Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.

MITAuto-check passed

Install Jtagprobe

skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill jtagprobe -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BrownFineSecurity/iothackbot jtagprobe --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/jtagprobe .claude/skills/jtagprobe && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
jtagprobe
GitHub stars
858
Token cost
~1.4k tokens
SKILL.md length
668 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.

  • Works in 5 steps: Unknown target, unknown protocol → Known target — pass the device name → Slow targets / long traces /… → …
  • Assessing whether a targets on-chip debug port can be reached
  • SKILL.md covers What the tool tests, Prerequisites, Basic usage and Common workflows, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Jtagprobe is an agent skill from BrownFineSecurity/iothackbot. Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link. Detects whether debug is OPEN, LOCKED (readout-protected), or DEAD (fused off). Use when assessing whether a target's on-chip debug port can be reached, identifying the silicon vendor from DPIDR/IDCODE, and confirming halt+memory access for full debugger control.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.

When your agent uses it

  • Assessing whether a targets on-chip debug port can be reached
  • Identifying the silicon vendor from DPIDR/IDCODE
  • Confirming halt+memory access for full debugger control

Example prompts

  • “/jtagprobe”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Unknown target, unknown protocol
  2. Known target — pass the device name
  3. Slow targets / long traces / level-shifted boards
  4. Layer-1 only (no halt)
  5. SWD only or JTAG only

What it can do on your machine

Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Jtagprobe loads about 1.4k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 668 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BrownFineSecurity/iothackbot at commit d443c40, republished under its MIT licence (© BrownFineSecurity). 668 words, ~1,432 tokens.

Download SKILL.mdSave it as .claude/skills/jtagprobe/SKILL.md (or your agent's skills folder).
name
jtagprobe
description
Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link. Detects whether debug is OPEN, LOCKED (readout-protected), or DEAD (fused off). Use when assessing whether a target's on-chip debug port can be reached, identifying the silicon vendor from DPIDR/IDCODE, and confirming halt+memory access for full debugger control.

Jtagprobe — SWD/JTAG Debug Interface Tester

You are helping the user determine whether a target's on-chip debug interface is exposed via SWD or JTAG, using the jtagprobe tool. This drives a SEGGER J-Link physically wired to the target.

What the tool tests

Three nested access layers are checked, and the target is classified into one of:

  • OPEN — DP responds, CPU halts, memory reads return plausible data. Full debugger control. Critical finding.
  • LOCKED — DP/IDCODE accessible but memory reads fail or return readout-protection sentinels (0xFFFFFFFF). Indicates STM32 RDP, NXP CRP, Nordic APPROTECT, etc. are engaged. Still a finding — the port should not respond at all in production.
  • DEAD — No DP/IDCODE response on any tested interface/speed. Debug fused off, pins not wired, or wrong target.

Prerequisites

  • A SEGGER J-Link (any variant) connected via USB
  • JLinkExe on PATH — verify with which JLinkExe. If it is installed but not on PATH, point the tool at it with --jlink-binary /path/to/JLinkExe instead of relying on PATH.
  • Target wired to the J-Link 20-pin (or 10-pin Cortex Debug) header. Confirm SWDIO/SWCLK or TDI/TDO/TMS/TCK identification before energizing the target.

If JLinkExe cannot be found at all, tell the user to install SEGGER J-Link software from segger.com. Do not attempt to install it without explicit approval.

Basic usage

Default — sweep SWD then JTAG at 4000/1000/100 kHz, halt, read memory, classify:

bash
jtagprobe

Save per-attempt JLinkExe logs as evidence (recommended for pentest writeups):

bash
jtagprobe --evidence-dir ./evidence/jtagprobe-$(date +%Y%m%d-%H%M%S)

JSON for chaining:

bash
jtagprobe --format json

Common workflows

1. Unknown target, unknown protocol

Just run with defaults. The tool will:

