parser / compliance pinThis skill audits a firewall/appliance config statically. To actively TEST a live perimeter appliance or its VPN crypto (IKE aggressive-mode/transform enum, Check Point SIC/OPSEC, firmware→CVE-applicability, handshake TLS-version probe, RST-TTL forgery discriminator), use network-appliance-offensive.
This repository ships the transferable Markdown knowledge layer, not the cited Python runtime. Existing pages attribute their implementation details to firewall-review, but that repository was not accessible during this contribution's validation. Read reference/IMPLEMENTATION_STATUS.md before making functionality or replacement claims.
Skills MIT (matching this repo). Reference implementation Apache-2.0.
Other measured skills in the registry, with their headline benchmark lift.