Agent skill

Implementing Rapid7 Insightvm For Scanning

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unauthenticated…

Apache-2.0Auto-check: notesSecurity

Install Implementing Rapid7 Insightvm For Scanning

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-rapid7-insightvm-for-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-rapid7-insightvm-for-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-rapid7-insightvm-for-scanning .claude/skills/implementing-rapid7-insightvm-for-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-rapid7-insightvm-for-scanning
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
668 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unauthenticated…

  • Works in 8 steps: Install Security Console → Deploy Distributed Scan Engines → Configure Asset Discovery Sites → …
  • Standing up InsightVM infrastructure
  • SKILL.md covers Overview, When to Use, Prerequisites and Core Concepts, plus 4 more sections
  • Runs Python scripts from its folder; calls docker and ssh; needs SHARED_SECRET

What it does

Implementing Rapid7 Insightvm For Scanning is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unauthenticated vulnerability scanning across enterprise environments. Use when standing up InsightVM infrastructure, configuring credentialed vulnerability scans, or integrating continuous asset assessment via the Insight Agent.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Vulnerability scanning. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Standing up InsightVM infrastructure
  • Configuring credentialed vulnerability scans
  • Integrating continuous asset assessment via the Insight Agent

Example prompts

  • “/implementing-rapid7-insightvm-for-scanning”

Requirements

  • Python 3
  • Docker
  • A credential in SHARED_SECRET

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Install Security Console
  2. Deploy Distributed Scan Engines
  3. Configure Asset Discovery Sites
  4. Configure Authenticated Scanning
  5. Configure Scan Templates
  6. Set Up Insight Agent Deployment
  7. Configure Remediation Workflows
  8. API Integration for Automation

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • docker
    • ssh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SHARED_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Rapid7 Insightvm For Scanning loads about 3.1k tokens when it runs, and up to ~6.1k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 668 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:189
    sudo User:        root
  • NoteRuns commands with sudoSKILL.md:190
    sudo Password:    <sudo-password>

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 668 words, ~3,075 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-rapid7-insightvm-for-scanning/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-rapid7-insightvm-for-scanning
description
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unauthenticated vulnerability scanning across enterprise environments. Use when standing up InsightVM infrastructure, configuring credentialed vulnerability scans, or integrating continuous asset assessment via the Insight Agent.
domain
cybersecurity
subdomain
vulnerability-management
tags
rapid7, insightvm, vulnerability-scanning, nexpose, scan-engine, asset-discovery, authenticated-scanning
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-02, ID.IM-02, ID.RA-06
mitre_attack
T1190, T1203, T1068

Implementing Rapid7 InsightVM for Scanning

Overview

Rapid7 InsightVM (formerly Nexpose) is an enterprise vulnerability management platform that combines on-premises scanning via Security Console and Scan Engines with cloud-based analytics through the Insight Platform. InsightVM leverages Rapid7's vulnerability research library, Metasploit exploit knowledge, global attacker behavior data, internet-wide scanning telemetry, and real-time reporting to provide comprehensive vulnerability visibility. This skill covers deploying the Security Console, configuring Scan Engines, setting up scan templates, credentialed scanning, and integrating with the Insight Agent for continuous assessment.

When to Use

  • When deploying or configuring implementing rapid7 insightvm for scanning capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Server meeting minimum requirements: 16 GB RAM, 4 CPU cores, 500 GB disk (Security Console)
  • Scan Engine: 8 GB RAM, 4 CPU cores, 100 GB disk
  • Network access to target subnets (ports vary by scan type)
  • Administrative credentials for authenticated scanning (SSH, WMI, SNMP)
  • Rapid7 InsightVM license and Insight Platform account
  • PostgreSQL database (bundled with Security Console)

Core Concepts

InsightVM Architecture Components
Security Console

The central management server that:

  • Hosts the web-based management interface (default port 3780)
  • Stores scan results in an embedded PostgreSQL database
  • Manages Scan Engine deployments and scan schedules
  • Generates reports and dashboards
  • Connects to Rapid7 Insight Platform for cloud analytics

Note: Security Console is NOT supported in containerized environments.

