Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
Agent skill
Performs ICS/OT asset discovery with Claroty xDome, combining passive monitoring and Claroty Edge active queries to inventory PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ics-asset-discovery-with-claroty --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-ics-asset-discovery-with-claroty .claude/skills/performing-ics-asset-discovery-with-claroty && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "performing-ics-asset-discovery-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ics-asset-discovery-with-claroty into .claude/skills/performing-ics-asset-discovery-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ics-asset-discovery-with-claroty", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ics-asset-discovery-with-clarotyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ics-asset-discovery-with-claroty --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/performing-ics-asset-discovery-with-claroty .agents/skills/performing-ics-asset-discovery-with-claroty && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "performing-ics-asset-discovery-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ics-asset-discovery-with-claroty into .agents/skills/performing-ics-asset-discovery-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ics-asset-discovery-with-claroty", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ics-asset-discovery-with-claroty --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/performing-ics-asset-discovery-with-claroty .cursor/skills/performing-ics-asset-discovery-with-claroty && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "performing-ics-asset-discovery-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ics-asset-discovery-with-claroty into .cursor/skills/performing-ics-asset-discovery-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ics-asset-discovery-with-claroty", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/performing-ics-asset-discovery-with-claroty--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ics-asset-discovery-with-claroty --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/performing-ics-asset-discovery-with-claroty .gemini/skills/performing-ics-asset-discovery-with-claroty && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "performing-ics-asset-discovery-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ics-asset-discovery-with-claroty into .gemini/skills/performing-ics-asset-discovery-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ics-asset-discovery-with-claroty", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ics-asset-discovery-with-clarotyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/performing-ics-asset-discovery-with-claroty .github/skills/performing-ics-asset-discovery-with-claroty && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "performing-ics-asset-discovery-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ics-asset-discovery-with-claroty into .github/skills/performing-ics-asset-discovery-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ics-asset-discovery-with-claroty", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-ics-asset-discovery-with-claroty --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/performing-ics-asset-discovery-with-claroty .opencode/skills/performing-ics-asset-discovery-with-claroty && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "performing-ics-asset-discovery-with-claroty" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/performing-ics-asset-discovery-with-claroty into .opencode/skills/performing-ics-asset-discovery-with-claroty/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-ics-asset-discovery-with-claroty", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
performing-ics-asset-discovery-with-clarotyPerforms ICS/OT asset discovery with Claroty xDome, combining passive monitoring and Claroty Edge active queries to inventory PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels.
Performing Ics Asset Discovery With Claroty is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs ICS/OT asset discovery with Claroty xDome, combining passive monitoring and Claroty Edge active queries to inventory PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels. Use when gaining visibility into an undocumented OT environment, preparing an IEC 62443 asset inventory, or onboarding Claroty xDome; not for IT-only discovery.
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).
It sits in Security. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
services.nvd.nist.govFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Performing Ics Asset Discovery With Claroty loads about 4.9k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 496 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 496 words, ~4,893 tokens.
.claude/skills/performing-ics-asset-discovery-with-claroty/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Do not use for IT-only asset discovery (use tools like Nessus or Qualys), for active scanning of sensitive PLC networks without vendor approval, or for environments where Claroty is not the deployed platform (see implementing-ot-network-traffic-analysis-with-nozomi).
Deploy Claroty sensors on SPAN ports to passively observe all OT network traffic without impacting operations.
#!/usr/bin/env python3
"""Claroty xDome Asset Discovery Configuration and Reporting Tool.
Automates the configuration of passive monitoring sensors and generates
asset inventory reports from Claroty xDome API.
