Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

MITAuto-check: notesSecurity

Install Chipsec

skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill chipsec -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BrownFineSecurity/iothackbot chipsec --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/chipsec .claude/skills/chipsec && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
chipsec
GitHub stars
858
Used in
1 other repo
Token cost
~3.9k tokens
SKILL.md length
1,000 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

  • Works in 12 steps: Malware and Vulnerability Scan (Primary… → Generate EFI Executable Inventory → Compare Against Baseline → …
  • Analyzing firmware .bin/.rom/.fd/.cap files offline without requiring hardware access
  • SKILL.md covers Tool Overview, Prerequisites, Core Commands and Supported Firmware Formats, plus 4 more sections
  • Calls pip

What it does

Chipsec is an agent skill from BrownFineSecurity/iothackbot. Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. Decode firmware structure, detect known malware and rootkits (LoJax, ThinkPwn, HackingTeam, MosaicRegressor), generate EFI executable inventories with hashes, extract NVRAM variables, and parse SPI flash descriptors. Use when analyzing firmware .bin/.rom/.fd/.cap files offline without requiring hardware access.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST. The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.

When your agent uses it

  • Analyzing firmware .bin/.rom/.fd/.cap files offline without requiring hardware access
  • Tasks that involve Static analysis and SAST

Example prompts

  • “/chipsec”

Requirements

  • Python 3

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Malware and Vulnerability Scan (Primary Use)
  2. Generate EFI Executable Inventory
  3. Compare Against Baseline
  4. Decode Firmware Structure
  5. Extract NVRAM Variables
  6. Parse SPI Flash Descriptor
  7. Always Run Threat Scan First
  8. Generate Inventory for Every Firmware
  9. Save All Output
  10. Verify Firmware Format First
  11. Use Organized Output Directories
  12. Cross-Reference with Other Tools

What it can do on your machine

Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Chipsec loads about 3.9k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 1,000 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:29
    sudo mkdir -p "$CHIPSEC_DIR/logs"
  • NoteRuns commands with sudoSKILL.md:30
    sudo chmod 777 "$CHIPSEC_DIR/logs"
  • NoteRuns commands with sudoSKILL.md:385
    sudo mkdir -p "$CHIPSEC_DIR/logs"
  • NoteRuns commands with sudoSKILL.md:386
    sudo chmod 777 "$CHIPSEC_DIR/logs"

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BrownFineSecurity/iothackbot at commit d443c40, republished under its MIT licence (© BrownFineSecurity). 1,000 words, ~3,889 tokens.

Download SKILL.mdSave it as .claude/skills/chipsec/SKILL.md (or your agent's skills folder).
name
chipsec
description
Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. Decode firmware structure, detect known malware and rootkits (LoJax, ThinkPwn, HackingTeam, MosaicRegressor), generate EFI executable inventories with hashes, extract NVRAM variables, and parse SPI flash descriptors. Use when analyzing firmware .bin/.rom/.fd/.cap files offline without requiring hardware access.

Chipsec - UEFI Firmware Static Analysis

You are helping the user perform static security analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. This skill focuses exclusively on offline analysis capabilities that do not require kernel driver access or root privileges.

Tool Overview

Chipsec is Intel's Platform Security Assessment Framework. For static analysis of firmware dumps, it provides:

  • EFI executable inventory generation with cryptographic hashes
  • Detection of known UEFI malware and vulnerabilities
  • Firmware structure decoding and extraction
  • NVRAM/UEFI variable extraction
  • SPI flash descriptor parsing
  • Baseline comparison for change detection

Prerequisites

One-Time Setup (Fix Logging Permission)

Chipsec writes into a logs/ directory inside its install location. Create it once. The Python version in the path varies by system, so derive the path instead of hardcoding it:

bash
CHIPSEC_DIR="$(find /usr/lib/python3*/site-packages ~/.local/lib/python3*/site-packages -maxdepth 1 -name chipsec -type d 2>/dev/null | head -1)"
sudo mkdir -p "$CHIPSEC_DIR/logs"
sudo chmod 777 "$CHIPSEC_DIR/logs"
Verify Installation
bash
chipsec_main --version

Core Commands

All static analysis commands use these flags:

  • -i : Ignore platform check (required for offline analysis)
  • -n : No kernel driver (required for static analysis)
1. Malware and Vulnerability Scan (Primary Use)

Scan firmware for known threats including UEFI rootkits and SMM vulnerabilities:

bash
chipsec_main -i -n -m tools.uefi.scan_blocked -a <firmware.bin>

Detected Threats:

