Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

MITAuto-check: notes

Install Ffind

skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill ffind -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BrownFineSecurity/iothackbot ffind --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ffind .claude/skills/ffind && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ffind
GitHub stars
858
Used in
1 other repo
Token cost
~730 tokens
SKILL.md length
328 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

  • Works in 4 steps: Understand the target → Execute the analysis → Output formats → …
  • You need to analyze firmware files
  • SKILL.md covers Tool Overview, Instructions, Examples and Important Notes
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ffind is an agent skill from BrownFineSecurity/iothackbot. Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems. Use when you need to analyze firmware files, identify file types, or extract ext2/3/4 or F2FS filesystems.

Its SKILL.md is about 730 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.

When your agent uses it

  • You need to analyze firmware files
  • Identify file types
  • Extract ext2/3/4
  • F2FS filesystems

Example prompts

  • “/ffind”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Understand the target
  2. Execute the analysis
  3. Output formats
  4. Extraction capabilities

What it can do on your machine

Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ffind loads about 730 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 328 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~730

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:39
    - Requires sudo privileges for extraction
  • NoteRuns commands with sudoSKILL.md:51
    sudo ffind /path/to/firmware.bin -e
  • NoteRuns commands with sudoSKILL.md:61
    sudo ffind /path/to/firmware.bin -e -d /tmp/my-extraction

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BrownFineSecurity/iothackbot at commit d443c40, republished under its MIT licence (© BrownFineSecurity). 328 words, ~730 tokens.

Download SKILL.mdSave it as .claude/skills/ffind/SKILL.md (or your agent's skills folder).
name
ffind
description
Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems. Use when you need to analyze firmware files, identify file types, or extract ext2/3/4 or F2FS filesystems.

Ffind - Advanced File Finder with Extraction

You are helping the user find and analyze files with advanced type detection and optional filesystem extraction capabilities using the ffind tool.

Tool Overview

Ffind analyzes files and directories, identifies file types, and can extract filesystems (ext2/3/4, F2FS) for deeper analysis. It's designed for firmware and IoT device analysis.

Instructions

When the user asks to analyze files, find specific file types, or extract filesystems:

  1. Understand the target:

    • Ask what path(s) they want to analyze
    • Determine if they want to extract filesystems or just analyze
    • Ask if they want all file types or just artifact types
  2. Execute the analysis:

    • Use the ffind command from the iothackbot bin directory
    • Basic usage: ffind <path> [<path2> ...]
    • To extract filesystems: ffind <path> -e
    • Custom extraction directory: ffind <path> -e -d /path/to/output
    • Show all file types: ffind <path> -a
    • Verbose output: ffind <path> -v
  3. Output formats:

    • --format text (default): Human-readable colored output with type summaries
    • --format json: Machine-readable JSON
    • --format quiet: Minimal output
  4. Extraction capabilities:

    • Supports ext2/ext3/ext4 filesystems (requires e2fsprogs)
    • Supports F2FS filesystems (requires f2fs-tools)
    • Requires sudo privileges for extraction
    • Default extraction location: /tmp/ffind_<timestamp>

Examples

Analyze a firmware file to see file types:

bash
ffind /path/to/firmware.bin

Extract all filesystems from a firmware image:

bash
sudo ffind /path/to/firmware.bin -e

Analyze multiple files and show all types:

bash
ffind /path/to/file1.bin /path/to/file2.bin -a

Extract to a custom directory:

bash
sudo ffind /path/to/firmware.bin -e -d /tmp/my-extraction

Important Notes

  • Name collision: The Sleuth Kit also ships a ffind (it finds file names for a given inode and takes a disk image plus an inode number). If which ffind points at /usr/bin/ffind or /usr/local/bin/ffind, the iothackbot flags below (-e, -d <dir>, -a, --format) will be misread by the wrong binary. Confirm with ffind --help (the iothackbot tool shows --extract/--format); if it shows image inode usage, invoke the iothackbot tool by its full path in the repo bin/ directory instead.
  • Extraction requires root/sudo privileges
  • Requires external tools: e2fsprogs, f2fs-tools, util-linux
  • Identifies "artifact" file types relevant to security analysis by default
  • Use -a flag to see all file types including common formats

© BrownFineSecurity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ffind of BrownFineSecurity/iothackbot.