  1. Try SWD at 4 MHz → 1 MHz → 100 kHz
  2. Fall back to JTAG with the same speed sweep
  3. Run a JTAG chain auto-scan as last resort
  4. Identify vendor from DPIDR/IDCODE JEP106 designer field
  5. Halt CPU and read memory to confirm access level
bash
jtagprobe --evidence-dir ./evidence
2. Known target — pass the device name

If the user knows the chip, pass --device for a more accurate halt/memory test. Use the same device strings J-Link accepts (STM32F407VG, nRF52840_xxAA, MK64FN1M0xxx12, etc.):

bash
jtagprobe --device STM32F407VG
3. Slow targets / long traces / level-shifted boards

Some pirate-flagged boards or long ribbon cables need a slower clock. Limit the sweep:

bash
jtagprobe --speeds 1000,100,10
4. Layer-1 only (no halt)

If the target is in a state where halting would crash an active firmware path you care about (rare in pentests, common in live systems), stop after the connect probe:

bash
jtagprobe --skip-memory
5. SWD only or JTAG only
bash
jtagprobe --interfaces SWD
jtagprobe --interfaces JTAG --speeds 4000,1000
Show full SKILL.md (282 more words)Show less

Interpreting the output

The text format leads with the classification and reason:

CLASSIFICATION: LOCKED
DP/IDCODE accessible but CPU halt or memory read failed. Typical of RDP / CRP / APPROTECT engaged.

Vendor: STMicroelectronics
  SW-DP DPIDR=0x2BA01477 partno=0xBA version=2 designer_identity=0x20

Access test:
  Halted: True
  CPUID @ 0xE000ED00 = 0x410FC241
  0x08000000: 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF [all-0xFF, possible RDP]

Protection hint: STM32 RDP Level 1/2 (see RM, FLASH_OPTR bits 15:8).

Key signals:

  • A non-zero DPIDR / IDCODE means the silicon answered. Even alone this is reportable.
  • 0xFFFFFFFF flash reads after a successful halt = readout protection. Capture the DPIDR and document the protection mechanism.
  • A "plausible vector table" (initial SP in SRAM range, reset vector with Thumb bit set) is the strongest signal of OPEN access — call this out in writeups.

Writeup-relevant detail

For a pentest finding under CWE-1191 (improper access control on debug interface) or CWE-1244 (asset exposed via debug):

  • Command run: full jtagprobe invocation
  • Classification + reason from the output
  • DPIDR / IDCODE raw value and decoded vendor
  • For OPEN: vector table words proving memory was read
  • For LOCKED: the all-0xFF read proving readout protection is the only line of defense (and that the port itself is still exposed)
  • Evidence files from --evidence-dir for the appendix

When the user says "test for JTAG"

Default assumption: they want both SWD and JTAG checked, full halt+memory test, and evidence captured. Run:

bash
jtagprobe --evidence-dir ./evidence/jtagprobe-$(date +%Y%m%d-%H%M%S)

If JLinkExe isn't on PATH, stop and report that the SEGGER tools aren't installed.

Limitations

  • Requires physical access to the debug header and a J-Link probe wired up. This is not a network or pcap-based check.
  • Generic Cortex-M device profiles are used when no --device is passed. Halt/memory access may succeed under a generic device even when the vendor-specific erase/unlock would not.
  • JLinkExe stdout parsing is regex-based. If SEGGER changes the format in a future release the parser may need updating — --format json shows what was extracted.
  • Does not attempt unlock / mass-erase. That is destructive and out of scope for a probe. Use the vendor's bootrom or unlock commands separately with explicit authorization.

© BrownFineSecurity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/jtagprobe of BrownFineSecurity/iothackbot.

Open the folder on GitHubat commit d443c40

Compare with similar skills

Jtagprobe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Jtagprobe compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Jtagprobe this skillBrownFineSecurity/iothackbot858—~1.4kAutomated safety check: PassMIT
Embedded Iot Mentoralirezarezvani/claude-skills28k—~2.6kAutomated safety check: PassMIT
Embedded DebugFastLED/FastLED7.5k—~1.4kAutomated safety check: PassMIT
Debugasgeirtj/system_prompts_leaks69k—~439Automated safety check: PassCC0-1.0
Openclaw Debuggingopenclaw/openclaw392k—~1.9kAutomated safety check: PassMIT
Embeddingsruvnet/ruflo74k3 repos~455Automated safety check: PassMIT

Similar skills

  • Embedded Iot Mentor

    alirezarezvani/claude-skills

    Mentor for embedded and IoT hardware projects. An agent skill from alirezarezvani/claude-skills.

