Recon Nmap
AgentSecOps/SecOpsAgentKit
Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.
Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging.
$ npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install automateyournetwork/netclaw nmap-network-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/nmap-network-scan .claude/skills/nmap-network-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nmap-network-scan" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/nmap-network-scan into .claude/skills/nmap-network-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap-network-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/nmap-network-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install automateyournetwork/netclaw nmap-network-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/workspace/skills/nmap-network-scan .agents/skills/nmap-network-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nmap-network-scan" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/nmap-network-scan into .agents/skills/nmap-network-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap-network-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install automateyournetwork/netclaw nmap-network-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/workspace/skills/nmap-network-scan .cursor/skills/nmap-network-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nmap-network-scan" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/nmap-network-scan into .cursor/skills/nmap-network-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap-network-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/automateyournetwork/netclaw.git --path workspace/skills/nmap-network-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install automateyournetwork/netclaw nmap-network-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/workspace/skills/nmap-network-scan .gemini/skills/nmap-network-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nmap-network-scan" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/nmap-network-scan into .gemini/skills/nmap-network-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap-network-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install automateyournetwork/netclaw nmap-network-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/workspace/skills/nmap-network-scan .github/skills/nmap-network-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nmap-network-scan" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/nmap-network-scan into .github/skills/nmap-network-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap-network-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install automateyournetwork/netclaw nmap-network-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/workspace/skills/nmap-network-scan .opencode/skills/nmap-network-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nmap-network-scan" agent skill from https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/nmap-network-scan into .opencode/skills/nmap-network-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap-network-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nmap-network-scanHost discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging.
Nmap Network Scan is an agent skill from automateyournetwork/netclaw. Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging. Use when discovering live hosts on a subnet, scanning for open ports, verifying firewall rules, or doing pre/post-change port scans
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing, Network security and Cloud networking. It works with Nmap. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nmap Network Scan loads about 1.3k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 506 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 506 words, ~1,278 tokens.
.claude/skills/nmap-network-scan/SKILL.md (or your agent's skills folder).python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" TOOL_NAME '{"param":"value"}'| Tool | Purpose | Privileges |
|---|---|---|
nmap_ping_scan | ICMP+TCP host discovery (no port scan) | none |
nmap_arp_discovery | ARP host discovery (LAN only) | cap_net_raw |
nmap_top_ports | Fast scan of N most common ports | none |
nmap_syn_scan | SYN half-open port scan (fast, stealthy) | cap_net_raw |
nmap_tcp_scan | Full TCP connect scan (no root needed) | none |
nmap_udp_scan | UDP port scan (DNS, SNMP, NTP, etc.) | cap_net_raw |
When asked "what's on this network?" or "scan this subnet":
Find live hosts first — avoids wasting time port-scanning dead IPs.
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_ping_scan '{"target":"192.168.1.0/24"}'On directly-connected LANs, ARP discovery is more reliable:
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_arp_discovery '{"target":"192.168.1.0/24"}'Scan the top 100 common ports on discovered hosts:
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_top_ports '{"target":"192.168.1.1","count":100}'For deeper scanning, use SYN scan (faster) or TCP connect scan:
# SYN scan — faster, requires cap_net_raw
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_syn_scan '{"target":"192.168.1.1","ports":"1-65535"}'
# TCP connect — works without special privileges
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_tcp_scan '{"target":"192.168.1.1","ports":"22,80,443,8080"}'Check for UDP services (DNS, SNMP, TFTP, NTP, syslog):
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_udp_scan '{"target":"192.168.1.1","ports":"53,67,68,69,123,161,162,500,514,1900"}'target (required): IP, hostname, or CIDR rangetarget (required): CIDR range or IP (LAN segment only)target (required): IP, hostname, or CIDR rangecount (optional): Number of top ports to scan (default 100, max 65535)target (required): IP, hostname, or CIDR rangeports (optional): Port range (default "1-1024", use "common" for top 1000)target (required): IP, hostname, or CIDR rangeports (optional): Port range (default "1-1024")target (required): IP, hostname, or CIDR rangeports (optional): Port list or range (default: common UDP service ports)All targets are validated against the CIDR allowlist in config.yaml. Targets outside the allowed ranges are hard-rejected before nmap runs. Default allowed ranges:
127.0.0.0/8 (loopback)10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 (RFC1918)fd00::/8 (IPv6 ULA)All tools return structured JSON with:
scan_id — unique identifier for retrieving results latertarget — what was scannedhosts_up / per_host — discovered hosts with open portscount / total_open — summary countsnmap_list_scans / nmap_get_scanNMAP_MCP_SCRIPT is set and valid before assuming a data or device problem.© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in workspace/skills/nmap-network-scan of automateyournetwork/netclaw.
Open the folder on GitHubat commit 95bb17e
Nmap Network Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nmap Network Scan this skillautomateyournetwork/netclaw | 676 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Recon NmapAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~4.6k | Automated safety check: Notes | Custom licence | |
| Detecting Network Scanning With Ids Signaturesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| NmapBrownFineSecurity/iothackbot | 859 | 1 repos | ~3.8k | Automated safety check: Notes | MIT | |
| Nmap ReconCommonHuman-Lab/nyxstrike | 157 | — | ~639 | Automated safety check: Pass | Custom licence | |
| Operate Network Reconcyberful/cyberful | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 |
AgentSecOps/SecOpsAgentKit
Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.
mukul975/Anthropic-Cybersecurity-Skills
Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning…
BrownFineSecurity/iothackbot
Professional network reconnaissance and port scanning using nmap.
CommonHuman-Lab/nyxstrike
Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools
cyberful/cyberful
Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.
mukul975/Anthropic-Cybersecurity-Skills
Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…
automateyournetwork/netclaw
Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.
automateyournetwork/netclaw
Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.
automateyournetwork/netclaw
Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.
automateyournetwork/netclaw
Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.
automateyournetwork/netclaw
Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).
automateyournetwork/netclaw
AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.
Works with
Categories
Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging. Nmap Network Scan is an agent skill from automateyournetwork/netclaw. Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging.
Nmap Network Scan fits situations like: discovering live hosts on a subnet; scanning for open ports; verifying firewall rules; doing pre/post-change port scans.
Run `npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a claude-code`. Or copy the skill folder (workspace/skills/nmap-network-scan in automateyournetwork/netclaw) into .claude/skills/nmap-network-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a codex`. Or copy the skill folder (workspace/skills/nmap-network-scan in automateyournetwork/netclaw) into .agents/skills/nmap-network-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nmap-network-scan, .gemini/skills/nmap-network-scan, .github/skills/nmap-network-scan and .opencode/skills/nmap-network-scan in your project.
Going by SKILL.md and its folder, Nmap Network Scan needs the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nmap Network Scan is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nmap Network Scan: Recon Nmap (AgentSecOps/SecOpsAgentKit, 220 stars), Detecting Network Scanning With Ids Signatures (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Nmap (BrownFineSecurity/iothackbot, 859 stars) and Nmap Recon (CommonHuman-Lab/nyxstrike, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.
Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.