Open the folder on GitHubat commit d443c40

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in BrownFineSecurity/iothackbot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Ffind next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ffind compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ffind this skillBrownFineSecurity/iothackbot8581 repos~730Automated safety check: NotesMIT
Detecting Model Extraction Attacksmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Threat Detectionalirezarezvani/claude-skills28k—~3.5kAutomated safety check: PassMIT
Extractalirezarezvani/claude-skills28k—~1.4kAutomated safety check: PassMIT
Resemble Detectgithub/awesome-copilot40k3 repos~4.1kAutomated safety check: PassApache-2.0
Motion Advancedaffaan-m/ECC275k1 repos~4.7kAutomated safety check: PassMIT

Similar skills

  • Detecting Model Extraction Attacks

    mukul975/Anthropic-Cybersecurity-Skills

    Detect MITRE ATLAS AML.T0024 attacks (model stealing, inversion, membership inference) performed via inference-API abuse, by monitoring per-principal query volume/distribution, rate-limiting and…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Threat Detection

    alirezarezvani/claude-skills

    A skill your agent uses when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.

    28k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Extract

    alirezarezvani/claude-skills

    Turn a proven pattern or debugging solution into a standalone reusable skill with SKILL.md, reference docs, and examples.

    28k GitHub stars~1.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Resemble Detect

    github/awesome-copilot

    Official

    Deepfake detection and media safety — detect AI-generated audio, images, video, and text, trace synthesis sources, apply watermarks, verify speaker identity, and analyze media intelligence using…

    40k GitHub starsUsed in 3 repos~4.1k tokens
    Media & CreativeAuto-check passed
  • Motion Advanced

    affaan-m/ECC

    Advanced motion patterns for React / Next.js — drag & drop, gestures, text animations, SVG path drawing, custom hooks, imperative sequences (useAnimate), loaders, and the full API decision tree.

    275k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed
  • Analyzing Network Packets With Scapy

    mukul975/Anthropic-Cybersecurity-Skills

    Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets.

    34k GitHub stars~626 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from BrownFineSecurity/iothackbot

All 8 skills in this repo
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 2 repos~3.8k tokens
    Auto-check: notes
  • Chipsec

    BrownFineSecurity/iothackbot

    Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

    858 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    858 GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • Onvifscan

    BrownFineSecurity/iothackbot

    ONVIF device security scanner for testing authentication and brute-forcing credentials.

    858 GitHub starsUsed in 1 repo~608 tokens
    Auto-check passed
  • Wsdiscovery

    BrownFineSecurity/iothackbot

    WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

    858 GitHub starsUsed in 1 repo~628 tokens
    Auto-check passed
  • Jtagprobe

    BrownFineSecurity/iothackbot

    Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.

    858 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Questions about Ffind

What does Ffind do?

Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems. Ffind is an agent skill from BrownFineSecurity/iothackbot. Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

When should I use Ffind?

Ffind fits situations like: you need to analyze firmware files; identify file types; extract ext2/3/4; F2FS filesystems.

How do I install Ffind in Claude Code?

Run `npx skills add BrownFineSecurity/iothackbot --skill ffind -a claude-code`. Or copy the skill folder (skills/ffind in BrownFineSecurity/iothackbot) into .claude/skills/ffind in your project. Claude Code loads it when a task matches its description.

How do I install Ffind in Codex?

Run `npx skills add BrownFineSecurity/iothackbot --skill ffind -a codex`. Or copy the skill folder (skills/ffind in BrownFineSecurity/iothackbot) into .agents/skills/ffind in your project. Codex loads it when a task matches its description.

Can I use Ffind in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill ffind -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ffind, .gemini/skills/ffind, .github/skills/ffind and .opencode/skills/ffind in your project.

What does Ffind need to run?

SKILL.md names no scripts, command-line tools or credentials: Ffind is instructions for the agent only.

Does Ffind access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ffind safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ffind use?

Ffind is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ffind use?

About 730 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ffind?

Skills that share tags, products or a category with Ffind: Detecting Model Extraction Attacks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Threat Detection (alirezarezvani/claude-skills, 28k stars), Extract (alirezarezvani/claude-skills, 28k stars) and Resemble Detect (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ffind?

BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.

Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.