Semgrep
vigolium/piolium
Run Semgrep static analysis scan on a codebase using parallel subagents.
Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.
$ npx skills add BrownFineSecurity/iothackbot --skill chipsec -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install BrownFineSecurity/iothackbot chipsec --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/chipsec .claude/skills/chipsec && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "chipsec" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/chipsec into .claude/skills/chipsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chipsec", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/chipsecType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add BrownFineSecurity/iothackbot --skill chipsec -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install BrownFineSecurity/iothackbot chipsec --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/chipsec .agents/skills/chipsec && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "chipsec" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/chipsec into .agents/skills/chipsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chipsec", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BrownFineSecurity/iothackbot --skill chipsec -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install BrownFineSecurity/iothackbot chipsec --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/chipsec .cursor/skills/chipsec && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "chipsec" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/chipsec into .cursor/skills/chipsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chipsec", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/BrownFineSecurity/iothackbot.git --path skills/chipsec--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add BrownFineSecurity/iothackbot --skill chipsec -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install BrownFineSecurity/iothackbot chipsec --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/chipsec .gemini/skills/chipsec && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "chipsec" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/chipsec into .gemini/skills/chipsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chipsec", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install BrownFineSecurity/iothackbot chipsecInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add BrownFineSecurity/iothackbot --skill chipsec -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/chipsec .github/skills/chipsec && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "chipsec" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/chipsec into .github/skills/chipsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chipsec", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BrownFineSecurity/iothackbot --skill chipsec -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install BrownFineSecurity/iothackbot chipsec --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/chipsec .opencode/skills/chipsec && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "chipsec" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/chipsec into .opencode/skills/chipsec/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "chipsec", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
chipsecStatic analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.
Chipsec is an agent skill from BrownFineSecurity/iothackbot. Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. Decode firmware structure, detect known malware and rootkits (LoJax, ThinkPwn, HackingTeam, MosaicRegressor), generate EFI executable inventories with hashes, extract NVRAM variables, and parse SPI flash descriptors. Use when analyzing firmware .bin/.rom/.fd/.cap files offline without requiring hardware access.
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Static analysis and SAST. The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Chipsec loads about 3.9k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 1,000 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
sudo mkdir -p "$CHIPSEC_DIR/logs"sudo chmod 777 "$CHIPSEC_DIR/logs"sudo mkdir -p "$CHIPSEC_DIR/logs"sudo chmod 777 "$CHIPSEC_DIR/logs"Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from BrownFineSecurity/iothackbot at commit d443c40, republished under its MIT licence (© BrownFineSecurity). 1,000 words, ~3,889 tokens.
.claude/skills/chipsec/SKILL.md (or your agent's skills folder).You are helping the user perform static security analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. This skill focuses exclusively on offline analysis capabilities that do not require kernel driver access or root privileges.
