// Open-source Claude skill · Study Tools

Cisco switch config audit skill

This is a skill for Claude that audits Cisco IOS and IOS-XE switch running-configs for security and reliability defects, entirely offline. A Python engine runs 121 checks over the config text. Every finding carries a severity, the masked evidence line, a paste-ready fix, and a citation to DISA STIG, NSA, CISA, or Cisco guidance. It also generates hardened baseline configurations from a short spec.

Who it is for

Reading a switch running-config by eye is slow and inconsistent. This gives the same checks the same way every time, with a line number and a reason for each finding.

  • Before an assessment or a handover. Run a config through it to find what a reviewer will find, or to see what you are inheriting from whoever built the switch.
  • Whether a config is safe for production. Ask it directly, and get findings ranked by severity.
  • Meeting the DISA STIG. A stig profile sits beside the default campus profile.
  • Pipelines. --fail-on sets the exit code, and SARIF output feeds a code-scanning view.

It covers Cisco IOS (12.x and 15.x Catalyst releases) and IOS-XE (3.x, 16.x, and 17.x) switches. It does not cover NX-OS, IOS-XR, ASA, or Meraki.

What it checks and produces

CHK-01

121 checks

52 medium, 34 high, 27 low, 5 critical, and 3 info. 79 are security checks and 42 are reliability checks.

CHK-02

Cited fixes

Each check cites DISA STIG (the IOS-XE Switch L2S and NDM STIGs), NSA, CISA, or Cisco guidance. The rationale text is written independently.

CHK-03

Baselines and diffs

Generate a hardened baseline from a JSON spec, or compare two configs and see which hardening controls a change crossed.

The 121 checks by area

AreaChecksAreaChecks
AAA12SSH9
VTY11SNMP10
NTP7Logging9
Management plane14DHCP9
Layer 214Spanning tree10
Interfaces8Resilience8

101 checks are deterministic, 16 are heuristic because they rest on an inferred interface role, and 4 need a manual review with you. A --role-map corrects a wrong role guess. Output comes as a table, JSON, SARIF, or the whole config as masked text.

Credentials are masked first

Secrets are masked on ingest, before any check, report, diff, or error message sees the text. A token shows the class and length of a credential, never the value, for example [REDACTED snmp-community, 8 chars]. Everything the scripts print is checked again, and a leaked secret stops the run. The skill never asks for a real credential and never decodes a type 7 password. The fix for one is to rotate it.

A sample of the output

An excerpt of the audit of the repository's deliberately unhardened example config, in the table format. Evidence lines come from the config with secrets masked, and secret slots in a fix are <REPLACE-ME> placeholders.

SEVERITY  CHECK          CONF  LINE  TITLE
critical  CSC-AAA-0010   det     23  Local user at privilege 15 with a type 0 or type 7 password - admin
          evidence: username admin privilege 15 password 0 [REDACTED local-user-password, 23 chars]
          fix: username <REPLACE-ME:local-username> algorithm-type sha256 secret <REPLACE-ME:local-user-secret>
critical  CSC-MGT-0010   det     19  `vstack` (Smart Install client) not disabled
          evidence: vstack
          fix: no vstack
critical  CSC-VTY-0001   det     70  A vty line accepts a non-SSH transport - vty 0 4
          evidence: transport input telnet
          fix: transport input ssh
high      CSC-AAA-0001   det      -  `aaa new-model` not enabled
          evidence: (not configured)
          fix: aaa new-model
...
121 checks evaluated - 98 findings (6 critical, 30 high, 40 medium, 22 low)
platform ios (inferred-version) - skill 1.0.0 - catalogue 2026.09

How to run it

It is a Claude skill, so you install it into Claude and ask in plain language. In Claude Code, the repository is its own plugin marketplace:

/plugin marketplace add hansstudy/cisco-switch-config
/plugin install cisco-switch-config@hansstudy-cisco

Other routes: copy the skill folder into ~/.claude/skills/ or a project's .claude/skills/, upload the .zip under Settings, Capabilities, Skills in claude.ai, or upload it with the Claude API's skills.create. The install guide has the steps for each.

