What problem does it solve? Palo Alto firewall and Panorama configurations are large, deeply nested XML documents where a missed vsys scope, a flattened pre/post-rulebase, or a silently dropped dynamic address group produces wrong audit findings and broken migrations. This Skill parses PAN-OS exports deterministically into a shared vendor-neutral schema so audits, conversions, and diffs rest on verified structure rather than plausible guesses. ## Core Features & Use Cases - Full-config extraction: Parses zones, address/service objects and groups, security policies, NAT and decryption rules, interfaces, routing (static, OSPF, OSPFv3, BGP), HA, VPN/IPsec, DHCP, admin users, and system settings from both XML and set-format exports, with multi-vsys and Panorama pre/post-rulebase handling. - Application resolution and audit checks: Maps PAN-OS App-IDs to canonical applications with confidence scores, then runs checks for unused objects, shadowed rules, overly permissive policies, missing logging, and User-ID or URL-category dependencies. - Use Case: You receive a Panorama export spanning three device-groups and need a migration assessment. The Skill parses every rulebase in correct evaluation order, flags dynamic address groups and unresolvable App-IDs, masks pre-shared keys, and emits schema-conformant JSON ready for the conversion or diff skills. ## Quick Start Ask the agent to parse the attached PAN-OS XML export into the shared firewall schema and report object counts, unresolved references, and audit findings.