Agent skill

Nmap Service Detection

by automateyournetwork in automateyournetwork/netclaw

Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP.

Apache-2.0Auto-check passedSecurity

Install Nmap Service Detection

skills CLI
$ npx skills add automateyournetwork/netclaw --skill nmap-service-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw nmap-service-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/nmap-service-detection .claude/skills/nmap-service-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nmap-service-detection
GitHub stars
676
Token cost
~1.5k tokens
SKILL.md length
574 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP.

  • Works in 5 steps: Service Version Detection → OS Fingerprinting → Full Recon → …
  • Identifying services on open ports
  • SKILL.md covers How to Call the nmap MCP Tools, When to Use, Available Tools and Workflow: Service Identification, plus 6 more sections
  • Calls python3

What it does

Nmap Service Detection is an agent skill from automateyournetwork/netclaw. Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP. Use when identifying services on open ports, fingerprinting OS versions, running NSE scripts for SSL or SMB checks, or scanning for known CVEs and vulnerabilities

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing and Vulnerability scanning. It works with Nmap and Model Context Protocol. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Identifying services on open ports
  • Fingerprinting OS versions
  • Running NSE scripts for SSL
  • Scanning for known CVEs and vulnerabilities

Example prompts

  • “/nmap-service-detection”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Service Version Detection
  2. OS Fingerprinting
  3. Full Recon
  4. Vulnerability Scan
  5. Targeted Script Scans

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nmap Service Detection loads about 1.5k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 574 words, ~1,544 tokens.

Download SKILL.mdSave it as .claude/skills/nmap-service-detection/SKILL.md (or your agent's skills folder).
name
nmap-service-detection
description
Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP. Use when identifying services on open ports, fingerprinting OS versions, running NSE scripts for SSL or SMB checks, or scanning for known CVEs and vulnerabilities
license
Apache-2.0
user-invocable
true

Service Detection & Vulnerability Scanning with nmap

How to Call the nmap MCP Tools

bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" TOOL_NAME '{"param":"value"}'

When to Use

  • Identify what software/version is running on an open port
  • Fingerprint the OS of a network device or server
  • Run targeted NSE scripts (SSL cert check, banner grab, protocol probe)
  • Scan for known CVEs and common misconfigurations
  • Full reconnaissance sweep of a single host or small range

Available Tools

ToolPurposePrivileges
nmap_service_detectionService name + version on open ports (-sV)none
nmap_os_detectionOS fingerprinting (-O)cap_net_raw
nmap_script_scanRun specific NSE scriptsnone
nmap_vuln_scanRun the "vuln" NSE script categorynone
nmap_full_reconSYN + service + OS + default scripts all-in-onecap_net_raw

Workflow: Service Identification

When asked "what's running on this host?" or "identify the services":

Step 1: Service Version Detection
bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_service_detection '{"target":"192.168.1.1","ports":"common","intensity":7}'

Returns per-port: service name, product, version, CPE identifier.

Step 2: OS Fingerprinting
bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_os_detection '{"target":"192.168.1.1"}'

Works best when the target has at least one open and one closed port.

Workflow: Security Assessment

When asked "check this host for vulnerabilities" or "security scan":

Step 1: Full Recon

Run the all-in-one audit sweep:

bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_full_recon '{"target":"192.168.1.1","ports":"common"}'

This combines SYN scan + service detection + OS fingerprinting + default NSE scripts.

Step 2: Vulnerability Scan

Run the vuln NSE category for known CVEs:

bash
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_vuln_scan '{"target":"192.168.1.1","ports":"common"}'

This is slow — use on specific targets, not wide ranges.

Step 3: Targeted Script Scans

Run specific NSE scripts for focused checks:

bash
# SSL certificate inspection
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_script_scan '{"target":"192.168.1.1","scripts":"ssl-cert,ssl-enum-ciphers","ports":"443"}'

# HTTP title + headers
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_script_scan '{"target":"192.168.1.1","scripts":"http-title,http-headers","ports":"80,443,8080"}'

# Banner grabbing
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_script_scan '{"target":"192.168.1.1","scripts":"banner","ports":"1-1024"}'

# SMB enumeration
python3 $MCP_CALL "python3 -u $NMAP_MCP_SCRIPT" nmap_script_scan '{"target":"192.168.1.1","scripts":"smb-enum-shares,smb-os-discovery","ports":"445"}'

Tool Parameters

nmap_service_detection
  • target (required): IP, hostname, or CIDR range
  • ports (optional): Port range or "common" for top 1000 (default: "common")
  • intensity (optional): Version detection aggressiveness 0-9 (default: 7)
nmap_os_detection
  • target (required): Single IP or hostname (ranges don't work well)
nmap_script_scan
  • target (required): IP, hostname, or CIDR range
  • scripts (required): NSE script name(s), e.g. "ssl-cert", "http-title,http-headers", "banner"
  • ports (optional): Port range or "common" (default: "common")
nmap_vuln_scan
  • target (required): IP or hostname (keep scope tight)
  • ports (optional): Port range or "common" (default: "common")
nmap_full_recon
  • target (required): IP, hostname, or small CIDR range (/28 or smaller)
  • ports (optional): Port range or "common" (default: "common")
Show full SKILL.md (257 more words)Show less

