Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add automateyournetwork/netclaw --skill fortianalyzer-opsgit clone --depth 1 https://github.com/automateyournetwork/netclawWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/automateyournetwork/netclaw/fortianalyzer-ops)<a href="https://agentmods.dev/skills/automateyournetwork/netclaw/fortianalyzer-ops"><img src="https://agentmods.dev/badge/skills/automateyournetwork/netclaw/fortianalyzer-ops/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/automateyournetwork/netclaw/fortianalyzer-ops"><img src="https://agentmods.dev/badge/skills/automateyournetwork/netclaw/fortianalyzer-ops.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.01433 |
| Opus 5 | $0.00032 | $0.00717 |
| Sonnet 5 | $0.00013 | $0.00287 |
| Haiku 4.5 | $0.00006 | $0.00143 |
Grade A, and why
fortianalyzer-ops scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 124 lines — stays where its author put it; the contents beside it link to each section on GitHub.
FortiAnalyzer Operations — the analyzer plane
MCP Server
- Server:
fortinet-mcp(NetClaw-authored, spec 080 / roadmap R3) - Command:
$FORTINET_MCP_CMD - Transport: stdio · JSON-RPC over
/jsonrpc(the same dialect FortiManager speaks) - Requires:
FORTIANALYZER_HOST,FORTIANALYZER_API_TOKEN(FortiAnalyzer 7.2.2+ for token auth) - Mode: read-only
The one rule that matters most here
"No logs matched" is NOT "this rule is unused."
This skill exists to answer "is this rule dead?" — and that question is dangerously easy to answer wrongly. An empty result can mean:
- nothing matched in the window you queried (retention is finite; history is not)
- the device never forwarded logs to this analyzer at all
- logging is disabled on the rule itself
Reporting any of those as "unused" would license someone to delete a live firewall
rule. So an empty result returns the explicit outcome no_logs_in_window, never
ok and never an error, with a message saying what it does and does not prove.
This is the same error class as spec 078's "no advisories ≠ not vulnerable" and spec 079's "no probes found ≠ outage", and it gets the same treatment: a separate, named outcome that cannot be silently collapsed.
Where this plane sits
| Question | Plane | Skill |
|---|---|---|
| "Has anything actually matched this rule?" | analyzer | this skill |
| "What policy is intended?" | manager | fortimanager-ops |
| "What is the box running right now?" | device | fortigate-ops |
The manager knows a rule exists. Only the analyzer knows whether anyone ever matched it. A configured rule is not a used rule.
Tools (4, all read-only)
| Tool | What it answers |
|---|---|
faz_query_logs |
Traffic logs matching a filter within a bounded window |
faz_fetch_more |
Next page, re-run at an offset |
faz_policy_activity |
Did anything match policy N in this window? |
faz_list_devices |
Which devices forward logs here — check this first |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 124 lines · 63 tokens per session scan A 1875906f7c45
fortianalyzer-ops is a skill published in the GitHub repository automateyournetwork/netclaw (655 stars, last pushed 4d ago), licensed Apache-2.0. It adds 63 tokens to every session and 1,433 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
analyzing-kubernetes-audit-logs
Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes cluster compromise or building k8s-specific SIEM detection rules.
analyzing-kubernetes-audit-logs
Use when parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat detection rules from audit event patterns. Use when investigating Kubernetes cluster compromise or building k8s-specific SIEM…
sd-onprem-proxmox-deploy
Deploy and validate Juniper Security Director On-Prem 25/26 as a Proxmox VE KVM guest. Use when planning, installing, rebuilding, validating network connectivity or first-boot seed data, and onboarding SRX/Junos devices. Not for Junos Space Security Director or Security Director Cloud.
srx-policy
Design, migrate, configure, audit, and troubleshoot Juniper SRX security policy on Junos 23.x+ non-Branch platforms. Use when handling global or zone policy, address and application objects, AppID, AppFW, NGWF, EWF, SecIntel, ATP, logging, rule order, hit counts, default deny, or cross-VLAN mDNS and SSDP boundaries.
parsing-cisco-configs
Parse Cisco ASA and FTD LINA running configurations into the shared firewall schema. Use when input contains show running-config, access-list, access-group, object network, object-group, nameif, security-level, NAT, interfaces, or failover, including audit, conversion, diff, summary, and explanation tasks. For FMC- or…
parsing-fortinet-configs
Parse FortiGate and FortiOS full-configuration or backup exports into the shared firewall schema. Use when input contains config/edit/set/next/end blocks, VDOM, firewall policy or address, srcintf, dstintf, UTM profiles, or VIPs, including audit, conversion, diff, summary, and explanation tasks.