← 返回 Skills 市场
anmolnagpal

Nsg Firewall Auditor

作者 Anmol Nagpal · GitHub ↗ · v1.0.0
cross-platform ✓ 安全检测通过
333
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install nsg-firewall-auditor
功能描述
Audit Azure NSG rules and Azure Firewall policies for dangerous internet exposure
安全使用建议
This skill is instruction-only and appears coherent, but take these precautions before using it: (1) Run the az commands locally yourself and review the JSON output — do not paste any credentials, tokens, or connection strings. (2) If you must share data, redact or replace sensitive identifiers and public IPs when possible, or share a sanitized example. (3) Use least-privilege roles locally (Reader is sufficient for many exports; Network Contributor is only needed for some effective-rule queries). (4) The skill will produce recommended CLI commands and tightened JSON — review those before applying them in your environment. (5) Note the skill lists a price and 'pack' metadata in its header; this is informational and not required to run the guidance. If you need the auditor to run commands directly against your subscription, prefer a vetted tool or grant temporary, audited access rather than pasting secrets into chat.
功能分析
Type: OpenClaw Skill Name: nsg-firewall-auditor Version: 1.0.0 The skill is explicitly designed as 'instruction-only' and states it 'does not execute any Azure CLI commands or access your Azure account directly.' It instructs the agent to analyze user-provided data and explicitly forbids asking for credentials or secret keys, further instructing the agent to confirm no credentials are included in user-pasted data. While 'bash' is listed as a tool, its implied use is for displaying example commands, not for executing commands based on user-provided data, which is stated to be analyzed by 'Claude'. There is no evidence of malicious intent, data exfiltration, or unauthorized execution in the `SKILL.md` instructions.
能力评估
Purpose & Capability
The name/description match the instructions: the skill asks users to provide az CLI exports (NSG lists, effective rules, firewall policies) and describes checks and remediation. It does not request unrelated credentials, binaries, or access.
Instruction Scope
SKILL.md stays within scope (it instructs the agent to analyze user-provided exports and not to run CLI against the user's account). Minor inconsistency: the front-matter lists 'tools: claude, bash' though the body emphasizes that the skill will not execute Azure CLI — this is likely informational but could confuse less technical users. The skill explicitly warns to confirm exported data contains no credentials before processing.
Install Mechanism
No install spec and no code files — instruction-only, so nothing is written to disk or downloaded. This is the lowest-risk install model and matches the stated behavior.
Credentials
No environment variables, no credentials, and no config paths are requested. The skill requests exported CLI output and recommends minimum RBAC roles for running those CLI commands locally; those requirements are proportionate to the auditing task.
Persistence & Privilege
always is false and model invocation is allowed (platform default). The skill does not request persistent presence or modification of other skills or system-wide settings.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install nsg-firewall-auditor
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /nsg-firewall-auditor 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release: Azure NSG & Firewall Auditor skill (v1.0.0). - Provides step-by-step instructions to audit Azure NSG rules and firewall policies for risky internet exposure. - Analyzes user-supplied exports of NSG, effective rules, and Azure Firewall policies for critical misconfigurations. - Checks for internet-exposed management/database ports, missing NSGs, permissive rules, and disabled flow logs. - Outputs findings with recommendations, including tightened JSON NSG rules and Azure Policy examples. - Recommends Azure Bastion and JIT VM Access for management port security. - Does not run CLI commands or request credentials; user provides exported data only.
元数据
Slug nsg-firewall-auditor
版本 1.0.0
许可证
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Nsg Firewall Auditor 是什么?

Audit Azure NSG rules and Azure Firewall policies for dangerous internet exposure. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 333 次。

如何安装 Nsg Firewall Auditor?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install nsg-firewall-auditor」即可一键安装,无需额外配置。

Nsg Firewall Auditor 是免费的吗?

是的,Nsg Firewall Auditor 完全免费(开源免费),可自由下载、安装和使用。

Nsg Firewall Auditor 支持哪些平台?

Nsg Firewall Auditor 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Nsg Firewall Auditor?

由 Anmol Nagpal(@anmolnagpal)开发并维护,当前版本 v1.0.0。

💬 留言讨论