"""
import json
import sys
import csv
from datetime import datetime
from typing import Optional
try:
import requests
except ImportError:
print("Install requests: pip install requests")
sys.exit(1)
class ClarotyAssetDiscovery:
"""Interface with Claroty xDome API for ICS asset discovery."""
def __init__(self, base_url: str, api_token: str, verify_ssl: bool = True):
self.base_url = base_url.rstrip("/")
self.session = requests.Session()
self.session.headers.update({
"Authorization": f"Bearer {api_token}",
"Content-Type": "application/json",
"Accept": "application/json",
})
self.session.verify = verify_ssl
def get_sites(self):
"""Retrieve all monitored sites."""
resp = self.session.get(f"{self.base_url}/api/v1/sites")
resp.raise_for_status()
return resp.json().get("sites", [])
def get_assets(self, site_id: Optional[str] = None, asset_type: Optional[str] = None):
"""Retrieve discovered assets with optional filtering.
asset_type: PLC, RTU, HMI, DCS, Engineering_Workstation,
Historian, Network_Device, IO_Module, Safety_Controller
"""
params = {}
if site_id:
params["site_id"] = site_id
if asset_type:
params["type"] = asset_type
resp = self.session.get(f"{self.base_url}/api/v1/assets", params=params)
resp.raise_for_status()
return resp.json().get("assets", [])
def get_asset_detail(self, asset_id: str):
"""Retrieve detailed asset information including firmware, modules, and CVEs."""
resp = self.session.get(f"{self.base_url}/api/v1/assets/{asset_id}")
resp.raise_for_status()
return resp.json()
def get_communication_map(self, site_id: str):
"""Retrieve communication relationships between assets."""
resp = self.session.get(
f"{self.base_url}/api/v1/sites/{site_id}/communications"
)
resp.raise_for_status()
return resp.json().get("communications", [])
def get_vulnerabilities(self, site_id: Optional[str] = None, severity: str = "critical"):
"""Retrieve vulnerabilities for discovered assets."""
params = {"min_severity": severity}
if site_id:
params["site_id"] = site_id
resp = self.session.get(f"{self.base_url}/api/v1/vulnerabilities", params=params)
resp.raise_for_status()
return resp.json().get("vulnerabilities", [])
def export_asset_inventory(self, output_file: str, site_id: Optional[str] = None):
"""Export full asset inventory to CSV for compliance reporting."""
assets = self.get_assets(site_id=site_id)
if not assets:
print("[!] No assets found")
return
fieldnames = [
"asset_id", "name", "type", "vendor", "model", "firmware_version",
"ip_address", "mac_address", "serial_number", "purdue_level",
"zone", "protocol", "first_seen", "last_seen", "risk_score",
"cve_count", "site_name",
]
with open(output_file, "w", newline="") as f:
writer = csv.DictWriter(f, fieldnames=fieldnames)
writer.writeheader()
for asset in assets:
writer.writerow({
"asset_id": asset.get("id", ""),
"name": asset.get("name", "Unknown"),
"type": asset.get("type", ""),
"vendor": asset.get("vendor", ""),
"model": asset.get("model", ""),
"firmware_version": asset.get("firmware_version", ""),
"ip_address": asset.get("ip_address", ""),
"mac_address": asset.get("mac_address", ""),
"serial_number": asset.get("serial_number", ""),
"purdue_level": asset.get("purdue_level", ""),
"zone": asset.get("zone", ""),
"protocol": ", ".join(asset.get("protocols", [])),
"first_seen": asset.get("first_seen", ""),
"last_seen": asset.get("last_seen", ""),
"risk_score": asset.get("risk_score", 0),
"cve_count": asset.get("cve_count", 0),
"site_name": asset.get("site_name", ""),
})
print(f"[+] Exported {len(assets)} assets to {output_file}")
def generate_purdue_level_report(self, site_id: str):
"""Generate asset distribution report by Purdue Model level."""
