Agent skill

Nmap Network Scan

by automateyournetwork in automateyournetwork/netclaw

Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging.

Apache-2.0Auto-check passedSecurity

Install Nmap Network Scan

skills CLI
$ npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw nmap-network-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/nmap-network-scan .claude/skills/nmap-network-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nmap-network-scan
GitHub stars
676
Token cost
~1.3k tokens
SKILL.md length
506 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging.

  • Works in 4 steps: Host Discovery → Quick Port Scan → Targeted Port Scan → …
  • Discovering live hosts on a subnet
  • SKILL.md covers How to Call the nmap MCP Tools, When to Use, Available Tools and Workflow: Subnet Discovery, plus 5 more sections
  • Calls python3

What it does

Nmap Network Scan is an agent skill from automateyournetwork/netclaw. Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging. Use when discovering live hosts on a subnet, scanning for open ports, verifying firewall rules, or doing pre/post-change port scans

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing, Network security and Cloud networking. It works with Nmap. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Discovering live hosts on a subnet
  • Scanning for open ports
  • Verifying firewall rules
  • Doing pre/post-change port scans

Example prompts

  • “/nmap-network-scan”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Host Discovery
  2. Quick Port Scan
  3. Targeted Port Scan
  4. UDP Services

What it can do on your machine

Read from SKILL.md and the folder at commit 95bb17e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nmap Network Scan loads about 1.3k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 506 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit 95bb17e, republished under its Apache-2.0 licence (© automateyournetwork). 506 words, ~1,278 tokens.

Download SKILL.mdSave it as .claude/skills/nmap-network-scan/SKILL.md (or your agent's skills folder).
name
nmap-network-scan
description
Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging. Use when discovering live hosts on a subnet, scanning for open ports, verifying firewall rules, or doing pre/post-change port scans
license
Apache-2.0
user-invocable
true

Network Scanning with nmap

How to Call the nmap MCP Tools

bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" TOOL_NAME '{"param":"value"}'

When to Use

  • Discover what hosts are alive on a subnet before deeper analysis
  • Find open ports on network devices, servers, or lab infrastructure
  • Verify firewall rules by checking which ports are reachable
  • Pre-change/post-change port scans to confirm expected service exposure
  • Asset discovery on RFC1918 or lab networks

Available Tools

ToolPurposePrivileges
nmap_ping_scanICMP+TCP host discovery (no port scan)none
nmap_arp_discoveryARP host discovery (LAN only)cap_net_raw
nmap_top_portsFast scan of N most common portsnone
nmap_syn_scanSYN half-open port scan (fast, stealthy)cap_net_raw
nmap_tcp_scanFull TCP connect scan (no root needed)none
nmap_udp_scanUDP port scan (DNS, SNMP, NTP, etc.)cap_net_raw

Workflow: Subnet Discovery

When asked "what's on this network?" or "scan this subnet":

Step 1: Host Discovery

Find live hosts first — avoids wasting time port-scanning dead IPs.

bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_ping_scan '{"target":"192.168.1.0/24"}'

On directly-connected LANs, ARP discovery is more reliable:

bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_arp_discovery '{"target":"192.168.1.0/24"}'
Step 2: Quick Port Scan

Scan the top 100 common ports on discovered hosts:

bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_top_ports '{"target":"192.168.1.1","count":100}'
Step 3: Targeted Port Scan

For deeper scanning, use SYN scan (faster) or TCP connect scan:

bash
# SYN scan — faster, requires cap_net_raw
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_syn_scan '{"target":"192.168.1.1","ports":"1-65535"}'

# TCP connect — works without special privileges
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_tcp_scan '{"target":"192.168.1.1","ports":"22,80,443,8080"}'
Step 4: UDP Services

Check for UDP services (DNS, SNMP, TFTP, NTP, syslog):

bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_udp_scan '{"target":"192.168.1.1","ports":"53,67,68,69,123,161,162,500,514,1900"}'

Tool Parameters

nmap_ping_scan
  • target (required): IP, hostname, or CIDR range
nmap_arp_discovery
  • target (required): CIDR range or IP (LAN segment only)
nmap_top_ports
  • target (required): IP, hostname, or CIDR range
  • count (optional): Number of top ports to scan (default 100, max 65535)
nmap_syn_scan
  • target (required): IP, hostname, or CIDR range
  • ports (optional): Port range (default "1-1024", use "common" for top 1000)
nmap_tcp_scan
  • target (required): IP, hostname, or CIDR range
  • ports (optional): Port range (default "1-1024")
nmap_udp_scan
  • target (required): IP, hostname, or CIDR range
  • ports (optional): Port list or range (default: common UDP service ports)

