pyats-security

Automate network security audits for router and switch configurations.

Updated Feb 28, 2026
One-click install
npx skills add https://github.com/dgethings/netclaw --skill pyats-security-dgethings
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pyats-security
Source: https://github.com/dgethings/netclaw/tree/main/workspace/skills/pyats-security
Command: npx skills add https://github.com/dgethings/netclaw --skill pyats-security-dgethings

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates comprehensive network security audits to identify misconfigurations and hardening gaps in device configurations across ACLs, AAA, CoPP, management-plane settings, encryption, and port security, aligned with CIS benchmarks.

Core Features & Use Cases

  • Automated ACL and AAA checks to verify access security on devices
  • Control plane policing (CoPP) and management-plane hardening checks for CPU protection
  • Encryption and credentials validation to ensure strong crypto usage
  • CIS benchmark alignment and incident-response readiness for routers and switches
  • Use cases include pre-deployment hardening, incident investigation, and periodic security validation

Quick Start

Run a complete security audit on your target device and generate a findings report.

Frequently Asked Questions about pyats-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate network security audits for routers and switches?

Automate network security audits by running checks against device configurations to identify misconfigurations and hardening gaps. This process verifies ACLs, AAA, CoPP, management-plane settings, encryption, and port security to ensure compliance with security best practices.

Can I check my device configurations against CIS benchmarks?

Yes, you can check device configurations against CIS benchmarks. The audit evaluates routers and switches to verify alignment with security best practices, identifying hardening gaps in encryption, credentials, and control plane policing.

What is control plane policing and how does it protect network devices?

Control plane policing (CoPP) protects network devices by restricting unnecessary traffic to the CPU. Security audits verify CoPP and management-plane hardening configurations to prevent CPU exhaustion and ensure device stability.

When should I run a network hardening audit on my infrastructure?

Run a network hardening audit during pre-deployment, incident response, or periodic compliance checks. Auditing routers and switches in production or lab environments identifies misconfigurations in ACLs, AAA, and encryption before they can be exploited.

Does this security audit validate AAA and access control list configurations?

Yes, the security audit validates AAA and access control list (ACL) configurations. It automatically verifies access security on devices to ensure authentication, authorization, and traffic filtering rules adhere to security best practices.

What is the best way to find encryption and credential hardening gaps?

The best way to find encryption and credential hardening gaps is to automate a comprehensive security audit. This validates strong crypto usage and checks device configurations for weak credentials and misconfigured encryption protocols.