IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

MITAuto-check: notesSecurity

Install Iotnet

skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill iotnet -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BrownFineSecurity/iothackbot iotnet --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/iotnet .claude/skills/iotnet && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iotnet
GitHub stars
858
Used in
1 other repo
Token cost
~1k tokens
SKILL.md length
403 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

  • Works in 3 steps: Determine input type → Gather requirements → Execute the analysis
  • You need to analyze network traffic
  • SKILL.md covers Tool Overview, Instructions, Usage Modes and Parameters, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Iotnet is an agent skill from BrownFineSecurity/iothackbot. IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. Use when you need to analyze network traffic, identify IoT protocols, or assess network security of IoT devices.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Network security. It works with Wireshark. The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.

When your agent uses it

  • You need to analyze network traffic
  • Identify IoT protocols
  • Assess network security of IoT devices

Example prompts

  • “/iotnet”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Determine input type
  2. Gather requirements
  3. Execute the analysis

What it can do on your machine

Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iotnet loads about 1k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 403 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:48
    sudo iotnet -i eth0 -d 30
  • NoteRuns commands with sudoSKILL.md:82
    sudo iotnet -i wlan0 -d 60
  • NoteRuns commands with sudoSKILL.md:92
    sudo iotnet -i eth0 -c "port 1883 or port 5683" -d 45

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BrownFineSecurity/iothackbot at commit d443c40, republished under its MIT licence (© BrownFineSecurity). 403 words, ~1,004 tokens.

Download SKILL.mdSave it as .claude/skills/iotnet/SKILL.md (or your agent's skills folder).
name
iotnet
description
IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. Use when you need to analyze network traffic, identify IoT protocols, or assess network security of IoT devices.

IoTNet - IoT Network Traffic Analyzer

You are helping the user analyze network traffic to detect IoT protocols and identify security vulnerabilities using the iotnet tool.

Tool Overview

IoTNet analyzes network packet captures (PCAPs) or performs live traffic capture to:

  • Detect IoT-specific protocols (MQTT, CoAP, Zigbee, etc.)
  • Identify security vulnerabilities in network traffic
  • Analyze protocol distribution
  • Find unencrypted communications
  • Detect weak authentication mechanisms
  • Identify insecure IoT device behaviors

Instructions

When the user asks to analyze network traffic, capture IoT traffic, or assess network security:

  1. Determine input type:

    • PCAP file analysis (offline)
    • Live network capture (requires interface)
  2. Gather requirements:

    • For PCAP: Get file path(s)
    • For live capture: Get network interface name and duration
    • Ask about filtering needs (specific IPs, protocols)
    • Check if custom detection rules are needed
  3. Execute the analysis:

    • Use the iotnet command from the iothackbot bin directory

Usage Modes

PCAP Analysis (Offline)

Analyze one or more existing packet capture files:

bash
iotnet capture1.pcap capture2.pcap
Live Capture

Capture and analyze traffic in real-time:

bash
sudo iotnet -i eth0 -d 30

Parameters

Input Options:

  • pcap_files: One or more PCAP files to analyze
  • -i, --interface: Network interface for live capture

Filtering Options:

  • --ip: Filter traffic by IP address
  • -c, --capture-filter: BPF syntax filter for live capture
  • --display-filter: Wireshark display filter for PCAP analysis

Live Capture Options:

  • -d, --duration: Capture duration in seconds (default: 30)

Analysis Options:

  • --config: Custom IoT detection rules configuration file
    • Default: config/iot/detection_rules.json in the iothackbot directory

Output Options:

  • --format text|json|quiet: Output format (default: text)
  • -v, --verbose: Detailed output
Show full SKILL.md (163 more words)Show less

Examples

Analyze a packet capture file:

bash
iotnet /path/to/capture.pcap

Live capture for 60 seconds on wifi interface:

bash
sudo iotnet -i wlan0 -d 60

Analyze traffic for specific IP:

bash
iotnet capture.pcap --ip 192.168.1.100

Live capture with BPF filter:

bash
sudo iotnet -i eth0 -c "port 1883 or port 5683" -d 45

Multiple PCAPs with custom config:

bash
iotnet file1.pcap file2.pcap --config custom-rules.json

Filter by display filter (Wireshark syntax):

bash
iotnet capture.pcap --display-filter "mqtt or coap"

Detected IoT Protocols

The tool can identify:

  • MQTT: Message Queue Telemetry Transport
  • CoAP: Constrained Application Protocol
  • Zigbee: Low-power mesh networking
  • Z-Wave: Home automation protocol
  • ONVIF: IP camera protocol
  • UPnP/SSDP: Universal Plug and Play
  • Modbus: Industrial control protocol
  • And many more (configurable)