Scope Enforcement

All targets are validated against the CIDR allowlist in config.yaml. Targets outside the allowed ranges are hard-rejected before nmap runs. Default allowed ranges:

  • 127.0.0.0/8 (loopback)
  • 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 (RFC1918)
  • fd00::/8 (IPv6 ULA)
Show full SKILL.md (188 more words)Show less

Output Format

All tools return structured JSON with:

  • scan_id — unique identifier for retrieving results later
  • target — what was scanned
  • hosts_up / per_host — discovered hosts with open ports
  • count / total_open — summary counts

Important Rules

  • Always start with host discovery before port scanning large ranges
  • SYN scan is faster but requires cap_net_raw on the nmap binary
  • UDP scans are inherently slow — keep port lists targeted
  • Every scan is logged in the audit log for compliance
  • Scan results are persisted and retrievable via nmap_list_scans / nmap_get_scan

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that NMAP_MCP_SCRIPT is set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/nmap-network-scan of automateyournetwork/netclaw.

Open the folder on GitHubat commit 95bb17e

Compare with similar skills

Nmap Network Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nmap Network Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nmap Network Scan this skillautomateyournetwork/netclaw676—~1.3kAutomated safety check: PassApache-2.0
Recon NmapAgentSecOps/SecOpsAgentKit2201 repos~4.6kAutomated safety check: NotesCustom licence
Detecting Network Scanning With Ids Signaturesmukul975/Anthropic-Cybersecurity-Skills34k—~3.5kAutomated safety check: PassApache-2.0
NmapBrownFineSecurity/iothackbot8591 repos~3.8kAutomated safety check: NotesMIT
Nmap ReconCommonHuman-Lab/nyxstrike157—~639Automated safety check: PassCustom licence
Operate Network Reconcyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • Recon Nmap

    AgentSecOps/SecOpsAgentKit

    Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.

    220 GitHub starsUsed in 1 repo~4.6k tokens
    SecurityAuto-check: notes
  • Detecting Network Scanning With Ids Signatures

    mukul975/Anthropic-Cybersecurity-Skills

    Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning…

    34k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    859 GitHub starsUsed in 1 repo~3.8k tokens
    SecurityAuto-check: notes
  • Nmap Recon

    CommonHuman-Lab/nyxstrike

    Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools

    157 GitHub stars~639 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Operate Network Recon

    cyberful/cyberful

    Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

    135 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Cloud Waf Rules

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated 4 days ago
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about Nmap Network Scan

What does Nmap Network Scan do?

Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging. Nmap Network Scan is an agent skill from automateyournetwork/netclaw. Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging.

When should I use Nmap Network Scan?

Nmap Network Scan fits situations like: discovering live hosts on a subnet; scanning for open ports; verifying firewall rules; doing pre/post-change port scans.

How do I install Nmap Network Scan in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a claude-code`. Or copy the skill folder (workspace/skills/nmap-network-scan in automateyournetwork/netclaw) into .claude/skills/nmap-network-scan in your project. Claude Code loads it when a task matches its description.

How do I install Nmap Network Scan in Codex?

Run `npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a codex`. Or copy the skill folder (workspace/skills/nmap-network-scan in automateyournetwork/netclaw) into .agents/skills/nmap-network-scan in your project. Codex loads it when a task matches its description.

Can I use Nmap Network Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill nmap-network-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nmap-network-scan, .gemini/skills/nmap-network-scan, .github/skills/nmap-network-scan and .opencode/skills/nmap-network-scan in your project.

What does Nmap Network Scan need to run?

Going by SKILL.md and its folder, Nmap Network Scan needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Nmap Network Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nmap Network Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nmap Network Scan use?

Nmap Network Scan is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nmap Network Scan use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nmap Network Scan?

Skills that share tags, products or a category with Nmap Network Scan: Recon Nmap (AgentSecOps/SecOpsAgentKit, 220 stars), Detecting Network Scanning With Ids Signatures (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Nmap (BrownFineSecurity/iothackbot, 859 stars) and Nmap Recon (CommonHuman-Lab/nyxstrike, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nmap Network Scan?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 5, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.