121 checks
52 medium, 34 high, 27 low, 5 critical, and 3 info. 79 are security checks and 42 are reliability checks.
Search hans.study
Indexed across articles, news, KB updates, knowledge base, books, learning, and tools. Press Esc to close.
// Open-source Claude skill · Study Tools
This is a skill for Claude that audits Cisco IOS and IOS-XE switch running-configs for security and reliability defects, entirely offline. A Python engine runs 121 checks over the config text. Every finding carries a severity, the masked evidence line, a paste-ready fix, and a citation to DISA STIG, NSA, CISA, or Cisco guidance. It also generates hardened baseline configurations from a short spec.
Reading a switch running-config by eye is slow and inconsistent. This gives the same checks the same way every time, with a line number and a reason for each finding.
stig profile sits beside the default campus profile.--fail-on sets the exit code, and SARIF output feeds a code-scanning view.It covers Cisco IOS (12.x and 15.x Catalyst releases) and IOS-XE (3.x, 16.x, and 17.x) switches. It does not cover NX-OS, IOS-XR, ASA, or Meraki.
52 medium, 34 high, 27 low, 5 critical, and 3 info. 79 are security checks and 42 are reliability checks.
Each check cites DISA STIG (the IOS-XE Switch L2S and NDM STIGs), NSA, CISA, or Cisco guidance. The rationale text is written independently.
Generate a hardened baseline from a JSON spec, or compare two configs and see which hardening controls a change crossed.
| Area | Checks | Area | Checks |
|---|---|---|---|
| AAA | 12 | SSH | 9 |
| VTY | 11 | SNMP | 10 |
| NTP | 7 | Logging | 9 |
| Management plane | 14 | DHCP | 9 |
| Layer 2 | 14 | Spanning tree | 10 |
| Interfaces | 8 | Resilience | 8 |
101 checks are deterministic, 16 are heuristic because they rest on an inferred interface role, and 4 need a manual review with you. A --role-map corrects a wrong role guess. Output comes as a table, JSON, SARIF, or the whole config as masked text.
Secrets are masked on ingest, before any check, report, diff, or error message sees the text. A token shows the class and length of a credential, never the value, for example [REDACTED snmp-community, 8 chars]. Everything the scripts print is checked again, and a leaked secret stops the run. The skill never asks for a real credential and never decodes a type 7 password. The fix for one is to rotate it.
An excerpt of the audit of the repository's deliberately unhardened example config, in the table format. Evidence lines come from the config with secrets masked, and secret slots in a fix are <REPLACE-ME> placeholders.
SEVERITY CHECK CONF LINE TITLE
critical CSC-AAA-0010 det 23 Local user at privilege 15 with a type 0 or type 7 password - admin
evidence: username admin privilege 15 password 0 [REDACTED local-user-password, 23 chars]
fix: username <REPLACE-ME:local-username> algorithm-type sha256 secret <REPLACE-ME:local-user-secret>
critical CSC-MGT-0010 det 19 `vstack` (Smart Install client) not disabled
evidence: vstack
fix: no vstack
critical CSC-VTY-0001 det 70 A vty line accepts a non-SSH transport - vty 0 4
evidence: transport input telnet
fix: transport input ssh
high CSC-AAA-0001 det - `aaa new-model` not enabled
evidence: (not configured)
fix: aaa new-model
...
121 checks evaluated - 98 findings (6 critical, 30 high, 40 medium, 22 low)
platform ios (inferred-version) - skill 1.0.0 - catalogue 2026.09 It is a Claude skill, so you install it into Claude and ask in plain language. In Claude Code, the repository is its own plugin marketplace:
/plugin marketplace add hansstudy/cisco-switch-config
/plugin install cisco-switch-config@hansstudy-cisco Other routes: copy the skill folder into ~/.claude/skills/ or a project's .claude/skills/, upload the .zip under Settings, Capabilities, Skills in claude.ai, or upload it with the Claude API's skills.create. The install guide has the steps for each.
Then paste a show running-config, or point at a file, and ask:
Audit this Cisco switch config for security issues.
Generate a hardened baseline for a 48-port Catalyst access switch with VLANs 10/20/99.
What changed between these two configs, and does it matter? The skill drives three scripts, and each can be run on its own from the skill folder. They need Python 3.11 or later and nothing else.
python scripts/audit_config.py running-config.txt --format table
python scripts/audit_config.py running-config.txt --category security --severity-min medium
python scripts/audit_config.py running-config.txt --profile stig --fail-on high
python scripts/gen_baseline.py spec.json --out baseline.cfg
python scripts/diff_config.py before.cfg after.cfg --explain-checks Exit codes are shared by all three. 0 means it ran with nothing at or above --fail-on, 1 means findings at or above it, and 2 means the input was not usable. 3, 4, and 5 are an incomplete install, an internal error, and the masking guard tripping.
<REPLACE-ME> slots for secrets. Fill them on the device or from your secret store.Published as working software, not a supported product, with no SLA.
Apache-2.0. See the LICENSE in the repository. Cisco, Catalyst, IOS, and IOS-XE are trademarks of Cisco Systems, Inc. CIS and CIS Benchmarks are trademarks of the Center for Internet Security.
The skill audits configs that already exist. The browser-based switch configuration generator is a different tool: it builds a base config for Cisco Catalyst, Aruba CX, and ALE OmniSwitch from your VLAN scheme and addressing. If you want a person to read a set of switch configs and report back, that is the paid audit.
No. It works on config text only. It never connects to a switch, logs in, or fetches anything, and the engine uses no network and sends no telemetry.
Cisco IOS (12.x and 15.x Catalyst releases) and IOS-XE (3.x, 16.x, and 17.x) switches. It does not cover NX-OS, IOS-XR, ASA, or Meraki.
121 checks across AAA, SSH, VTY, SNMP, NTP, logging, management plane, DHCP, Layer 2, spanning tree, interfaces, and resilience. Each finding carries a severity, the masked evidence line, a paste-ready fix, and a citation. Findings are advisory, not a compliance attestation.
Secrets are masked on ingest, before any check, report, diff, or error message sees the text. Masking can't withdraw text you already pasted into a chat, so pass a file where you can and remove passwords, keys, and SNMP communities first.
In Claude Code, add the repository as a plugin marketplace with /plugin marketplace add hansstudy/cisco-switch-config, then install cisco-switch-config@hansstudy-cisco. You can also copy the skill folder into ~/.claude/skills/ or upload the zip in claude.ai.
The skill is open source under Apache-2.0, published as working software, not a supported product. If you want a person to read a set of switch configs and report back, that is the switch config audit service.
Source, the check catalogue, the install guide, and example configs and reports are in the repository.
Two tools run by default to help me understand how the site is used. You can turn either off at any time. Cloudflare's server-side analytics is always on and never sees your identity.