Scan Engines

Distributed scanning components that:

  • Perform active network scanning against target assets
  • Can be deployed across network segments for segmented environments
  • Available as container images on Docker Hub for flexible deployment
  • Report results back to the Security Console
Insight Agent

Lightweight endpoint agent providing:

  • Continuous vulnerability assessment without network scans
  • Assessment of remote/roaming endpoints
  • Complement to engine-based scanning for comprehensive coverage
  • Real-time asset inventory updates
Scan Template Types
TemplateUse CaseDepth
Discovery ScanAsset inventory, host enumerationLow
Full Audit without Web SpiderStandard vulnerability assessmentMedium
Full Audit Enhanced LoggingDeep assessment with verbose loggingHigh
HIPAA ComplianceHealthcare regulatory complianceHigh
PCI ASV AuditPCI DSS external scanning requirementHigh
CIS Policy ComplianceConfiguration benchmarkingMedium
Web SpiderWeb application discovery and assessmentMedium

Workflow

Step 1: Install Security Console
bash
# Download InsightVM installer (Linux)
chmod +x Rapid7Setup-Linux64.bin
./Rapid7Setup-Linux64.bin -c

# Verify service is running
systemctl status nexposeconsole.service

# Access web interface
# https://<console-ip>:3780

Initial configuration:

  1. Navigate to https://localhost:3780
  2. Complete the setup wizard with license key
  3. Configure database settings (embedded PostgreSQL recommended)
  4. Set administrator credentials
  5. Activate Insight Platform connection for cloud analytics
Show full SKILL.md (264 more words)Show less
Step 2: Deploy Distributed Scan Engines
bash
# Install Scan Engine on remote server
./Rapid7Setup-Linux64.bin -c

# During installation, select "Scan Engine only"
# Pair with Security Console using shared secret

# Docker-based Scan Engine deployment
docker pull rapid7/insightvm-scan-engine
docker run -d \
  --name scan-engine \
  -p 40814:40814 \
  -e CONSOLE_HOST=<console-ip> \
  -e CONSOLE_PORT=3780 \
  -e ENGINE_NAME=DMZ-Scanner \
  -e SHARED_SECRET=<pairing-secret> \
  rapid7/insightvm-scan-engine

Pair engines in Security Console:

  1. Administration > Scan Engines > New Scan Engine
  2. Enter engine hostname/IP and port (default 40814)
  3. Use shared secret for authentication
  4. Verify connectivity status shows "Active"
Step 3: Configure Asset Discovery Sites
Site Configuration:
  Name:           Production-Network
  Scan Engine:    Primary-Engine-01
  Scan Template:  Full Audit without Web Spider

  Included Assets:
    - 10.0.0.0/8     (Internal network)
    - 172.16.0.0/12   (DMZ network)

  Excluded Assets:
    - 10.0.0.1        (Core router - fragile)
    - 10.0.100.0/24   (ICS/SCADA segment)

  Schedule:
    Frequency:    Weekly
    Day:          Sunday
    Time:         02:00 AM
    Max Duration: 8 hours
Step 4: Configure Authenticated Scanning
Windows Credentials (WMI)
Credential Type:    Microsoft Windows/Samba (SMB/CIFS)
Domain:             CORP.EXAMPLE.COM
Username:           svc_insightvm_scan
Password:           <service-account-password>
Authentication:     NTLM

Privilege Elevation:
  Type:   None (use domain admin or local admin)
Linux/Unix Credentials (SSH)
Credential Type:    Secure Shell (SSH)
Username:           insightvm_scan
Authentication:     SSH Key (preferred) or Password
SSH Private Key:    /opt/rapid7/.ssh/scan_key
Port:               22

Privilege Elevation:
  Type:             sudo
  sudo User:        root
  sudo Password:    <sudo-password>
Database Credentials
Credential Type:    Microsoft SQL Server
Instance:           MSSQLSERVER
Domain:             CORP
Username:           insightvm_db_scan
Authentication:     Windows Authentication