ThreatDescriptionReference
HT_UEFI_RootkitHackingTeam commercial UEFI rootkitMcAfee ATR
MR_UEFI_RootkitMosaicRegressor APT UEFI implantKaspersky
LoJaxFirst UEFI rootkit found in the wild (Sednit/APT28)ESET
ThinkPwnSystemSmmRuntimeRt SMM code execution vulnerabilitycr4.sh
FirmwareBleedSMM Return Stack Buffer stuffing vulnerabilityBinarly

Example Output (Threat Found):

[!] match 'ThinkPwn.SystemSmmRuntimeRt'
    GUID  : {7c79ac8c-5e6c-4e3d-ba6f-c260ee7c172e}
[!] found EFI binary matching 'ThinkPwn'
    MD5   : 59f5ba825911e7d0dffe06ee0d6d9828
    SHA256: 7f0e16f244151e7bfa170b7def014f6a225c5af626c223567f36a8b19f95e3ab

WARNING: Blocked EFI binary found in the UEFI firmware image
2. Generate EFI Executable Inventory

Create a JSON manifest of all EFI modules with cryptographic hashes:

bash
chipsec_main -i -n -m tools.uefi.scan_image -a generate <output.json> <firmware.bin>

Use Cases:

  • Create baseline for change detection
  • Inventory all DXE drivers, PEI modules, applications
  • Generate hashes for threat intelligence lookup

Output Format (efilist.json):

json
{
  "sha256_hash": {
    "sha1": "...",
    "guid": "EFD652CC-0E99-40F0-96C0-E08C089070FC",
    "name": "S3Resume",
    "type": "S_PE32"
  }
}
3. Compare Against Baseline

Check firmware against a known-good inventory:

bash
chipsec_main -i -n -m tools.uefi.scan_image -a check <baseline.json> <firmware.bin>

Use Cases:

  • Detect unauthorized firmware modifications
  • Verify firmware update integrity
  • Incident response - compare compromised vs clean
4. Decode Firmware Structure

Extract and analyze firmware volumes, files, and sections:

bash
chipsec_util -i -n uefi decode <firmware.bin>

Creates output directory containing:

firmware.bin.dir/
├── firmware_volumes/     # Extracted FV regions
├── efi_files/           # Individual EFI binaries
├── nvram/               # NVRAM variables (if found)
└── ...
5. Extract NVRAM Variables

NVRAM variables are extracted as part of the uefi decode command:

bash
chipsec_util -i -n uefi decode <firmware.bin>

NVRAM output location:

firmware.bin.dir/
├── nvram_.nvram.lst          # List of NVRAM variables
├── nvram/                    # Extracted variable files (if present)
└── FV/                       # Firmware volumes

View extracted variables:

bash
cat firmware.bin.dir/nvram_.nvram.lst

Note: The standalone uefi nvram command requires driver access and cannot be used for static analysis. Use uefi decode instead, which extracts NVRAM as part of the full firmware decode process.

6. Parse SPI Flash Descriptor

Analyze SPI flash regions (requires platform hint):

bash
chipsec_util -p <PLATFORM> spidesc <firmware.bin>

Common Platform Codes:

CodePlatform
SNBSandy Bridge (2nd Gen Core)
IVBIvy Bridge (3rd Gen Core)
HSWHaswell (4th Gen Core)
BDWBroadwell (5th Gen Core)
SKLSkylake (6th Gen Core)
KBLKaby Lake (7th Gen Core)
CFLCoffee Lake (8th/9th Gen Core)
ICLIce Lake (10th Gen Core)
TGLTiger Lake (11th Gen Core)
ADLAlder Lake (12th Gen Core)
RPLRaptor Lake (13th Gen Core)

Shows:

  • Flash regions (Descriptor, BIOS, ME, GbE, PDR)
  • Region base addresses and sizes
  • Flash component information
  • Master access permissions

Supported Firmware Formats

ExtensionDescription
.binRaw firmware/SPI flash dumps
.romSPI flash ROM dumps
.fdUEFI Firmware Descriptor (OVMF, EDK2)
.capUEFI Capsule update files
.scapSigned UEFI Capsule updates
.fvUEFI Firmware Volume
.flashFull flash dumps

Workflows

Workflow 1: Standard Security Audit

Complete firmware security assessment:

bash
TARGET="firmware.bin"
OUTPUT_DIR="./chipsec-analysis"
mkdir -p "$OUTPUT_DIR"

