Install the "nmap" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/nmap into .claude/skills/nmap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill nmap -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "nmap" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/nmap into .agents/skills/nmap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill nmap -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "nmap" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/nmap into .cursor/skills/nmap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill nmap -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "nmap" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/nmap into .gemini/skills/nmap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill nmap -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "nmap" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/nmap into .github/skills/nmap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill nmap -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "nmap" agent skill from https://github.com/BrownFineSecurity/iothackbot/tree/master/skills/nmap into .opencode/skills/nmap/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nmap", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
nmap
GitHub stars
858
Used in
1 other repo
Token cost
~3.8k tokens
SKILL.md length
1,371 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT
At a glance
Professional network reconnaissance and port scanning using nmap.
Works in 7 steps: Fast Port Discovery (Root SYN Scan) → Targeted Service Detection → Always Save Output → …
You need to enumerate network services
SKILL.md covers Output Directory, Default Scanning Strategy, Implementation Workflow and Scan Types, plus 4 more sections
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Nmap is an agent skill from BrownFineSecurity/iothackbot. Professional network reconnaissance and port scanning using nmap. Supports various scan types (quick, full, UDP, stealth), service detection, vulnerability scanning, and NSE scripts. Use when you need to enumerate network services, detect versions, or perform network reconnaissance.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Penetration testing and Vulnerability scanning. It works with Nmap. The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.
When your agent uses it
You need to enumerate network services
Detect versions
Perform network reconnaissance
Example prompts
“/nmap”
Workflow steps
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Nmap loads about 3.8k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 1,371 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~72
When it runs· the whole SKILL.md, loaded when a task matches
~3.8k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: notes
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/nmap/SKILL.md (or your agent's skills folder).
name
nmap
description
Professional network reconnaissance and port scanning using nmap. Supports various scan types (quick, full, UDP, stealth), service detection, vulnerability scanning, and NSE scripts. Use when you need to enumerate network services, detect versions, or perform network reconnaissance.
Nmap Scan - Professional Network Reconnaissance
You are helping the user perform professional network reconnaissance and port scanning using nmap. This skill provides guidance for various scan types, output formats, and result analysis.
Output Directory
Directory Structure
bash
nmap-output/
├── nmap-portscan.nmap # Initial fast port discovery
├── nmap-portscan.xml
├── nmap-portscan.gnmap
├── nmap-services.nmap # Detailed service detection on open ports
├── nmap-services.xml
└── nmap-services.gnmap
IMPORTANT: Always save nmap output to an organized directory structure. By default, use ./nmap-output/ or specify a custom directory.
Default Scanning Strategy
IMPORTANT: Unless the user explicitly requests a different scan type, ALWAYS use this two-phase approach:
if [ -n "$OPEN_PORTS" ]; then
nmap -p "$OPEN_PORTS" -sV -sC <target> -oA "$OUTPUT_DIR/nmap-services"
else
echo "No open ports found, skipping service detection."
fi
Report results location
bash
echo "Scan complete. Results saved to: $OUTPUT_DIR"
Scan Types
Quick Scan (Top 1000 Ports)
Use for initial reconnaissance, when time is limited, or only when the user explicitly requests a quick/fast scan instead of the default two-phase strategy:
bash
nmap -sV -sC <target> -oA <output-prefix>
-sV: Service version detection
-sC: Run default NSE scripts
-oA: Output in all formats (normal, XML, grepable)
Scans top 1000 most common ports
Typical duration: 1-3 minutes
Limitation: May miss services on non-standard ports
Comprehensive Scan (All Ports)
Use for thorough assessment when all ports must be checked:
bash
nmap -sV -sC -p- <target> -oA <output-prefix>
-p-: Scan all 65535 ports
Significantly longer duration (5-30+ minutes depending on target)
Use only when comprehensive coverage is required
Stealth SYN Scan
Use when trying to avoid detection (requires root/sudo):
--script vuln: Run NSE vulnerability detection scripts
Checks for common CVEs and misconfigurations
Can be noisy and trigger alerts
OS Detection
Use to identify operating system:
bash
sudo nmap -O <target> -oA <output-prefix>
-O: Enable OS detection
Requires root privileges
Uses TCP/IP stack fingerprinting
Scan Workflow
Default Workflow (Two-Phase Strategy)
Run Phase 1 (port discovery) and Phase 2 (service detection) per the Default Scanning Strategy and Implementation Workflow sections above. Then analyze:
Phase 3: Analysis
Review the service detection results to determine:
What services are running?
What versions are detected?
Are there any interesting services (web, SSH, database, IoT protocols)?
Do NSE scripts reveal any issues?
Additional Targeted Scans (Optional)
Based on service detection results, run specialized scans:
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in BrownFineSecurity/iothackbot, which our catalogue first saw on October 7, 2026.
Nmap next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Professional network reconnaissance and port scanning using nmap. Nmap is an agent skill from BrownFineSecurity/iothackbot. Professional network reconnaissance and port scanning using nmap.
When should I use Nmap?
Nmap fits situations like: you need to enumerate network services; detect versions; perform network reconnaissance.
How do I install Nmap in Claude Code?
Run `npx skills add BrownFineSecurity/iothackbot --skill nmap -a claude-code`. Or copy the skill folder (skills/nmap in BrownFineSecurity/iothackbot) into .claude/skills/nmap in your project. Claude Code loads it when a task matches its description.
How do I install Nmap in Codex?
Run `npx skills add BrownFineSecurity/iothackbot --skill nmap -a codex`. Or copy the skill folder (skills/nmap in BrownFineSecurity/iothackbot) into .agents/skills/nmap in your project. Codex loads it when a task matches its description.
Can I use Nmap in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill nmap -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nmap, .gemini/skills/nmap, .github/skills/nmap and .opencode/skills/nmap in your project.
What does Nmap need to run?
SKILL.md names no scripts, command-line tools or credentials: Nmap is instructions for the agent only.
Does Nmap access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Nmap safe to install?
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
What licence does Nmap use?
Nmap is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Nmap use?
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Nmap?
Skills that share tags, products or a category with Nmap: Scanning Network With Nmap Advanced (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Network Scanner (ptn1411/skill, 219 stars), Nmap Service Detection (automateyournetwork/netclaw, 674 stars) and Code Audit (3stoneBrother/code-audit, 893 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Nmap?
BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.
Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.