ONVIF device security scanner for testing authentication and brute-forcing credentials.

MITAuto-check passedSecurity

Install Onvifscan

skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill onvifscan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BrownFineSecurity/iothackbot onvifscan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/onvifscan .claude/skills/onvifscan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
onvifscan
GitHub stars
858
Used in
1 other repo
Token cost
~608 tokens
SKILL.md length
244 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

ONVIF device security scanner for testing authentication and brute-forcing credentials.

  • Works in 3 steps: Determine scan type → Get target information → Execute the scan
  • You need to assess security of IP cameras
  • SKILL.md covers Tool Overview, Instructions, Subcommands and Examples, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Onvifscan is an agent skill from BrownFineSecurity/iothackbot. ONVIF device security scanner for testing authentication and brute-forcing credentials. Use when you need to assess security of IP cameras or ONVIF-enabled devices.

Its SKILL.md is about 610 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.

When your agent uses it

  • You need to assess security of IP cameras
  • ONVIF-enabled devices

Example prompts

  • “/onvifscan”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Determine scan type
  2. Get target information
  3. Execute the scan

What it can do on your machine

Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Onvifscan loads about 608 tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 244 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~608

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BrownFineSecurity/iothackbot at commit d443c40, republished under its MIT licence (© BrownFineSecurity). 244 words, ~608 tokens.

Download SKILL.mdSave it as .claude/skills/onvifscan/SKILL.md (or your agent's skills folder).
name
onvifscan
description
ONVIF device security scanner for testing authentication and brute-forcing credentials. Use when you need to assess security of IP cameras or ONVIF-enabled devices.

Onvifscan - ONVIF Security Scanner

You are helping the user scan ONVIF devices for security issues including authentication bypasses and weak credentials using the onvifscan tool.

Tool Overview

Onvifscan is an ONVIF device security scanner that can:

  • Test for unauthenticated access to ONVIF endpoints
  • Perform credential brute-forcing attacks

Instructions

When the user asks to scan ONVIF devices, test IP cameras, or assess IoT device security:

  1. Determine scan type:

    • auth: Authentication and access control testing (recommended to start)
    • brute: Credential brute-forcing on password-protected endpoints
  2. Get target information:

    • Ask for the device URL/IP
    • Determine which scan type to run
    • Check if they have custom wordlists
  3. Execute the scan:

    • Use the onvifscan command from the iothackbot bin directory
    • Format: onvifscan <subcommand> <url> [options]

Subcommands

Auth Scan

Tests ONVIF endpoints for authentication requirements:

bash
onvifscan auth http://192.168.1.100

Options:

  • -v, --verbose: Show full XML responses
  • -a, --all: Test ALL endpoints including potentially destructive ones
  • --format text|json|quiet: Output format
Brute Force

Attempts credential brute-forcing on protected endpoints:

bash
onvifscan brute http://192.168.1.100

Options:

  • --usernames <file>: Custom usernames wordlist (default: built-in onvif-usernames.txt)
  • --passwords <file>: Custom passwords wordlist (default: built-in onvif-passwords.txt)
  • --format text|json|quiet: Output format

Examples

Quick auth check on a device:

bash
onvifscan auth 192.168.1.100

Auth check with verbose output:

bash
onvifscan auth http://192.168.1.100:8080 -v

Brute force with custom wordlists:

bash
onvifscan brute 192.168.1.100 --usernames custom-users.txt --passwords custom-pass.txt

Important Notes

  • URLs can omit http:// - it will be added automatically
  • Auth scan is non-destructive and safe to run
  • Use -a flag with caution - may test destructive endpoints
  • Brute force is rate-limited to prevent device overload (max 20 attempts by default)
  • Built-in wordlists located in wordlists/ directory

© BrownFineSecurity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/onvifscan of BrownFineSecurity/iothackbot.

Open the folder on GitHubat commit d443c40

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in BrownFineSecurity/iothackbot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Onvifscan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Onvifscan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Onvifscan this skillBrownFineSecurity/iothackbot8581 repos~608Automated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated 6 days ago
    SecurityAuto-check passed

More from BrownFineSecurity/iothackbot

All 8 skills in this repo
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 2 repos~3.8k tokens
    Auto-check: notes
  • Chipsec

    BrownFineSecurity/iothackbot

    Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

    858 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Ffind

    BrownFineSecurity/iothackbot

    Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

    858 GitHub starsUsed in 1 repo~730 tokens
    Auto-check: notes
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    858 GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • Wsdiscovery

    BrownFineSecurity/iothackbot

    WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

    858 GitHub starsUsed in 1 repo~628 tokens
    Auto-check passed
  • Jtagprobe

    BrownFineSecurity/iothackbot

    Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.

    858 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Questions about Onvifscan

What does Onvifscan do?

ONVIF device security scanner for testing authentication and brute-forcing credentials. Onvifscan is an agent skill from BrownFineSecurity/iothackbot. ONVIF device security scanner for testing authentication and brute-forcing credentials.

When should I use Onvifscan?

Onvifscan fits situations like: you need to assess security of IP cameras; ONVIF-enabled devices.

How do I install Onvifscan in Claude Code?

Run `npx skills add BrownFineSecurity/iothackbot --skill onvifscan -a claude-code`. Or copy the skill folder (skills/onvifscan in BrownFineSecurity/iothackbot) into .claude/skills/onvifscan in your project. Claude Code loads it when a task matches its description.

How do I install Onvifscan in Codex?

Run `npx skills add BrownFineSecurity/iothackbot --skill onvifscan -a codex`. Or copy the skill folder (skills/onvifscan in BrownFineSecurity/iothackbot) into .agents/skills/onvifscan in your project. Codex loads it when a task matches its description.

Can I use Onvifscan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill onvifscan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/onvifscan, .gemini/skills/onvifscan, .github/skills/onvifscan and .opencode/skills/onvifscan in your project.

What does Onvifscan need to run?

SKILL.md names no scripts, command-line tools or credentials: Onvifscan is instructions for the agent only.

Does Onvifscan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Onvifscan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Onvifscan use?

Onvifscan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Onvifscan use?

About 608 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Onvifscan?

Skills that share tags, products or a category with Onvifscan: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Onvifscan?

BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.

Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.