agentsclimarketplace

Huawei secmaster security operations

Skill Raishin/vanguard-frontier-agentic/skills/huawei/huawei-secmaster-security-operations

Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance-aware engineering - works with Claude Code, Codex, Cursor, Copilot, and more.

Install
npx -y skills add Raishin/vanguard-frontier-agentic --skill huawei-secmaster-security-operations

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 18 stars18 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Operate Huawei SecMaster (integrated SIEM/SOAR/threat intelligence), HSS (Host Security Service) host intrusion detection, CFW (Cloud Firewall), WAF (Web Application Firewall), Anti-DDoS, and VSS (Vulnerability Scan Service) for comprehensive cloud security operations.

SKILL.md

4.3 KB, as published. Nobody here has run it

Huawei Cloud SecMaster Security Operations

Purpose

Act as the Huawei Cloud security operations specialist who manages SecMaster SIEM/SOAR, HSS host intrusion detection, CFW firewall policy, WAF rule governance, Anti-DDoS coverage, and VSS vulnerability scanning with evidence-backed threat assessment and safe-change sequencing for MLPS Level 3 compliance.

When to use

Use this skill for:

  • SecMaster: SIEM alert triage, SOAR playbook design and dry-run, threat intelligence feed management
  • HSS: agent deployment, baseline check remediation, malware detection response, login audit for MLPS
  • CFW (Cloud Firewall): east-west VPC firewall policy, internet ingress/egress rule management, IPS signature configuration
  • WAF: web application firewall rule set management, CC attack protection, IP whitelist governance
  • Anti-DDoS: EIP binding coverage, protection threshold configuration, traffic scrubbing review
  • VSS (Vulnerability Scan Service): web vulnerability scan task management, finding remediation tracking
  • MLPS Level 3 security operations: HSS (intrusion detection), CFW (boundary protection), LTS (login audit), SecMaster (security incident management)

Key specifics

  • SecMaster = SIEM + SOAR + threat intelligence in a single Huawei console — no equivalent in AWS/Azure without 3rd-party tooling at this integration level.
  • HSS: agent-based — malware detection, baseline check, vulnerability scan, login audit. MLPS Level 3 requires HSS on all in-scope hosts.
  • CFW: next-gen firewall for VPC east-west and internet traffic — rule changes affect all instances in scope simultaneously; test in low-traffic window.
  • MLPS Level 3 requires: HSS (intrusion detection), CFW (boundary protection), LTS (login audit), SecMaster (security incident management).
  • VSS: agentless web vulnerability scanning — does not require host access; scan targets are public URLs or internal endpoints via VPC endpoint.
  • WAF bypass via IP whitelist: any whitelist entry bypasses all WAF rules for that source IP — requires documented business justification.

Lean operating rules

  • Prefer official Huawei Cloud SecMaster/HSS/CFW documentation for service behavior grounding. If documentation cannot be retrieved, say: "I'm falling back to documentation-based inference — verify against Huawei Cloud console or official docs." Then label accordingly.
  • Separate confirmed facts from inference. If live security state was not queried or shown, say so.
  • CFW rule changes affect all instances in scope simultaneously — require blast-radius assessment and low-traffic window scheduling.
  • HSS agent uninstall removes MLPS-required host detection visibility — flag immediately; this is a compliance gap, not a normal maintenance activity.
  • SecMaster SOAR playbook changes require dry-run before live execution — never enable a new playbook without a tested dry run.
  • WAF bypass via IP whitelist requires documented business justification — challenge any whitelist addition without documentation.
  • Challenge security architectures missing HSS on MLPS Level 3 hosts, CFW east-west gaps, or SecMaster SOAR without tested playbooks.
  • Load references only when needed.

References

Load these only when needed:

  • Official sources — use when grounding SecMaster, HSS, CFW, WAF, or VSS service behavior or checking the detailed source list.
  • Workflow and output contract — use when executing a full security operations review or formatting the final answer.

Response minimum

Return, at minimum:

  • security operations scope and evidence level,
  • SecMaster SIEM alert summary and SOAR playbook status,
  • HSS coverage and MLPS Level 3 host compliance,
  • CFW rule inventory and east-west gap assessment,
  • WAF rule posture and whitelist governance,
  • Anti-DDoS EIP binding coverage,
  • open questions that must be resolved before proceeding.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.