Credential Type:    Oracle
Port:               1521
SID:                ORCL
Username:           insightvm_scan
Step 5: Configure Scan Templates

Custom scan template for balanced scanning:

Template Name:      Enterprise-Standard-Scan

Service Discovery:
  TCP Ports:        Well-known (1-1024) + common services
  UDP Ports:        DNS(53), SNMP(161), NTP(123), TFTP(69)
  Method:           SYN scan (stealth)

Vulnerability Checks:
  Safe checks only: Enabled
  Skip potential:   Disabled
  Web spidering:    Disabled (separate template)
  Policy checks:    Enabled (CIS benchmarks)

Performance:
  Max parallel assets:     10
  Max requests per second: 100
  Timeout per asset:       30 minutes
  Retries:                 2
Step 6: Set Up Insight Agent Deployment
powershell
# Windows Agent Installation (via GPO or SCCM)
msiexec /i agentInstaller-x86_64.msi /quiet /norestart `
  CUSTOMTOKEN=<platform-token> `
  CUSTOMCONFIG=<agent-config>

# Linux Agent Installation
chmod +x agent_installer.sh
./agent_installer.sh install_start \
  --token <platform-token>

# Verify agent connectivity
# Check InsightVM console: Assets > Agent Management
Step 7: Configure Remediation Workflows
Remediation Project:
  Name:             Q1-2025-Critical-Remediation

  Scope:
    Severity:       Critical + High
    CVSS Score:     >= 7.0
    Assets:         Production-Network site

  Assignment:
    Team:           Infrastructure-Ops
    Due Date:       2025-03-31

  Tracking:
    Auto-verify:    Enabled (re-scan on next scheduled scan)
    Notification:   Email on overdue items
    Escalation:     Manager notification at 75% SLA
Step 8: API Integration for Automation
python
import requests
import json

class InsightVMClient:
    """Rapid7 InsightVM API v3 client for automation."""

    def __init__(self, console_url, api_key):
        self.base_url = f"{console_url}/api/3"
        self.session = requests.Session()
        self.session.headers.update({
            "Content-Type": "application/json",
            "Authorization": f"Bearer {api_key}"
        })
        self.session.verify = not os.environ.get("SKIP_TLS_VERIFY", "").lower() == "true"  # Set SKIP_TLS_VERIFY=true for self-signed certs in lab environments

    def get_sites(self):
        """List all configured scan sites."""
        response = self.session.get(f"{self.base_url}/sites")
        response.raise_for_status()
        return response.json().get("resources", [])

    def start_scan(self, site_id, engine_id=None, template_id=None):
        """Trigger an ad-hoc scan for a site."""
        payload = {}
        if engine_id:
            payload["engineId"] = engine_id
        if template_id:
            payload["templateId"] = template_id

        response = self.session.post(
            f"{self.base_url}/sites/{site_id}/scans",
            json=payload
        )
        response.raise_for_status()
        return response.json()

    def get_asset_vulnerabilities(self, asset_id):
        """Retrieve vulnerabilities for a specific asset."""
        response = self.session.get(
            f"{self.base_url}/assets/{asset_id}/vulnerabilities"
        )
        response.raise_for_status()
        return response.json().get("resources", [])

    def get_scan_status(self, scan_id):
        """Check the status of a running scan."""
        response = self.session.get(f"{self.base_url}/scans/{scan_id}")
        response.raise_for_status()
        return response.json()

    def create_remediation_project(self, name, description, assets, vulns):
        """Create a remediation tracking project."""
        payload = {
            "name": name,
            "description": description,
            "assets": {"includedTargets": {"addresses": assets}},
            "vulnerabilities": {"includedVulnerabilities": vulns}
        }
        response = self.session.post(
            f"{self.base_url}/remediations",
            json=payload
        )
        response.raise_for_status()
        return response.json()


