# Audit UniFi Security Policies

UniFi teams need clear reviews of zones, ACLs, and guest access. This skill guides Claude, Codex, and Claude Code through audits, policy checks, and compliance-ready summaries.

## Install

```bash
npx skillstore add dataknifeai/security-management
```

## Metadata

- Status: approved
- Slug: dataknifeai-security-management
- Skillstore revision: r1
- Version status: missing
- Tree hash: 0c7b7e8b3cdd1f41a6407408fe1b4f0fbc2c630e74c3b780b6d62aec12bd3521
- Author: DataKnifeAI
- GitHub username: DataKnifeAI
- License: MIT
- Repository: https://github.com/DataKnifeAI/unifi-network-mcp/tree/main/.github/skills/security-management
- Ref: 34f316ba14ef36c7a620fc09f2676d2429997a77
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands
- Quality score: 78
- Quality tier: bronze
- Public page: https://skillstore.pages.dev/skills/dataknifeai-security-management
- Manifest: https://skillstore.pages.dev/api/skills/dataknifeai-security-management/manifest

## Capabilities

- Guides review of UniFi firewall zones and network segmentation.
- Guides review of access control rules and policy purpose.
- Supports checks of hotspot voucher status and expiration.
- Produces structured security audit findings and recommendations.
- Helps verify compliance posture from available UniFi network data.

## Use Cases

- Quarterly Security Review: Review firewall zones, ACLs, and guest access before a scheduled compliance check.
- Guest Access Cleanup: Find active, expired, and soon-expiring vouchers so guest access can be controlled.
- Segmentation Assessment: Compare zone design and access rules against least privilege and trust boundaries.

## Prompt Templates

### List Security Objects

```
Show the current firewall zones, ACL rules, and guest vouchers. Summarize anything that needs attention.
```

### Review Guest Access

```
Review active guest vouchers and identify expired, expiring, or unusually broad access. Recommend cleanup actions.
```

### Audit Segmentation

```
Assess firewall zones and ACL rules for segmentation gaps. Highlight rules that may violate least privilege.
```

### Create Compliance Summary

```
Perform a full security audit using zones, ACLs, guest vouchers, and network info. Provide risks, evidence, and prioritized recommendations.
```

## Limitations

- Requires access to compatible UniFi network management tools.
- Does not replace a formal penetration test or legal compliance review.
- Cannot verify physical network controls or undocumented business policies.
- Recommendations depend on the completeness of available configuration data.

## Best Practices

- Review firewall zones and ACLs on a regular schedule.
- Confirm each rule has a documented business purpose.
- Remove expired guest vouchers and narrow active guest access.

## Anti Patterns

- Using broad allow rules without documented justification.
- Leaving guest vouchers active after the intended access window.
- Treating generated recommendations as final without operator review.

## Security Audit

- Audited at: 2026-07-06T10:31:40.905\+00:00
- Summary: The static findings are false positives caused by Markdown inline code for MCP tool names, not executable Ruby or shell backticks. No prompt injection, data exfiltration intent, or unauthorized execution instructions were found in SKILL.md.

## Stats

- Views: 241
- Downloads: 6
- Favorites: 0
- Popularity score: 0
