/unifly-audit
Config profile to use (e.g., home, office)
> /plugin marketplace add hyperb1iss/unifly > /plugin install unifly@hyperb1iss
How it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/unifly-audit
Context preview
What this command does when you run it.
Config profile to use (e.g., home, office)
Command definition
unifly-audit.mdname: unifly-audit
description: Security audit of UniFi configuration. Checks for open WiFi, permissive firewall rules, and misconfigurations
arguments:
- name: profile
description: "Config profile to use (e.g., home, office)"
required: falseUniFi Security Audit
Perform a security-focused audit of the UniFi configuration.
Execution
Run each check and compile findings into a security report.
1. WiFi Security Check
Identify SSIDs with weak or no security:
unifly wifi list -p {{profile}} -o json | jq '[
.[] | {
name,
security,
enabled,
alert: (if .security == "open" then "CRITICAL: Open network"
elif .security == "wpa2-personal" then "MODERATE: WPA2 only"
else "OK" end)
} | select(.alert != "OK")
]'2. Firewall Policy Review
Check for overly permissive rules:
# All allow rules
unifly firewall policies list -p {{profile}} -o json | jq '[
.[] | select(.action == "ALLOW") | {id, description, source_zone, dest_zone}
]'
# Rules without logging
unifly firewall policies list -p {{profile}} -o json | jq '[
.[] | select(.logging == false) | {id, description, action}
]'3. Device Firmware Check
Identify devices with outdated firmware:
unifly devices list --all -p {{profile}} -o json | jq '[
.[] | select(.upgrade_available == true) | {name, mac, model, current_version}
]'4. Network Isolation Check
Verify IoT and guest networks are properly isolated:
unifly networks list --all -p {{profile}} -o json | jq '[
.[] | {name, vlan_id, isolation}
]'5. Unused Resources
Find networks with no cross-references:
unifly networks list --all -p {{profile}} -o jsonFor each network, check `unifly networks refs <id>` for cross-references.
When `-p {{profile}}` is provided, the `-p {{profile}}` flag is already wired into every command above; no further substitution is needed.
Result Reporting
Compile findings into a report with severity levels:
- **CRITICAL**: Open WiFi networks, no firewall between zones
- **HIGH**: WPA2-only networks, allow-all firewall rules, no logging
- **MODERATE**: Outdated firmware, unused networks
- **INFO**: Network isolation status, device counts
Recommend specific remediation steps for each finding.
Read more
name: unifly-audit
description: Security audit of UniFi configuration. Checks for open WiFi, permissive firewall rules, and misconfigurations
arguments:
- name: profile
description: "Config profile to use (e.g., home, office)"
required: falseUniFi Security Audit
Perform a security-focused audit of the UniFi configuration.
Execution
Run each check and compile findings into a security report.
1. WiFi Security Check
Identify SSIDs with weak or no security:
unifly wifi list -p {{profile}} -o json | jq '[
.[] | {
name,
security,
enabled,
alert: (if .security == "open" then "CRITICAL: Open network"
elif .security == "wpa2-personal" then "MODERATE: WPA2 only"
else "OK" end)
} | select(.alert != "OK")
]'2. Firewall Policy Review
Check for overly permissive rules:
# All allow rules
unifly firewall policies list -p {{profile}} -o json | jq '[
.[] | select(.action == "ALLOW") | {id, description, source_zone, dest_zone}
]'
# Rules without logging
unifly firewall policies list -p {{profile}} -o json | jq '[
.[] | select(.logging == false) | {id, description, action}
]'3. Device Firmware Check
Identify devices with outdated firmware:
unifly devices list --all -p {{profile}} -o json | jq '[
.[] | select(.upgrade_available == true) | {name, mac, model, current_version}
]'4. Network Isolation Check
Verify IoT and guest networks are properly isolated:
unifly networks list --all -p {{profile}} -o json | jq '[
.[] | {name, vlan_id, isolation}
]'5. Unused Resources
Find networks with no cross-references:
unifly networks list --all -p {{profile}} -o jsonFor each network, check `unifly networks refs <id>` for cross-references.
When `-p {{profile}}` is provided, the `-p {{profile}}` flag is already wired into every command above; no further substitution is needed.
Result Reporting
Compile findings into a report with severity levels:
- **CRITICAL**: Open WiFi networks, no firewall between zones
- **HIGH**: WPA2-only networks, allow-all firewall rules, no logging
- **MODERATE**: Outdated firmware, unused networks
- **INFO**: Network isolation status, device counts
Recommend specific remediation steps for each finding.
๐ Elegant UniFi network management CLI & TUI - for humans and agents
Repo: hyperb1iss/unifly

