WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

MITAuto-check passed

Install Wsdiscovery

skills CLI
$ npx skills add BrownFineSecurity/iothackbot --skill wsdiscovery -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BrownFineSecurity/iothackbot wsdiscovery --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BrownFineSecurity/iothackbot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wsdiscovery .claude/skills/wsdiscovery && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wsdiscovery
GitHub stars
858
Used in
1 other repo
Token cost
~628 tokens
SKILL.md length
265 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

  • Works in 3 steps: Understand the target → Execute the scan → Output formats
  • You need to discover ONVIF devices
  • SKILL.md covers Tool Overview, Instructions, What It Discovers and Examples, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Wsdiscovery is an agent skill from BrownFineSecurity/iothackbot. WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network. Use when you need to discover ONVIF devices, cameras, or WS-Discovery enabled equipment on a network.

Its SKILL.md is about 630 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting. The licence is MIT.

When your agent uses it

  • You need to discover ONVIF devices
  • WS-Discovery enabled equipment on a network

Example prompts

  • “/wsdiscovery”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Understand the target
  2. Execute the scan
  3. Output formats

What it can do on your machine

Read from SKILL.md and the folder at commit d443c40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wsdiscovery loads about 628 tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 265 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~628

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BrownFineSecurity/iothackbot at commit d443c40, republished under its MIT licence (© BrownFineSecurity). 265 words, ~628 tokens.

Download SKILL.mdSave it as .claude/skills/wsdiscovery/SKILL.md (or your agent's skills folder).
name
wsdiscovery
description
WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network. Use when you need to discover ONVIF devices, cameras, or WS-Discovery enabled equipment on a network.

Wsdiscovery - WS-Discovery Protocol Scanner

You are helping the user discover and enumerate devices using the WS-Discovery protocol (commonly used by ONVIF cameras and IoT devices) using the wsdiscovery tool.

Tool Overview

Wsdiscovery implements the WS-Discovery protocol to discover network devices that support this standard. It's particularly useful for finding ONVIF cameras, network video recorders (NVRs), and other IoT devices that advertise themselves via WS-Discovery.

Instructions

When the user asks to discover ONVIF devices, find network cameras, or scan for WS-Discovery devices:

  1. Understand the target:

    • Ask for the target hostname or IP address
    • Determine if they want verbose output (full XML responses)
    • Decide on output format
  2. Execute the scan:

    • Use the wsdiscovery command from the iothackbot bin directory
    • Basic usage: wsdiscovery <hostname_or_ip>
    • For verbose output: wsdiscovery <hostname_or_ip> -v
    • For JSON output: wsdiscovery <hostname_or_ip> --format json
  3. Output formats:

    • --format text (default): Human-readable colored output with device details
    • --format json: Machine-readable JSON
    • --format quiet: Minimal output

What It Discovers

The tool extracts and displays:

  • IP addresses and ports
  • Endpoint references (device UUIDs)
  • Device types
  • Manufacturer information
  • Device names and models
  • Hardware versions
  • Serial numbers
  • Firmware versions
  • Location information
  • Service endpoints (XAddrs) - URLs for device management
  • Metadata versions

Examples

Discover devices on a specific host:

bash
wsdiscovery 192.168.1.100

Discover with full XML responses:

bash
wsdiscovery 192.168.1.100 -v

Output device information as JSON:

bash
wsdiscovery 192.168.1.100 --format json

Scan network broadcast address to find all devices:

bash
wsdiscovery 239.255.255.250

Important Notes

  • WS-Discovery uses multicast/broadcast discovery
  • Devices must support the WS-Discovery protocol to be found
  • Common with ONVIF cameras, printers, and network media devices
  • Service endpoints (XAddrs) can be used with onvifscan for further testing
  • The tool parses ONVIF-specific scope information when available

© BrownFineSecurity, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/wsdiscovery of BrownFineSecurity/iothackbot.

Open the folder on GitHubat commit d443c40

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in BrownFineSecurity/iothackbot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Wsdiscovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wsdiscovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wsdiscovery this skillBrownFineSecurity/iothackbot8581 repos~628Automated safety check: PassMIT
Discover Pluginsruvnet/ruflo74k—~2kAutomated safety check: NotesMIT
Aas Discoversickn33/agentic-awesome-skills47k1 repos~523Automated safety check: PassMIT
Creating Replay Vision ScannersPostHog/posthog40k—~3.6kAutomated safety check: PassCustom licence
Designing Replay Vision ScannersPostHog/posthog40k—~3.6kAutomated safety check: PassCustom licence
Discoverbrycewang-stanford/Auto-Empirical-Research-Skills4.5k—~2.2kAutomated safety check: PassCustom licence

Similar skills

  • Discover Plugins

    ruvnet/ruflo

    Discover and recommend ruflo plugins based on your workflow, installed MCP tools, and current task

    74k GitHub stars~2k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Aas Discover

    sickn33/agentic-awesome-skills

    Discover AAS skills for an explicit task and compare their complete instructions without installing them.

