Back to skill

Security audit

Cisco Firewall Audit

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Cisco firewall audit guide that needs authorized access to sensitive firewall data but does not install code or perform changes.

Use this only with explicit authorization for the Cisco firewall environment. Prefer a read-only audit account, keep the scope limited to named ASA/FTD devices and FMC domains, and treat collected configs, VPN data, policy exports, and logs as sensitive security information.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.