Security Checks

IoTNet identifies vulnerabilities such as:

  • Unencrypted MQTT traffic
  • Missing TLS/encryption
  • Weak or no authentication
  • Plaintext credentials
  • Insecure protocol versions
  • Known vulnerable implementations

Output Information

Results include:

  • Total packets analyzed
  • Protocol distribution with percentages
  • IoT findings with protocol details and packet info
  • Vulnerabilities with severity levels (high/medium/low)
  • Recommendations for remediation

Important Notes

  • Live capture requires root/sudo privileges
  • Requires network access to specified interface
  • PCAP analysis does not require elevated privileges
  • Detection rules can be customized in config file
  • Supports standard PCAP format from tcpdump, Wireshark, etc.

© BrownFineSecurity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/iotnet of BrownFineSecurity/iothackbot.

Open the folder on GitHubat commit d443c40

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in BrownFineSecurity/iothackbot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Iotnet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iotnet compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iotnet this skillBrownFineSecurity/iothackbot8581 repos~1kAutomated safety check: NotesMIT
Wireshark Analysiszebbern/claude-code-guide4.6k7 repos~3kAutomated safety check: PassMIT
Netzhinkgit/embeddedskills731—~1.1kAutomated safety check: PassMIT
Performing Network Forensics With Wiresharkmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: NotesApache-2.0
Performing Network Traffic Analysis With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: NotesApache-2.0
Analyzing Network Traffic With Wiresharkmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • Wireshark Analysis

    zebbern/claude-code-guide

    This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…

    4.6k GitHub starsUsed in 7 repos~3k tokens
    SecurityAuto-check passed
  • Net

    zhinkgit/embeddedskills

    嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills.

    731 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Network Forensics With Wireshark

    mukul975/Anthropic-Cybersecurity-Skills

    Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Performing Network Traffic Analysis With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Analyzing Network Traffic With Wireshark

    mukul975/Anthropic-Cybersecurity-Skills

    Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Network Traffic Analysis With Tshark

    mukul975/Anthropic-Cybersecurity-Skills

    Automate network traffic analysis using tshark (Wireshark CLI) and pyshark to compute protocol distribution statistics, detect suspicious flows such as port scans and beaconing, extract IOCs (IPs…

    34k GitHub stars~610 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from BrownFineSecurity/iothackbot

All 8 skills in this repo
  • Chipsec

    BrownFineSecurity/iothackbot

    Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

    858 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Ffind

    BrownFineSecurity/iothackbot

    Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

    858 GitHub starsUsed in 1 repo~730 tokens
    Auto-check: notes
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 1 repo~3.8k tokens
    Auto-check: notes
  • Onvifscan

    BrownFineSecurity/iothackbot

    ONVIF device security scanner for testing authentication and brute-forcing credentials.

    858 GitHub starsUsed in 1 repo~608 tokens
    Auto-check passed
  • Wsdiscovery

    BrownFineSecurity/iothackbot

    WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

    858 GitHub starsUsed in 1 repo~628 tokens
    Auto-check passed
  • Jtagprobe

    BrownFineSecurity/iothackbot

    Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.

    858 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Iotnet

What does Iotnet do?

IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. Iotnet is an agent skill from BrownFineSecurity/iothackbot. IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

When should I use Iotnet?

Iotnet fits situations like: you need to analyze network traffic; identify IoT protocols; assess network security of IoT devices.

How do I install Iotnet in Claude Code?

Run `npx skills add BrownFineSecurity/iothackbot --skill iotnet -a claude-code`. Or copy the skill folder (skills/iotnet in BrownFineSecurity/iothackbot) into .claude/skills/iotnet in your project. Claude Code loads it when a task matches its description.

How do I install Iotnet in Codex?

Run `npx skills add BrownFineSecurity/iothackbot --skill iotnet -a codex`. Or copy the skill folder (skills/iotnet in BrownFineSecurity/iothackbot) into .agents/skills/iotnet in your project. Codex loads it when a task matches its description.

Can I use Iotnet in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill iotnet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iotnet, .gemini/skills/iotnet, .github/skills/iotnet and .opencode/skills/iotnet in your project.

What does Iotnet need to run?

SKILL.md names no scripts, command-line tools or credentials: Iotnet is instructions for the agent only.

Does Iotnet access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Iotnet safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Iotnet use?

Iotnet is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iotnet use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iotnet?

Skills that share tags, products or a category with Iotnet: Wireshark Analysis (zebbern/claude-code-guide, 4.6k stars), Net (zhinkgit/embeddedskills, 731 stars), Performing Network Forensics With Wireshark (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Performing Network Traffic Analysis With Zeek (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iotnet?

BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.

Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.