# Step 1: Scan for known threats (most important)
echo "[+] Scanning for known malware/vulnerabilities..."
chipsec_main -i -n -m tools.uefi.scan_blocked -a "$TARGET" 2>&1 | tee "$OUTPUT_DIR/threat_scan.txt"

# Step 2: Generate EFI inventory
echo "[+] Generating EFI executable inventory..."
chipsec_main -i -n -m tools.uefi.scan_image -a generate "$OUTPUT_DIR/efi_inventory.json" "$TARGET"

# Step 3: Decode firmware structure
echo "[+] Decoding firmware structure..."
chipsec_util -i -n uefi decode "$TARGET"

# Step 4: Check for NVRAM in decoded output
echo "[+] Checking for extracted NVRAM variables..."
cat "$TARGET.dir/nvram_.nvram.lst" 2>/dev/null || echo "No NVRAM variables extracted"

echo "[+] Analysis complete. Results in: $OUTPUT_DIR/"
echo "[+] Decoded firmware in: $TARGET.dir/"
Workflow 2: Malware Detection Focus

Quick check for known threats:

bash
# Run blocklist scan
chipsec_main -i -n -m tools.uefi.scan_blocked -a firmware.bin 2>&1 | tee scan_results.txt

# Check for any matches
echo "[+] Checking for threat matches..."
grep -E "match|found|WARNING" scan_results.txt

# If threats found, get details
grep -A10 "found EFI binary matching" scan_results.txt
Workflow 3: Firmware Update Verification

Compare before/after firmware update:

bash
# Before update - create baseline
chipsec_main -i -n -m tools.uefi.scan_image -a generate baseline_before.json firmware_original.bin

# After update - compare
chipsec_main -i -n -m tools.uefi.scan_image -a check baseline_before.json firmware_updated.bin

# Also generate new inventory for diff analysis
chipsec_main -i -n -m tools.uefi.scan_image -a generate baseline_after.json firmware_updated.bin

# Compare inventories
diff baseline_before.json baseline_after.json
Workflow 4: Incident Response

Analyze potentially compromised firmware:

bash
SUSPECT="compromised_dump.bin"
KNOWN_GOOD="golden_image.bin"
OUTPUT_DIR="./ir-analysis"
mkdir -p "$OUTPUT_DIR"

# 1. Immediate threat scan
echo "[!] Scanning for known implants..."
chipsec_main -i -n -m tools.uefi.scan_blocked -a "$SUSPECT" 2>&1 | tee "$OUTPUT_DIR/threat_scan.txt"

# 2. Generate inventory of suspect firmware
chipsec_main -i -n -m tools.uefi.scan_image -a generate "$OUTPUT_DIR/suspect_inventory.json" "$SUSPECT"

# 3. If golden image available, compare
if [ -f "$KNOWN_GOOD" ]; then
    chipsec_main -i -n -m tools.uefi.scan_image -a generate "$OUTPUT_DIR/golden_inventory.json" "$KNOWN_GOOD"
    echo "[+] Comparing against known-good baseline..."
    chipsec_main -i -n -m tools.uefi.scan_image -a check "$OUTPUT_DIR/golden_inventory.json" "$SUSPECT"
fi

# 4. Full decode for manual analysis
chipsec_util -i -n uefi decode "$SUSPECT"

echo "[+] IR analysis complete. Review: $OUTPUT_DIR/"
Workflow 5: IoT Device Firmware Analysis

Analyze firmware extracted from IoT device:

bash
# After extracting firmware with ffind or binwalk
IOT_FIRMWARE="extracted_firmware.bin"

# Quick threat check
chipsec_main -i -n -m tools.uefi.scan_blocked -a "$IOT_FIRMWARE"

# Generate inventory for documentation
chipsec_main -i -n -m tools.uefi.scan_image -a generate iot_efi_list.json "$IOT_FIRMWARE"

# Extract structure for deeper analysis
chipsec_util -i -n uefi decode "$IOT_FIRMWARE"

# NVRAM variables extracted as part of decode - check output
cat "$IOT_FIRMWARE.dir/nvram_.nvram.lst" 2>/dev/null

Output Interpretation

Exit Codes
CodeMeaning
0All checks passed, no issues found
2Security issues detected (FAILED tests)
16Module execution errors
128Module not applicable
Result States
StateMeaningAction
PASSEDNo known threats detectedDocument and proceed
WARNINGPotential issue foundInvestigate further
FAILEDSecurity vulnerability confirmedRemediate immediately
NOT APPLICABLETest couldn't runCheck firmware format
Show full SKILL.md (404 more words)Show less
Interpreting Threat Matches