Then paste a show running-config, or point at a file, and ask:

Audit this Cisco switch config for security issues.
Generate a hardened baseline for a 48-port Catalyst access switch with VLANs 10/20/99.
What changed between these two configs, and does it matter?

The skill drives three scripts, and each can be run on its own from the skill folder. They need Python 3.11 or later and nothing else.

python scripts/audit_config.py running-config.txt --format table

python scripts/audit_config.py running-config.txt --category security --severity-min medium

python scripts/audit_config.py running-config.txt --profile stig --fail-on high

python scripts/gen_baseline.py spec.json --out baseline.cfg

python scripts/diff_config.py before.cfg after.cfg --explain-checks

Exit codes are shared by all three. 0 means it ran with nothing at or above --fail-on, 1 means findings at or above it, and 2 means the input was not usable. 3, 4, and 5 are an incomplete install, an internal error, and the masking guard tripping.

Limits and safety notes

  • Config text only. It never connects to a switch, logs in, or fetches anything. The engine uses no network and sends no telemetry.
  • Pasted text stays in the conversation. Masking covers what the scripts read and print. It cannot withdraw text you already pasted into a chat, so pass a file where you can, and remove passwords, keys, and SNMP communities first.
  • Three masking gaps. A secret written before its trigger word, a trigger split across two comment lines, and a secret embedded in an identifier such as a VLAN name or hostname can appear in clear. The skill is built to tell you which line and to recommend rotating it.
  • Advisory, not an attestation. Findings are not a compliance attestation. This is not a CIS Benchmark, and this catalogue version carries no CIS cross-references. It is not affiliated with or endorsed by Cisco, CIS, DISA, NSA, or CISA.
  • Judgment stays with you. The scripts decide what is present and what fired. Whether a finding matters for your network, and in what order to fix things, is for you and Claude to work out. Reachability and routing questions need a network model, not one config.
  • Placeholders stay empty. Generated baselines carry <REPLACE-ME> slots for secrets. Fill them on the device or from your secret store.

Published as working software, not a supported product, with no SLA.

Licence

Apache-2.0. See the LICENSE in the repository. Cisco, Catalyst, IOS, and IOS-XE are trademarks of Cisco Systems, Inc. CIS and CIS Benchmarks are trademarks of the Center for Internet Security.

Two Cisco offerings, and a service

The skill audits configs that already exist. The browser-based switch configuration generator is a different tool: it builds a base config for Cisco Catalyst, Aruba CX, and ALE OmniSwitch from your VLAN scheme and addressing. If you want a person to read a set of switch configs and report back, that is the paid audit.

Questions

Does the Cisco switch config audit skill connect to my switch?

No. It works on config text only. It never connects to a switch, logs in, or fetches anything, and the engine uses no network and sends no telemetry.

Which Cisco platforms does it cover?

Cisco IOS (12.x and 15.x Catalyst releases) and IOS-XE (3.x, 16.x, and 17.x) switches. It does not cover NX-OS, IOS-XR, ASA, or Meraki.

What does the skill check?

121 checks across AAA, SSH, VTY, SNMP, NTP, logging, management plane, DHCP, Layer 2, spanning tree, interfaces, and resilience. Each finding carries a severity, the masked evidence line, a paste-ready fix, and a citation. Findings are advisory, not a compliance attestation.

Are my passwords and SNMP communities masked?

Secrets are masked on ingest, before any check, report, diff, or error message sees the text. Masking can't withdraw text you already pasted into a chat, so pass a file where you can and remove passwords, keys, and SNMP communities first.

How do I install it?

In Claude Code, add the repository as a plugin marketplace with /plugin marketplace add hansstudy/cisco-switch-config, then install cisco-switch-config@hansstudy-cisco. You can also copy the skill folder into ~/.claude/skills/ or upload the zip in claude.ai.

Is it free, or should I hire you for a switch audit?

The skill is open source under Apache-2.0, published as working software, not a supported product. If you want a person to read a set of switch configs and report back, that is the switch config audit service.

The skill on GitHub

Source, the check catalogue, the install guide, and example configs and reports are in the repository.