Common NSE Script Names

ScriptPurpose
ssl-certDisplay SSL certificate details
ssl-enum-ciphersList supported SSL/TLS ciphers
http-titleGrab HTML page title
http-headersDump HTTP response headers
http-methodsCheck supported HTTP methods
bannerGrab service banners
smb-enum-sharesEnumerate SMB shares
smb-os-discoveryDiscover OS via SMB
ssh-hostkeyShow SSH host keys
dns-bruteDNS subdomain brute force
ftp-anonCheck for anonymous FTP

Output Format

All tools return structured JSON:

  • scan_id — for retrieving results later
  • per_host — per-host breakdown with open ports, services, versions
  • os_detection — OS match name, accuracy, device type
  • results / vulnerability_findings — script output organized by port

Important Rules

  • OS detection requires at least one open and one closed port to fingerprint accurately
  • Vuln scans are slow — target specific hosts, not wide ranges
  • Full recon combines multiple scan types — takes longer but gives comprehensive results
  • All scans respect the CIDR allowlist and are audit-logged
  • Scan results persist and can be retrieved with nmap_list_scans / nmap_get_scan

Failure Behavior

  • If a tool call fails with an authentication or connection error, check that NMAP_MCP_SCRIPT is set and valid before assuming a data or device problem.
  • On a tool error (timeout, unreachable host, malformed response), report the failure and its error message directly to the user rather than fabricating or guessing at results.
  • For a confirmed read-only call, check connectivity and retry once if appropriate. For any call that changes state or sends a message, a timeout does not prove the action failed: inspect current state or delivery status before retrying, preserve the required approval/change gates, and do not repeat an action whose outcome is unknown.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/nmap-service-detection of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Nmap Service Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nmap Service Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nmap Service Detection this skillautomateyournetwork/netclaw676—~1.5kAutomated safety check: PassApache-2.0
NmapBrownFineSecurity/iothackbot8591 repos~3.8kAutomated safety check: NotesMIT
Scanning Network With Nmap Advancedmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Network Scannerptn1411/skill219—~1.4kAutomated safety check: NotesNone
Skill InspectorNVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    859 GitHub starsUsed in 1 repo~3.8k tokens
    SecurityAuto-check: notes
  • Scanning Network With Nmap Advanced

    mukul975/Anthropic-Cybersecurity-Skills

    Performs advanced network recon using Nmap's Scripting Engine (NSE), timing controls, firewall/IDS evasion, and structured output parsing to discover hosts, enumerate service versions, detect…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Network Scanner

    ptn1411/skill

    Run authorized network reconnaissance with Nmap on Windows (or Linux).

    219 GitHub stars~1.4k tokensUpdated 19 days ago
    SecurityAuto-check: notes
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

    376 GitHub stars~2.3k tokensUpdated 12 days ago
    SecurityAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    676 GitHub stars~612 tokensUpdated yesterday
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    676 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    676 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    676 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    676 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    676 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Nmap Service Detection

What does Nmap Service Detection do?

Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP. Nmap Service Detection is an agent skill from automateyournetwork/netclaw. Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP.

When should I use Nmap Service Detection?

Nmap Service Detection fits situations like: identifying services on open ports; fingerprinting OS versions; running NSE scripts for SSL; scanning for known CVEs and vulnerabilities.

How do I install Nmap Service Detection in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill nmap-service-detection -a claude-code`. Or copy the skill folder (workspace/skills/nmap-service-detection in automateyournetwork/netclaw) into .claude/skills/nmap-service-detection in your project. Claude Code loads it when a task matches its description.

How do I install Nmap Service Detection in Codex?

Run `npx skills add automateyournetwork/netclaw --skill nmap-service-detection -a codex`. Or copy the skill folder (workspace/skills/nmap-service-detection in automateyournetwork/netclaw) into .agents/skills/nmap-service-detection in your project. Codex loads it when a task matches its description.

Can I use Nmap Service Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill nmap-service-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nmap-service-detection, .gemini/skills/nmap-service-detection, .github/skills/nmap-service-detection and .opencode/skills/nmap-service-detection in your project.

What does Nmap Service Detection need to run?

Going by SKILL.md and its folder, Nmap Service Detection needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Nmap Service Detection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nmap Service Detection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nmap Service Detection use?

Nmap Service Detection is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nmap Service Detection use?

About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nmap Service Detection?

Skills that share tags, products or a category with Nmap Service Detection: Nmap (BrownFineSecurity/iothackbot, 859 stars), Scanning Network With Nmap Advanced (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Network Scanner (ptn1411/skill, 219 stars) and Skill Inspector (NVIDIA/SkillSpector, 20k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nmap Service Detection?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.