When scan_blocked finds a match:

[!] match 'ThinkPwn.SystemSmmRuntimeRt'
    GUID  : {7c79ac8c-5e6c-4e3d-ba6f-c260ee7c172e}
    regexp: bytes '...' at offset 1184h
[!] found EFI binary matching 'ThinkPwn'
    MD5   : 59f5ba825911e7d0dffe06ee0d6d9828
    SHA1  : 4979bc7660fcf3ab5562ef2e1c4c45097ecb615e
    SHA256: 7f0e16f244151e7bfa170b7def014f6a225c5af626c223567f36a8b19f95e3ab

Key Information:

  • Threat Name: Which known threat was matched
  • GUID: Unique identifier of the affected EFI module
  • Hashes: For further threat intelligence lookup
  • Offset: Location in binary where pattern matched

Integration with IoTHackBot Tools

With ffind (Firmware Extraction)
bash
# Find firmware files in extracted filesystem
ffind /path/to/extracted -a

# Analyze found UEFI firmware
chipsec_main -i -n -m tools.uefi.scan_blocked -a found_firmware.bin
With binwalk (Pre-processing)
bash
# Extract firmware components first
binwalk -e firmware_package.bin

# Find and analyze UEFI images
find _firmware_package.bin.extracted -name "*.fd" -o -name "*.rom" | while read fw; do
    echo "[+] Analyzing: $fw"
    chipsec_main -i -n -m tools.uefi.scan_blocked -a "$fw"
done

Troubleshooting

Permission Denied on Logs
PermissionError: [Errno 13] Permission denied: '.../site-packages/logs/...'

Solution: create the logs directory inside the chipsec install (the Python version in the path varies, so derive it):

bash
CHIPSEC_DIR="$(find /usr/lib/python3*/site-packages ~/.local/lib/python3*/site-packages -maxdepth 1 -name chipsec -type d 2>/dev/null | head -1)"
sudo mkdir -p "$CHIPSEC_DIR/logs"
sudo chmod 777 "$CHIPSEC_DIR/logs"
Module Not Found
ERROR: No module named 'chipsec.modules.tools.uefi.scan_blocked'

Solution: Verify chipsec installation:

bash
pip show chipsec
pip install --upgrade chipsec
Invalid Firmware Format
[CHIPSEC] Found 0 EFI executables in UEFI firmware image

Possible Causes:

  • File is not valid UEFI firmware
  • File is encrypted or compressed
  • File needs pre-processing (binwalk extraction)

Diagnosis:

bash
file firmware.bin
binwalk firmware.bin
Platform Required for spidesc
ERROR: This module requires a configuration to be loaded.

Solution: Specify platform with -p:

bash
chipsec_util -p SKL spidesc firmware.bin
NVRAM Not Extracted

If nvram_.nvram.lst is empty or shows an error after decode:

Possible Causes:

  • Firmware doesn't contain standard NVRAM format
  • NVRAM region is encrypted or compressed
  • Non-standard vendor format

Alternative Analysis:

bash
# Search for variable-like patterns in decoded output
grep -r "Setup\|Boot\|SecureBoot" firmware.bin.dir/

# Use binwalk to find NVRAM signatures
binwalk -R "\x06\x00\x00\x00" firmware.bin

Best Practices

1. Always Run Threat Scan First

The blocklist scan is quick and catches known threats:

bash
chipsec_main -i -n -m tools.uefi.scan_blocked -a firmware.bin
2. Generate Inventory for Every Firmware

Create baselines for future comparison:

bash
chipsec_main -i -n -m tools.uefi.scan_image -a generate "$(basename firmware.bin .bin)_inventory.json" firmware.bin
3. Save All Output

Redirect output for documentation:

bash
chipsec_main -i -n -m tools.uefi.scan_blocked -a firmware.bin 2>&1 | tee analysis_$(date +%Y%m%d).txt
4. Verify Firmware Format First

Before running chipsec:

bash
file firmware.bin
binwalk firmware.bin | head -20
5. Use Organized Output Directories
bash
mkdir -p analysis/{threats,inventories,decoded,nvram}
6. Cross-Reference with Other Tools
  • UEFITool: Visual firmware structure analysis
  • binwalk: Entropy analysis and extraction
  • strings: Quick secrets/URL discovery

