What problem does it solve? Firewall compliance reviews against DISA STIGs are error-prone: agents and engineers mix benchmark releases, overstate findings from incomplete evidence, or claim compliance they cannot defend in an audit. This Skill pins the assessment to the verified DISA Y25M01 SRX benchmark and enforces conservative, evidence-based rule statuses. ## Core Features & Use Cases - Source-pinned rule catalogs: Evaluates 148 rules across NDM, ALG, IDPS, and VPN components with preserved V-ID, SV-ID, JUSX identifiers, and CAT severities, failing closed if the checksum does not match. - Four-class evidence model: Classifies normalized config, raw config, operational output, and manual evidence separately, defaulting to Not Reviewed when proof is incomplete. - Junos compatibility tracking: Separates formal STIG status from current Junos support, flagging legacy or contradictory benchmark guidance for verification before remediation. - Use Case: Given a redacted SRX configuration export and operational command output, produce an assessor-ready report with per-rule status, evidence gaps, and remediation candidates routed to the appropriate SRX configuration skills. ## Quick Start Use the srx-disa-stig-compliance skill to assess this parsed SRX configuration and show version output against the DISA Y25M01 STIG and list all Open and Not Reviewed rules.