# Usage
client = InsightVMClient("https://insightvm-console:3780", "api-key-here")
sites = client.get_sites()
for site in sites:
    print(f"Site: {site['name']} - Assets: {site.get('assets', 0)}")

Best Practices

  1. Deploy Scan Engines close to target networks to minimize scan traffic traversing firewalls
  2. Use Insight Agents for roaming laptops and remote workers that are not always reachable by network scans
  3. Combine agent-based and engine-based scanning for the most accurate vulnerability view
  4. Configure scan blackout windows during business-critical hours to avoid operational impact
  5. Use credential testing before full scans to validate authentication works
  6. Enable safe checks to prevent accidental denial of service on production systems
  7. Separate scan sites by network segment, business unit, or compliance scope
  8. Leverage tag-based asset groups for dynamic reporting and remediation tracking

Common Pitfalls

  • Running full scans during business hours causing network congestion or service degradation
  • Using unauthenticated scans only, missing 60-80% of local vulnerabilities
  • Not excluding fragile devices (printers, ICS/SCADA, medical devices) from aggressive scan templates
  • Failing to distribute Scan Engines across network segments, causing firewall bottlenecks
  • Ignoring scan engine resource utilization leading to incomplete scans
  • Not configuring scan duration limits, allowing runaway scans to consume resources indefinitely
  • performing-agentless-vulnerability-scanning
  • building-vulnerability-data-pipeline-with-api
  • implementing-wazuh-for-vulnerability-detection
  • performing-remediation-validation-scanning

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-rapid7-insightvm-for-scanning of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Rapid7 Insightvm For Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Rapid7 Insightvm For Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Rapid7 Insightvm For Scanning this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: NotesApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Implementing Rapid7 Insightvm For Scanning

What does Implementing Rapid7 Insightvm For Scanning do?

Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unauthenticated…. Implementing Rapid7 Insightvm For Scanning is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploy and configure Rapid7 InsightVM Security Console and Scan Engines, including scan templates, credentialed scanning, and Insight Agent integration, for authenticated and unauthenticated vulnerability scanning across enterprise environments.

When should I use Implementing Rapid7 Insightvm For Scanning?

Implementing Rapid7 Insightvm For Scanning fits situations like: standing up InsightVM infrastructure; configuring credentialed vulnerability scans; integrating continuous asset assessment via the Insight Agent.

How do I install Implementing Rapid7 Insightvm For Scanning in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-rapid7-insightvm-for-scanning -a claude-code`. Or copy the skill folder (skills/implementing-rapid7-insightvm-for-scanning in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-rapid7-insightvm-for-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Rapid7 Insightvm For Scanning in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-rapid7-insightvm-for-scanning -a codex`. Or copy the skill folder (skills/implementing-rapid7-insightvm-for-scanning in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-rapid7-insightvm-for-scanning in your project. Codex loads it when a task matches its description.

Can I use Implementing Rapid7 Insightvm For Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-rapid7-insightvm-for-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-rapid7-insightvm-for-scanning, .gemini/skills/implementing-rapid7-insightvm-for-scanning, .github/skills/implementing-rapid7-insightvm-for-scanning and .opencode/skills/implementing-rapid7-insightvm-for-scanning in your project.

What does Implementing Rapid7 Insightvm For Scanning need to run?

Going by SKILL.md and its folder, Implementing Rapid7 Insightvm For Scanning needs Python for the scripts in its folder, the command-line tools its instructions call (docker and ssh) and credentials named SHARED_SECRET. Our summary lists: Python 3; Docker; A credential in SHARED_SECRET.

Does Implementing Rapid7 Insightvm For Scanning access the network?

SKILL.md contains no URLs. Its commands use docker and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Implementing Rapid7 Insightvm For Scanning safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Rapid7 Insightvm For Scanning use?

Implementing Rapid7 Insightvm For Scanning is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Rapid7 Insightvm For Scanning use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Rapid7 Insightvm For Scanning?

Skills that share tags, products or a category with Implementing Rapid7 Insightvm For Scanning: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Rapid7 Insightvm For Scanning?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.