Chipsec is Intel's Platform Security Assessment Framework. For static analysis of firmware dumps, it provides:
Chipsec writes into a logs/ directory inside its install location. Create it once. The Python version in the path varies by system, so derive the path instead of hardcoding it:
CHIPSEC_DIR="$(find /usr/lib/python3*/site-packages ~/.local/lib/python3*/site-packages -maxdepth 1 -name chipsec -type d 2>/dev/null | head -1)"
sudo mkdir -p "$CHIPSEC_DIR/logs"
sudo chmod 777 "$CHIPSEC_DIR/logs"chipsec_main --versionAll static analysis commands use these flags:
-i : Ignore platform check (required for offline analysis)-n : No kernel driver (required for static analysis)Scan firmware for known threats including UEFI rootkits and SMM vulnerabilities:
chipsec_main -i -n -m tools.uefi.scan_blocked -a <firmware.bin>Detected Threats:
| Threat | Description | Reference |
|---|---|---|
| HT_UEFI_Rootkit | HackingTeam commercial UEFI rootkit | McAfee ATR |
| MR_UEFI_Rootkit | MosaicRegressor APT UEFI implant | Kaspersky |
| LoJax | First UEFI rootkit found in the wild (Sednit/APT28) | ESET |
| ThinkPwn | SystemSmmRuntimeRt SMM code execution vulnerability | cr4.sh |
| FirmwareBleed | SMM Return Stack Buffer stuffing vulnerability | Binarly |
Example Output (Threat Found):
[!] match 'ThinkPwn.SystemSmmRuntimeRt'
GUID : {7c79ac8c-5e6c-4e3d-ba6f-c260ee7c172e}
[!] found EFI binary matching 'ThinkPwn'
MD5 : 59f5ba825911e7d0dffe06ee0d6d9828
SHA256: 7f0e16f244151e7bfa170b7def014f6a225c5af626c223567f36a8b19f95e3ab
WARNING: Blocked EFI binary found in the UEFI firmware imageCreate a JSON manifest of all EFI modules with cryptographic hashes:
chipsec_main -i -n -m tools.uefi.scan_image -a generate <output.json> <firmware.bin>Use Cases:
Output Format (efilist.json):
{
"sha256_hash": {
"sha1": "...",
"guid": "EFD652CC-0E99-40F0-96C0-E08C089070FC",
"name": "S3Resume",
"type": "S_PE32"
}
}Check firmware against a known-good inventory:
chipsec_main -i -n -m tools.uefi.scan_image -a check <baseline.json> <firmware.bin>Use Cases:
Extract and analyze firmware volumes, files, and sections:
chipsec_util -i -n uefi decode <firmware.bin>Creates output directory containing:
firmware.bin.dir/
├── firmware_volumes/ # Extracted FV regions
├── efi_files/ # Individual EFI binaries
├── nvram/ # NVRAM variables (if found)
└── ...NVRAM variables are extracted as part of the uefi decode command:
chipsec_util -i -n uefi decode <firmware.bin>NVRAM output location:
firmware.bin.dir/
├── nvram_.nvram.lst # List of NVRAM variables
├── nvram/ # Extracted variable files (if present)
└── FV/ # Firmware volumesView extracted variables:
cat firmware.bin.dir/nvram_.nvram.lstNote: The standalone uefi nvram command requires driver access and cannot be used for static analysis. Use uefi decode instead, which extracts NVRAM as part of the full firmware decode process.
Analyze SPI flash regions (requires platform hint):
chipsec_util -p <PLATFORM> spidesc <firmware.bin>Common Platform Codes:
| Code | Platform |
|---|---|
| SNB | Sandy Bridge (2nd Gen Core) |
| IVB | Ivy Bridge (3rd Gen Core) |
| HSW | Haswell (4th Gen Core) |
| BDW | Broadwell (5th Gen Core) |
| SKL | Skylake (6th Gen Core) |
| KBL | Kaby Lake (7th Gen Core) |
| CFL | Coffee Lake (8th/9th Gen Core) |
| ICL | Ice Lake (10th Gen Core) |
| TGL | Tiger Lake (11th Gen Core) |
| ADL | Alder Lake (12th Gen Core) |
| RPL | Raptor Lake (13th Gen Core) |
Shows:
| Extension | Description |
|---|---|
.bin | Raw firmware/SPI flash dumps |
.rom | SPI flash ROM dumps |
.fd | UEFI Firmware Descriptor (OVMF, EDK2) |
.cap | UEFI Capsule update files |
.scap | Signed UEFI Capsule updates |
.fv | UEFI Firmware Volume |
.flash | Full flash dumps |
Complete firmware security assessment:
TARGET="firmware.bin"
OUTPUT_DIR="./chipsec-analysis"
mkdir -p "$OUTPUT_DIR"
# Step 1: Scan for known threats (most important)
echo "[+] Scanning for known malware/vulnerabilities..."
chipsec_main -i -n -m tools.uefi.scan_blocked -a "$TARGET" 2>&1 | tee "$OUTPUT_DIR/threat_scan.txt"
# Step 2: Generate EFI inventory
echo "[+] Generating EFI executable inventory..."
chipsec_main -i -n -m tools.uefi.scan_image -a generate "$OUTPUT_DIR/efi_inventory.json" "$TARGET"
# Step 3: Decode firmware structure
echo "[+] Decoding firmware structure..."
chipsec_util -i -n uefi decode "$TARGET"
# Step 4: Check for NVRAM in decoded output
echo "[+] Checking for extracted NVRAM variables..."
cat "$TARGET.dir/nvram_.nvram.lst" 2>/dev/null || echo "No NVRAM variables extracted"
echo "[+] Analysis complete. Results in: $OUTPUT_DIR/"
echo "[+] Decoded firmware in: $TARGET.dir/"Quick check for known threats:
# Run blocklist scan
chipsec_main -i -n -m tools.uefi.scan_blocked -a firmware.bin 2>&1 | tee scan_results.txt
# Check for any matches
echo "[+] Checking for threat matches..."