assets = self.get_assets(site_id=site_id)
levels = {0: [], 1: [], 2: [], 3: [], 3.5: [], 4: [], 5: []}
for asset in assets:
level = asset.get("purdue_level", -1)
if level in levels:
levels[level].append(asset)
print(f"\n{'='*65}")
print("PURDUE MODEL ASSET DISTRIBUTION REPORT")
print(f"{'='*65}")
print(f"Site: {site_id}")
print(f"Total Assets Discovered: {len(assets)}")
print(f"Report Generated: {datetime.now().isoformat()}")
print(f"{'-'*65}")
level_names = {
0: "Level 0 - Physical Process (Sensors/Actuators)",
1: "Level 1 - Basic Control (PLCs/RTUs)",
2: "Level 2 - Supervisory Control (HMI/SCADA)",
3: "Level 3 - Site Operations (Historian/MES)",
3.5: "Level 3.5 - IT/OT DMZ",
4: "Level 4 - Enterprise IT",
5: "Level 5 - Enterprise Network/Internet",
}
for level, name in level_names.items():
device_list = levels.get(level, [])
print(f"\n {name}")
print(f" Count: {len(device_list)}")
if device_list:
vendors = set(a.get("vendor", "Unknown") for a in device_list)
types = set(a.get("type", "Unknown") for a in device_list)
print(f" Vendors: {', '.join(vendors)}")
print(f" Types: {', '.join(types)}")
high_risk = [a for a in device_list if a.get("risk_score", 0) >= 7]
if high_risk:
print(f" High-Risk Assets: {len(high_risk)}")
for a in high_risk[:5]:
print(f" - {a['name']} (Risk: {a.get('risk_score')})")
if __name__ == "__main__":
discovery = ClarotyAssetDiscovery(
base_url="https://your-claroty-instance.claroty.cloud",
api_token="your-api-token-here",
verify_ssl=True,
)
print("[*] Fetching sites...")
sites = discovery.get_sites()
for site in sites:
print(f" Site: {site['name']} (ID: {site['id']})")
if sites:
site_id = sites[0]["id"]
print(f"\n[*] Generating Purdue level report for {sites[0]['name']}...")
discovery.generate_purdue_level_report(site_id)
print(f"\n[*] Exporting asset inventory...")
discovery.export_asset_inventory(
f"asset_inventory_{datetime.now().strftime('%Y%m%d')}.csv",
site_id=site_id,
)
print(f"\n[*] Checking critical vulnerabilities...")
vulns = discovery.get_vulnerabilities(site_id=site_id, severity="critical")
print(f" Critical vulnerabilities: {len(vulns)}")
for v in vulns[:10]:
print(f" - {v.get('cve_id')}: {v.get('description', '')[:80]}")Claroty Edge performs safe, targeted queries of OT devices using native industrial protocols (not IT scanning) to extract detailed asset information from devices that passive monitoring alone cannot fully identify.
# Claroty Edge Active Discovery Configuration
# Safe active queries using native industrial protocols
edge_configuration:
deployment_mode: "on-premises"
collection_schedule:
frequency: "weekly"
maintenance_window: "Sunday 02:00-06:00"
max_concurrent_queries: 5
protocol_queries:
siemens_s7:
enabled: true
target_subnets: ["10.10.1.0/24", "10.10.2.0/24"]
ports: [102]
query_type: "SZL_read"
information_collected:
- "Module identification"
- "Firmware version"
- "Hardware configuration"
- "Protection level"
rockwell_cip:
enabled: true
target_subnets: ["10.10.3.0/24"]
ports: [44818]
query_type: "CIP_identity"
information_collected:
- "Product name and revision"
- "Serial number"
- "Device type"
- "Vendor ID"
modbus:
enabled: true
target_subnets: ["10.10.4.0/24"]
ports: [502]
query_type: "read_device_identification"
function_code: 43
information_collected:
- "Vendor name"
- "Product code"
- "Firmware revision"
bacnet:
enabled: true
target_subnets: ["10.10.5.0/24"]
ports: [47808]
query_type: "who_is"
information_collected:
- "Device name"
- "Vendor identifier"
- "Model name"
- "Application software version"
safety_controls:
excluded_subnets: ["10.10.100.0/24"] # SIS network - never active scan
rate_limiting: true
max_packets_per_second: 10
timeout_seconds: 5
retry_count: 1
abort_on_device_error: trueCross-reference discovered assets against known inventories and enrich with vulnerability data.
#!/usr/bin/env python3
"""Asset Validation and Enrichment Tool.
Cross-references Claroty discovery results against existing CMDB
and enriches with NVD vulnerability data.
