generated: '2026-09-05' method: generated source: openapi/zero-networks-platform-openapi.yaml note: >- Zero Networks publishes no Agent Skills, AGENTS.md or agent operating instructions — searched the vendor site, llms.txt and the 19-repo zeronetworks GitHub organization on 2026-09-05. These three skills are GENERATED by API Evangelist from the provider's own OpenAPI 3.0.1 contract. Every operationId, path, required field and enum value cited in them was read out of that spec; nothing is invented. They cover the three marquee write flows the 40 documented operations support. Each skill leads with the same two safety facts the contract establishes — there is no idempotency mechanism on any of the 29 mutating operations, and no reversal window is published for any of them — because this API's writes change enterprise network firewall policy. skills: - name: zero-networks-segment-an-asset file: zero-networks-segment-an-asset.md description: >- Create, verify and roll back an inbound or outbound segmentation firewall rule for a protected asset — the platform's core write flow. api: zero-networks-platform operations: [Assets_Search, InboundRules_Create, InboundRule_Get, InboundRule_Update, InboundRule_Delete, OutboundRules_Create, OutboundRule_Get, OutboundRule_Update, OutboundRule_Delete] - name: zero-networks-apply-mfa-policy file: zero-networks-apply-mfa-policy.md description: >- Put just-in-time MFA in front of RDP/SSH/SMB/WinRM with a reactive (MFA) policy, or grant time-boxed user access with an internal access policy. api: zero-networks-platform operations: [Assets_Search, MFAInboundPolicies_Create, MFAInboundPolicies_Get, MFAInboundPolicies_Update, MFAInboundPolicies_Delete, MFAOutboundPolicies_Create, MFAOutboundPolicies_Get, MFAOutboundPolicies_Update, MFAOutboundPolicies_Delete, InternalAccessPolicy_Create, InternalAccessPolicy_Get, InternalAccessPolicy_Update, InternalAccessPolicy_Delete] - name: zero-networks-manage-custom-groups file: zero-networks-manage-custom-groups.md description: >- Create groups and bulk-manage the asset and identity members that segmentation rules target, without editing the rules themselves. api: zero-networks-platform operations: [Assets_Search, CustomGroups_Create, CustomGroups_Get, CustomGroups_Update, CustomGroups_Delete, CustomGroupMembers_List, CustomGroupsMembers_Add, CustomGroupsMembers_Delete] coverage: documented_operations: 40 operations_covered: 28 uncovered: - RPCRules_Create - RPCRule_Get - RPCRule_Update - RPCRule_Delete - AEExclusionsInbound_Create - AEExclusionsInbound_Get - AEExclusionsInbound_Update - AEExclusionsInbound_Delete - AEExclusionsOutbound_Create - AEExclusionsOutbound_Get - AEExclusionsOutbound_Update - AEExclusionsOutbound_Delete note: >- RPC Firewall rules and Automation Engine exclusions are deliberately not packaged as skills. Both are expert surfaces — RPC rules address raw interface UUIDs and operation numbers on domain controllers, and AE exclusions suppress the platform's own automated rule learning. Neither is safe to drive from a generated skill without a documented reference for the values involved, and Zero Networks publishes none.