    47k GitHub starsUsed in 1 repo~523 tokens
    Auto-check passed
  • Official

    Guides agents through creating and safely sizing a Replay Vision scanner: choosing the scanner type (monitor/classifier/scorer/summarizer), shaping the RecordingsQuery that selects sessions, and —…

    40k GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Official

    Designs a Replay Vision scanner that produces trustworthy observations: one visible question per scanner, a type chosen from the answer shape, a query that selects only sessions able to answer it, a…

    40k GitHub stars~3.6k tokensUpdated today
    Business, Finance & HRAuto-check passed
  • Discover

    brycewang-stanford/Auto-Empirical-Research-Skills

    Discovery phase combining research interviews, literature search, data discovery, and ideation.

    4.5k GitHub stars~2.2k tokensUpdated 3 days ago
    Agent WorkflowsAuto-check passed
  • Frost Sequence Camera Orbit

    heygen-com/hyperframes

    A ready-made HyperFrames video block where an orbiting camera follows an ice logo that shatters, reforms into two text lines and fades, at 1920×1080.

    59k GitHub starsUsed in 1 repo~9.6k tokens
    Media & CreativeAuto-check passed

More from BrownFineSecurity/iothackbot

All 8 skills in this repo
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 2 repos~3.8k tokens
    Auto-check: notes
  • Chipsec

    BrownFineSecurity/iothackbot

    Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

    858 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Ffind

    BrownFineSecurity/iothackbot

    Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems.

    858 GitHub starsUsed in 1 repo~730 tokens
    Auto-check: notes
  • Iotnet

    BrownFineSecurity/iothackbot

    IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.

    858 GitHub starsUsed in 1 repo~1k tokens
    Auto-check: notes
  • Onvifscan

    BrownFineSecurity/iothackbot

    ONVIF device security scanner for testing authentication and brute-forcing credentials.

    858 GitHub starsUsed in 1 repo~608 tokens
    Auto-check passed
  • Jtagprobe

    BrownFineSecurity/iothackbot

    Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link.

    858 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Questions about Wsdiscovery

What does Wsdiscovery do?

WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network. Wsdiscovery is an agent skill from BrownFineSecurity/iothackbot. WS-Discovery protocol scanner for discovering and enumerating ONVIF cameras and IoT devices on the network.

When should I use Wsdiscovery?

Wsdiscovery fits situations like: you need to discover ONVIF devices; WS-Discovery enabled equipment on a network.

How do I install Wsdiscovery in Claude Code?

Run `npx skills add BrownFineSecurity/iothackbot --skill wsdiscovery -a claude-code`. Or copy the skill folder (skills/wsdiscovery in BrownFineSecurity/iothackbot) into .claude/skills/wsdiscovery in your project. Claude Code loads it when a task matches its description.

How do I install Wsdiscovery in Codex?

Run `npx skills add BrownFineSecurity/iothackbot --skill wsdiscovery -a codex`. Or copy the skill folder (skills/wsdiscovery in BrownFineSecurity/iothackbot) into .agents/skills/wsdiscovery in your project. Codex loads it when a task matches its description.

Can I use Wsdiscovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BrownFineSecurity/iothackbot --skill wsdiscovery -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wsdiscovery, .gemini/skills/wsdiscovery, .github/skills/wsdiscovery and .opencode/skills/wsdiscovery in your project.

What does Wsdiscovery need to run?

SKILL.md names no scripts, command-line tools or credentials: Wsdiscovery is instructions for the agent only.

Does Wsdiscovery access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wsdiscovery safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wsdiscovery use?

Wsdiscovery is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wsdiscovery use?

About 628 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Wsdiscovery?

Skills that share tags, products or a category with Wsdiscovery: Discover Plugins (ruvnet/ruflo, 74k stars), Aas Discover (sickn33/agentic-awesome-skills, 47k stars), Creating Replay Vision Scanners (PostHog/posthog, 40k stars) and Designing Replay Vision Scanners (PostHog/posthog, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wsdiscovery?

BrownFineSecurity (a GitHub organization) maintains it in BrownFineSecurity/iothackbot, which has 858 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 1, 2026.

Source: BrownFineSecurity/iothackbot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.