"""
import json
import csv
import sys
from datetime import datetime
try:
import requests
except ImportError:
print("Install requests: pip install requests")
sys.exit(1)
class AssetValidator:
"""Validates and enriches OT asset inventory."""
def __init__(self, inventory_file: str):
self.discovered_assets = []
self.load_inventory(inventory_file)
self.discrepancies = []
def load_inventory(self, filepath: str):
"""Load Claroty-discovered asset inventory."""
with open(filepath, "r") as f:
reader = csv.DictReader(f)
self.discovered_assets = list(reader)
print(f"[*] Loaded {len(self.discovered_assets)} discovered assets")
def compare_with_cmdb(self, cmdb_file: str):
"""Compare discovered assets against CMDB records."""
with open(cmdb_file, "r") as f:
cmdb_assets = {row["ip_address"]: row for row in csv.DictReader(f)}
discovered_ips = {a["ip_address"] for a in self.discovered_assets if a["ip_address"]}
cmdb_ips = set(cmdb_assets.keys())
shadow_devices = discovered_ips - cmdb_ips
missing_devices = cmdb_ips - discovered_ips
print(f"\n{'='*60}")
print("ASSET INVENTORY VALIDATION REPORT")
print(f"{'='*60}")
print(f"Discovered assets: {len(discovered_ips)}")
print(f"CMDB records: {len(cmdb_ips)}")
print(f"Shadow OT devices (not in CMDB): {len(shadow_devices)}")
print(f"Missing devices (in CMDB, not seen): {len(missing_devices)}")
if shadow_devices:
print(f"\n SHADOW DEVICES (Unauthorized/Undocumented):")
for ip in sorted(shadow_devices):
asset = next((a for a in self.discovered_assets if a["ip_address"] == ip), {})
print(f" - {ip} | {asset.get('vendor', 'Unknown')} {asset.get('model', '')} | Type: {asset.get('type', 'Unknown')}")
self.discrepancies.append({
"type": "SHADOW_DEVICE",
"severity": "HIGH",
"ip": ip,
"detail": f"Undocumented {asset.get('type', 'device')} from {asset.get('vendor', 'unknown vendor')}",
})
if missing_devices:
print(f"\n MISSING DEVICES (Expected but not seen):")
for ip in sorted(missing_devices):
cmdb = cmdb_assets[ip]
print(f" - {ip} | {cmdb.get('name', 'Unknown')} | Last CMDB update: {cmdb.get('last_updated', 'N/A')}")
self.discrepancies.append({
"type": "MISSING_DEVICE",
"severity": "MEDIUM",
"ip": ip,
"detail": f"CMDB asset {cmdb.get('name', ip)} not seen on network",
})
def check_firmware_vulnerabilities(self, asset):
"""Check NVD for known vulnerabilities matching asset firmware."""
vendor = asset.get("vendor", "").lower()
model = asset.get("model", "").lower()
firmware = asset.get("firmware_version", "")
if not vendor or not model:
return []
search_term = f"{vendor} {model}"
try:
resp = requests.get(
"https://services.nvd.nist.gov/rest/json/cves/2.0",
params={"keywordSearch": search_term, "resultsPerPage": 10},
timeout=15,
)
if resp.status_code == 200:
data = resp.json()
return data.get("vulnerabilities", [])
except requests.RequestException:
pass
return []
def generate_risk_summary(self):
"""Generate risk-prioritized summary of findings."""
print(f"\n{'='*60}")
print("RISK SUMMARY")
print(f"{'='*60}")
high_risk = [a for a in self.discovered_assets if float(a.get("risk_score", 0)) >= 7]
end_of_life = [a for a in self.discovered_assets if a.get("firmware_version", "").startswith("v1.")]