    28k GitHub stars~2.6k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Embedded Debug

    FastLED/FastLED

    Firmware crash analysis, stack trace decoder, and register dump interpreter for ESP32/ARM/AVR platforms.

    7.5k GitHub stars~1.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Debug

    asgeirtj/system_prompts_leaks

    Enable debug logging for this session and help diagnose issues

    69k GitHub stars~439 tokensUpdated yesterday
    Auto-check passed
  • Openclaw Debugging

    openclaw/openclaw

    Debug OpenClaw model, provider, tool-surface, code-mode, streaming, and live/Crabbox behavior by choosing the right logs, probes, and proof path before changing code, including fetching stored…

    392k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Embeddings

    ruvnet/ruflo

    Vector embeddings with HNSW indexing, sql.js persistence, and hyperbolic support.

    74k GitHub starsUsed in 3 repos~455 tokens
    AI & LLM EngineeringAuto-check passed
  • Official

    Debug failed or wrong-output workflow executions using executions tools.

    207k GitHub stars~2.6k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from BrownFineSecurity/iothackbot

All 8 skills in this repo
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 2 repos~3.8k tokens
    Auto-check: notes
  • Chipsec

    BrownFineSecurity/iothackbot

    Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

    858 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Ffind

    BrownFineSecurity/iothackbot

    Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

    858 GitHub starsUsed in 1 repo~730 tokens
    Auto-check: notes
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    858 GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • Onvifscan

    BrownFineSecurity/iothackbot

    ONVIF device security scanner for testing authentication and brute-forcing credentials.

    858 GitHub starsUsed in 1 repo~608 tokens
    Auto-check passed
  • Wsdiscovery

    BrownFineSecurity/iothackbot

    WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

    858 GitHub starsUsed in 1 repo~628 tokens
    Auto-check passed

Questions about Jtagprobe

What does Jtagprobe do?

Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link. Jtagprobe is an agent skill from BrownFineSecurity/iothackbot. Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.

When should I use Jtagprobe?

Jtagprobe fits situations like: assessing whether a targets on-chip debug port can be reached; identifying the silicon vendor from DPIDR/IDCODE; confirming halt+memory access for full debugger control.

How do I install Jtagprobe in Claude Code?

Run `npx skills add BrownFineSecurity/iothackbot --skill jtagprobe -a claude-code`. Or copy the skill folder (skills/jtagprobe in BrownFineSecurity/iothackbot) into .claude/skills/jtagprobe in your project. Claude Code loads it when a task matches its description.

How do I install Jtagprobe in Codex?

Run `npx skills add BrownFineSecurity/iothackbot --skill jtagprobe -a codex`. Or copy the skill folder (skills/jtagprobe in BrownFineSecurity/iothackbot) into .agents/skills/jtagprobe in your project. Codex loads it when a task matches its description.

Can I use Jtagprobe in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill jtagprobe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jtagprobe, .gemini/skills/jtagprobe, .github/skills/jtagprobe and .opencode/skills/jtagprobe in your project.

What does Jtagprobe need to run?

SKILL.md names no scripts, command-line tools or credentials: Jtagprobe is instructions for the agent only.

Does Jtagprobe access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Jtagprobe safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Jtagprobe use?

Jtagprobe is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Jtagprobe use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Jtagprobe?

Skills that share tags, products or a category with Jtagprobe: Embedded Iot Mentor (alirezarezvani/claude-skills, 28k stars), Embedded Debug (FastLED/FastLED, 7.5k stars), Debug (asgeirtj/system_prompts_leaks, 69k stars) and Openclaw Debugging (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Jtagprobe?

BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.

Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.