grep -E "match|found|WARNING" scan_results.txt
# If threats found, get details
grep -A10 "found EFI binary matching" scan_results.txtCompare before/after firmware update:
# Before update - create baseline
chipsec_main -i -n -m tools.uefi.scan_image -a generate baseline_before.json firmware_original.bin
# After update - compare
chipsec_main -i -n -m tools.uefi.scan_image -a check baseline_before.json firmware_updated.bin
# Also generate new inventory for diff analysis
chipsec_main -i -n -m tools.uefi.scan_image -a generate baseline_after.json firmware_updated.bin
# Compare inventories
diff baseline_before.json baseline_after.jsonAnalyze potentially compromised firmware:
SUSPECT="compromised_dump.bin"
KNOWN_GOOD="golden_image.bin"
OUTPUT_DIR="./ir-analysis"
mkdir -p "$OUTPUT_DIR"
# 1. Immediate threat scan
echo "[!] Scanning for known implants..."
chipsec_main -i -n -m tools.uefi.scan_blocked -a "$SUSPECT" 2>&1 | tee "$OUTPUT_DIR/threat_scan.txt"
# 2. Generate inventory of suspect firmware
chipsec_main -i -n -m tools.uefi.scan_image -a generate "$OUTPUT_DIR/suspect_inventory.json" "$SUSPECT"
# 3. If golden image available, compare
if [ -f "$KNOWN_GOOD" ]; then
chipsec_main -i -n -m tools.uefi.scan_image -a generate "$OUTPUT_DIR/golden_inventory.json" "$KNOWN_GOOD"
echo "[+] Comparing against known-good baseline..."
chipsec_main -i -n -m tools.uefi.scan_image -a check "$OUTPUT_DIR/golden_inventory.json" "$SUSPECT"
fi
# 4. Full decode for manual analysis
chipsec_util -i -n uefi decode "$SUSPECT"
echo "[+] IR analysis complete. Review: $OUTPUT_DIR/"Analyze firmware extracted from IoT device:
# After extracting firmware with ffind or binwalk
IOT_FIRMWARE="extracted_firmware.bin"
# Quick threat check
chipsec_main -i -n -m tools.uefi.scan_blocked -a "$IOT_FIRMWARE"
# Generate inventory for documentation
chipsec_main -i -n -m tools.uefi.scan_image -a generate iot_efi_list.json "$IOT_FIRMWARE"
# Extract structure for deeper analysis
chipsec_util -i -n uefi decode "$IOT_FIRMWARE"
# NVRAM variables extracted as part of decode - check output
cat "$IOT_FIRMWARE.dir/nvram_.nvram.lst" 2>/dev/null| Code | Meaning |
|---|---|
| 0 | All checks passed, no issues found |
| 2 | Security issues detected (FAILED tests) |
| 16 | Module execution errors |
| 128 | Module not applicable |
| State | Meaning | Action |
|---|---|---|
| PASSED | No known threats detected | Document and proceed |
| WARNING | Potential issue found | Investigate further |
| FAILED | Security vulnerability confirmed | Remediate immediately |
| NOT APPLICABLE | Test couldn't run | Check firmware format |
When scan_blocked finds a match:
[!] match 'ThinkPwn.SystemSmmRuntimeRt'
GUID : {7c79ac8c-5e6c-4e3d-ba6f-c260ee7c172e}
regexp: bytes '...' at offset 1184h
[!] found EFI binary matching 'ThinkPwn'
MD5 : 59f5ba825911e7d0dffe06ee0d6d9828
SHA1 : 4979bc7660fcf3ab5562ef2e1c4c45097ecb615e
SHA256: 7f0e16f244151e7bfa170b7def014f6a225c5af626c223567f36a8b19f95e3abKey Information:
# Find firmware files in extracted filesystem
ffind /path/to/extracted -a
# Analyze found UEFI firmware
chipsec_main -i -n -m tools.uefi.scan_blocked -a found_firmware.bin# Extract firmware components first
binwalk -e firmware_package.bin
# Find and analyze UEFI images
find _firmware_package.bin.extracted -name "*.fd" -o -name "*.rom" | while read fw; do
echo "[+] Analyzing: $fw"
chipsec_main -i -n -m tools.uefi.scan_blocked -a "$fw"
donePermissionError: [Errno 13] Permission denied: '.../site-packages/logs/...'Solution: create the logs directory inside the chipsec install (the Python version in the path varies, so derive it):
CHIPSEC_DIR="$(find /usr/lib/python3*/site-packages ~/.local/lib/python3*/site-packages -maxdepth 1 -name chipsec -type d 2>/dev/null | head -1)"
sudo mkdir -p "$CHIPSEC_DIR/logs"
sudo chmod 777 "$CHIPSEC_DIR/logs"ERROR: No module named 'chipsec.modules.tools.uefi.scan_blocked'Solution: Verify chipsec installation:
pip show chipsec
pip install --upgrade chipsec[CHIPSEC] Found 0 EFI executables in UEFI firmware imagePossible Causes:
Diagnosis:
file firmware.bin
binwalk firmware.binERROR: This module requires a configuration to be loaded.Solution: Specify platform with -p:
chipsec_util -p SKL spidesc firmware.binIf nvram_.nvram.lst is empty or shows an error after decode:
Possible Causes:
Alternative Analysis:
# Search for variable-like patterns in decoded output
grep -r "Setup\|Boot\|SecureBoot" firmware.bin.dir/
# Use binwalk to find NVRAM signatures
binwalk -R "\x06\x00\x00\x00" firmware.binThe blocklist scan is quick and catches known threats:
chipsec_main -i -n -m tools.uefi.scan_blocked -a firmware.binCreate baselines for future comparison:
chipsec_main -i -n -m tools.uefi.scan_image -a generate "$(basename firmware.bin .bin)_inventory.json" firmware.binRedirect output for documentation:
chipsec_main -i -n -m tools.uefi.scan_blocked -a firmware.bin 2>&1 | tee analysis_$(date +%Y%m%d).txtBefore running chipsec:
file firmware.bin
binwalk firmware.bin | head -20mkdir -p analysis/{threats,inventories,decoded,nvram}| Task | Command |
|---|---|
| Scan for malware | chipsec_main -i -n -m tools.uefi.scan_blocked -a <fw> |
| Generate inventory | chipsec_main -i -n -m tools.uefi.scan_image -a generate <out.json> <fw> |
| Compare baseline | chipsec_main -i -n -m tools.uefi.scan_image -a check <base.json> <fw> |
| Decode structure + NVRAM | chipsec_util -i -n uefi decode <fw> |
| Parse SPI descriptor | chipsec_util -p <PLAT> spidesc <fw> |
| Flag | Purpose |
|---|---|
-i | Ignore platform check (required for offline) |
-n | No kernel driver (required for static analysis) |
-m | Specify module to run |
-a | Module arguments |
-p | Specify platform (for spidesc) |
-j | JSON output file |
IMPORTANT: Only analyze firmware you own or have explicit authorization to analyze.
A successful chipsec static analysis includes:
© BrownFineSecurity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/chipsec of BrownFineSecurity/iothackbot.
Open the folder on GitHubat commit d443c40
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in BrownFineSecurity/iothackbot, which our catalogue first saw on October 7, 2026.
Chipsec next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Chipsec this skillBrownFineSecurity/iothackbot | 858 | 1 repos | ~3.9k | Automated safety check: Notes | MIT | |
| Semgrepvigolium/piolium | 138 | 1 repos | ~2.4k | Automated safety check: Notes | MIT | |
| C To AstNarwhal-Lab/MagicSkills | 316 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Semgrep Security Scantrailofbits/skills | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| LLM Sast ScannerSunWeb3Sec/llm-sast-scanner | 286 | — | ~6.2k | Automated safety check: Pass | None | |
| Sast SemgrepAgentSecOps/SecOpsAgentKit | 219 | 2 repos | ~2.4k | Automated safety check: Pass | Custom licence |
vigolium/piolium
Run Semgrep static analysis scan on a codebase using parallel subagents.
Narwhal-Lab/MagicSkills
Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
SunWeb3Sec/llm-sast-scanner
General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.
AgentSecOps/SecOpsAgentKit
Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.
Automattic/agent-skills
A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…
BrownFineSecurity/iothackbot
Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.
BrownFineSecurity/iothackbot
IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.
BrownFineSecurity/iothackbot
Professional network reconnaissance and port scanning using nmap.
BrownFineSecurity/iothackbot
ONVIF device security scanner for testing authentication and brute-forcing credentials.
BrownFineSecurity/iothackbot
WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.
BrownFineSecurity/iothackbot
Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.
Categories
Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. Chipsec is an agent skill from BrownFineSecurity/iothackbot. Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.
Chipsec fits situations like: analyzing firmware .bin/.rom/.fd/.cap files offline without requiring hardware access; tasks that involve Static analysis and SAST.
Run `npx skills add BrownFineSecurity/iothackbot --skill chipsec -a claude-code`. Or copy the skill folder (skills/chipsec in BrownFineSecurity/iothackbot) into .claude/skills/chipsec in your project. Claude Code loads it when a task matches its description.
Run `npx skills add BrownFineSecurity/iothackbot --skill chipsec -a codex`. Or copy the skill folder (skills/chipsec in BrownFineSecurity/iothackbot) into .agents/skills/chipsec in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill chipsec -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chipsec, .gemini/skills/chipsec, .github/skills/chipsec and .opencode/skills/chipsec in your project.
Going by SKILL.md and its folder, Chipsec needs the command-line tools its instructions call (pip). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Chipsec is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Chipsec: Semgrep (vigolium/piolium, 138 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.
Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.