no_encryption = [a for a in self.discovered_assets if "modbus" in a.get("protocol", "").lower()]
print(f" High-risk assets (score >= 7): {len(high_risk)}")
print(f" Potentially end-of-life firmware: {len(end_of_life)}")
print(f" Assets using unencrypted protocols: {len(no_encryption)}")
print(f" Inventory discrepancies: {len(self.discrepancies)}")
if __name__ == "__main__":
if len(sys.argv) < 2:
print("Usage: python validate_assets.py <claroty_export.csv> [cmdb_export.csv]")
sys.exit(1)
validator = AssetValidator(sys.argv[1])
if len(sys.argv) >= 3:
validator.compare_with_cmdb(sys.argv[2])
validator.generate_risk_summary()| Term | Definition |
|---|---|
| Passive Monitoring | Observing mirrored network traffic via SPAN/TAP without injecting packets, safe for all OT devices |
| Active Querying | Sending native protocol requests to extract detailed device information; requires careful scheduling |
| Claroty Edge | Claroty's safe active discovery collector that uses native industrial protocols rather than IT scanning |
| Purdue Level | Hierarchical classification of industrial network assets from Level 0 (physical process) to Level 5 (enterprise) |
| Shadow OT Device | Asset connected to the OT network that is not documented in the asset management system |
| xDome | Claroty's SaaS-based cyber-physical systems protection platform providing visibility, risk management, and threat detection |
Context: A manufacturing plant with 20 years of equipment additions needs a complete OT asset inventory for an IEC 62443 risk assessment. No accurate asset records exist.
Approach:
Pitfalls: Do not rush active discovery before passive monitoring has captured baseline traffic patterns. Never use IT vulnerability scanners (Nessus active scans) directly against PLCs or RTUs -- this can crash legacy controllers. Always exclude Safety Instrumented Systems (SIS) from active queries.
ICS ASSET DISCOVERY REPORT
============================
Date: YYYY-MM-DD
Platform: Claroty xDome
Site: [Site Name]
DISCOVERY SUMMARY:
Total Assets Discovered: [count]
New Assets (not in CMDB): [count]
High-Risk Assets: [count]
PURDUE LEVEL DISTRIBUTION:
Level 0 (Process): [count] assets
Level 1 (Control): [count] assets
Level 2 (Supervisory): [count] assets
Level 3 (Operations): [count] assets
Level 3.5 (DMZ): [count] assets
Level 4-5 (Enterprise): [count] assets
TOP VENDORS:
1. [Vendor] - [count] devices
2. [Vendor] - [count] devices
CRITICAL FINDINGS:
- [Shadow device description]
- [End-of-life firmware finding]
- [Unencrypted protocol concern]© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts, references) in skills/performing-ics-asset-discovery-with-claroty of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Performing Ics Asset Discovery With Claroty next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Performing Ics Asset Discovery With Claroty this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 481 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Shiro Attack CLISummerSec/ShiroAttack2 | 2.6k | — | ~945 | Automated safety check: Pass | MIT |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
rundeck/rundeck
Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Performs ICS/OT asset discovery with Claroty xDome, combining passive monitoring and Claroty Edge active queries to inventory PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels. Performing Ics Asset Discovery With Claroty is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs ICS/OT asset discovery with Claroty xDome, combining passive monitoring and Claroty Edge active queries to inventory PLCs, RTUs, HMIs, and network infrastructure across Purdue Model levels.
Performing Ics Asset Discovery With Claroty fits situations like: gaining visibility into an undocumented OT environment; preparing an IEC 62443 asset inventory; onboarding Claroty xDome; not for IT-only discovery.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a claude-code`. Or copy the skill folder (skills/performing-ics-asset-discovery-with-claroty in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-ics-asset-discovery-with-claroty in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a codex`. Or copy the skill folder (skills/performing-ics-asset-discovery-with-claroty in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-ics-asset-discovery-with-claroty in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ics-asset-discovery-with-claroty -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-ics-asset-discovery-with-claroty, .gemini/skills/performing-ics-asset-discovery-with-claroty, .github/skills/performing-ics-asset-discovery-with-claroty and .opencode/skills/performing-ics-asset-discovery-with-claroty in your project.
Going by SKILL.md and its folder, Performing Ics Asset Discovery With Claroty needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: services.nvd.nist.gov; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Performing Ics Asset Discovery With Claroty is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 381 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Performing Ics Asset Discovery With Claroty: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.