Command Reference

Quick Reference Table
TaskCommand
Scan for malwarechipsec_main -i -n -m tools.uefi.scan_blocked -a <fw>
Generate inventorychipsec_main -i -n -m tools.uefi.scan_image -a generate <out.json> <fw>
Compare baselinechipsec_main -i -n -m tools.uefi.scan_image -a check <base.json> <fw>
Decode structure + NVRAMchipsec_util -i -n uefi decode <fw>
Parse SPI descriptorchipsec_util -p <PLAT> spidesc <fw>
Flag Reference
FlagPurpose
-iIgnore platform check (required for offline)
-nNo kernel driver (required for static analysis)
-mSpecify module to run
-aModule arguments
-pSpecify platform (for spidesc)
-jJSON output file

Security and Ethics

IMPORTANT: Only analyze firmware you own or have explicit authorization to analyze.

  • Respect intellectual property and licensing
  • Follow responsible disclosure for vulnerabilities found
  • Document all analysis activities
  • Be aware that some firmware may contain proprietary code
  • Use findings for defensive security purposes only

Success Criteria

A successful chipsec static analysis includes:

  • Threat scan completed (PASSED or findings documented)
  • EFI inventory JSON generated with module hashes
  • Firmware structure decoded (if applicable)
  • NVRAM variables extracted (if present)
  • All findings documented with:
    • Threat name and severity
    • Affected module GUID and hashes
    • Recommendations for remediation
  • Output files organized and saved for reporting

© BrownFineSecurity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/chipsec of BrownFineSecurity/iothackbot.

Open the folder on GitHubat commit d443c40

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in BrownFineSecurity/iothackbot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Chipsec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Chipsec compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Chipsec this skillBrownFineSecurity/iothackbot8581 repos~3.9kAutomated safety check: NotesMIT
Semgrepvigolium/piolium1381 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner286—~6.2kAutomated safety check: PassNone
Sast SemgrepAgentSecOps/SecOpsAgentKit2192 repos~2.4kAutomated safety check: PassCustom licence

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    138 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    286 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    219 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Wp Phpstan

    Automattic/agent-skills

    A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

    211 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed

More from BrownFineSecurity/iothackbot

All 8 skills in this repo
  • Ffind

    BrownFineSecurity/iothackbot

    Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

    858 GitHub starsUsed in 1 repo~730 tokens
    Auto-check: notes
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    858 GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 1 repo~3.8k tokens
    Auto-check: notes
  • Onvifscan

    BrownFineSecurity/iothackbot

    ONVIF device security scanner for testing authentication and brute-forcing credentials.

    858 GitHub starsUsed in 1 repo~608 tokens
    Auto-check passed
  • Wsdiscovery

    BrownFineSecurity/iothackbot

    WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

    858 GitHub starsUsed in 1 repo~628 tokens
    Auto-check passed
  • Jtagprobe

    BrownFineSecurity/iothackbot

    Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.

    858 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Chipsec

What does Chipsec do?

Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. Chipsec is an agent skill from BrownFineSecurity/iothackbot. Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

When should I use Chipsec?

Chipsec fits situations like: analyzing firmware .bin/.rom/.fd/.cap files offline without requiring hardware access; tasks that involve Static analysis and SAST.

How do I install Chipsec in Claude Code?

Run `npx skills add BrownFineSecurity/iothackbot --skill chipsec -a claude-code`. Or copy the skill folder (skills/chipsec in BrownFineSecurity/iothackbot) into .claude/skills/chipsec in your project. Claude Code loads it when a task matches its description.

How do I install Chipsec in Codex?

Run `npx skills add BrownFineSecurity/iothackbot --skill chipsec -a codex`. Or copy the skill folder (skills/chipsec in BrownFineSecurity/iothackbot) into .agents/skills/chipsec in your project. Codex loads it when a task matches its description.

Can I use Chipsec in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill chipsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chipsec, .gemini/skills/chipsec, .github/skills/chipsec and .opencode/skills/chipsec in your project.

What does Chipsec need to run?

Going by SKILL.md and its folder, Chipsec needs the command-line tools its instructions call (pip). Our summary lists: Python 3.

Does Chipsec access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Chipsec safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Chipsec use?

Chipsec is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Chipsec use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Chipsec?

Skills that share tags, products or a category with Chipsec: Semgrep (vigolium/piolium, 138 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Chipsec?

BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.

Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.