Agent skill

Nmap Parse

by SpecterOps in SpecterOps/skills

Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

Apache-2.0Auto-check passedSecurity

Install Nmap Parse

skills CLI
$ npx skills add SpecterOps/skills --skill nmap-parse -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills nmap-parse --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ops-reconnaissance/skills/nmap-parse .claude/skills/nmap-parse && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nmap-parse
GitHub stars
702
Token cost
~738 tokens
SKILL.md length
309 words
Files
4 (incl. assets)
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

  • Works in 3 steps: Read the nmap output file provided by… → Extract and organize by host → Classify services into attack categories
  • Analyzing nmap XML/grepable output
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Planning service enumeration

What it does

Nmap Parse is an agent skill from SpecterOps/skills. Parse nmap scan output and generate actionable recon notes. Use when analyzing nmap XML/grepable output, planning service enumeration, or doing network reconnaissance.

Its SKILL.md is about 740 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including assets (for example `agents/openai.yaml`).

It sits in Security, covering Penetration testing. It works with Nmap. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.

When your agent uses it

  • Analyzing nmap XML/grepable output
  • Planning service enumeration
  • Doing network reconnaissance

Example prompts

  • “/nmap-parse”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read the nmap output file provided by the user
  2. Extract and organize by host
  3. Classify services into attack categories

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nmap Parse loads about 738 tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 309 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~738

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 309 words, ~738 tokens.

Download SKILL.mdSave it as .claude/skills/nmap-parse/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
nmap-parse
description
Parse nmap scan output and generate actionable recon notes. Use when analyzing nmap XML/grepable output, planning service enumeration, or doing network reconnaissance.
metadata.author
GhostWorks

Nmap Parse & Recon Planning

Parse nmap scan results and produce actionable reconnaissance notes.

Parse the user's input to determine the file and focus area:

  • $nmap-parse scan.xml → parse XML output, all service categories
  • $nmap-parse scan.gnmap web → parse grepable output, web services only
  • $nmap-parse scan.nmap ad → parse normal output, Active Directory focus

Focus areas: all (default), web, ad, databases, remote-access

Steps

  1. Read the nmap output file provided by the user

    • Detect format: XML (look for <?xml), grepable (look for Host:), or normal output
    • XML is preferred for structured parsing — use Python's xml.etree.ElementTree or regex extraction
    • For grepable/normal: extract with pattern matching
  2. Extract and organize by host:

    • IP address and hostname (if resolved)
    • OS detection results (if available)
    • Open ports with service name, version, and state
    • Script output (NSE results)
  3. Classify services into attack categories:

Web Services (ports 80, 443, 8080, 8443, etc.)
  • Note web server version (Apache, Nginx, IIS + version)
  • Flag interesting headers from NSE scripts
  • Suggest: gobuster, ffuf, nikto, Burp Suite targets
Active Directory (ports 88, 389, 636, 445, 135, 5985, etc.)
  • Identify domain controllers (88+389+445+636 combo)
  • Note SMB signing status
  • Note LDAP/LDAPS availability
  • Suggest: BloodHound collection, crackmapexec/netexec enumeration, Kerberos attacks
Databases (1433, 3306, 5432, 1521, 27017, 6379, etc.)
  • Note database type and version
  • Flag default ports
  • Suggest: authentication testing, impacket-mssqlclient
Remote Access (22, 3389, 5985, 5986, 2222, etc.)
  • SSH version and auth methods
  • RDP availability and NLA status
  • WinRM/PSRemoting availability
  • Suggest: credential testing, key-based auth checks
Other Notable Services
  • FTP (21) — anonymous access?
  • SNMP (161/162) — community string testing
  • DNS (53) — zone transfer testing
  • SMTP (25) — relay testing
  1. Generate output as structured markdown:
markdown
# Network Recon — [date]

## Host Summary
| IP | Hostname | OS | Open Ports |
|---|---|---|---|

## Priority Targets
[Hosts with the most attack surface, ordered by interest]

## Service Breakdown
### Web Servers
### Active Directory
### Databases
### Remote Access

## Suggested Next Steps
[Ordered list of enumeration commands to run next]
  1. If the user specified a focus area, filter output to only that category but still mention other notable services in a brief "Other Services" section

  2. Create the output directory if it doesn't exist (mkdir -p recon/) and save output to recon/nmap-analysis-[date].md

© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (assets) in plugins/ops-reconnaissance/skills/nmap-parse of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/icon.png
  • assets/icon.svg

Open the folder on GitHubat commit e655f93

Compare with similar skills

Nmap Parse next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nmap Parse compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nmap Parse this skillSpecterOps/skills702—~738Automated safety check: PassApache-2.0
NmapBrownFineSecurity/iothackbot8581 repos~3.8kAutomated safety check: NotesMIT
Nmap ReconCommonHuman-Lab/nyxstrike156—~639Automated safety check: PassCustom licence
Operate Network Reconcyberful/cyberful134—~1.1kAutomated safety check: PassAGPL-3.0
Recon NmapAgentSecOps/SecOpsAgentKit2191 repos~4.6kAutomated safety check: NotesCustom licence
Detecting Network Scanning With Ids Signaturesmukul975/Anthropic-Cybersecurity-Skills34k—~3.5kAutomated safety check: PassApache-2.0

Similar skills

  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    858 GitHub starsUsed in 1 repo~3.8k tokens
    SecurityAuto-check: notes
  • Nmap Recon

    CommonHuman-Lab/nyxstrike

    Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools

    156 GitHub stars~639 tokensUpdated today
    SecurityAuto-check passed
  • Operate Network Recon

    cyberful/cyberful

    Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

    134 GitHub stars~1.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Recon Nmap

    AgentSecOps/SecOpsAgentKit

    Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.

    219 GitHub starsUsed in 1 repo~4.6k tokens
    SecurityAuto-check: notes
  • Detecting Network Scanning With Ids Signatures

    mukul975/Anthropic-Cybersecurity-Skills

    Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning…

    34k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Scanning Network With Nmap Advanced

    mukul975/Anthropic-Cybersecurity-Skills

    Performs advanced network recon using Nmap's Scripting Engine (NSE), timing controls, firewall/IDS evasion, and structured output parsing to discover hosts, enumerate service versions, detect…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from SpecterOps/skills

All 38 skills in this repo
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    702 GitHub stars~805 tokensUpdated 14 days ago
    Auto-check passed
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    702 GitHub stars~1.5k tokensUpdated 14 days ago
    Auto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    702 GitHub stars~2.4k tokensUpdated 14 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    702 GitHub stars~665 tokensUpdated 14 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    702 GitHub stars~813 tokensUpdated 14 days ago
    Auto-check passed
  • Proxychains Tunnel

    SpecterOps/skills

    Run in-scope network commands through a SOCKS5 tunnel with proxychains4, including tunnel readiness checks and evidence capture.

    702 GitHub stars~826 tokensUpdated 14 days ago
    Auto-check passed

Works with

Categories

Questions about Nmap Parse

What does Nmap Parse do?

Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills. Nmap Parse is an agent skill from SpecterOps/skills. Parse nmap scan output and generate actionable recon notes.

When should I use Nmap Parse?

Nmap Parse fits situations like: analyzing nmap XML/grepable output; planning service enumeration; doing network reconnaissance.

How do I install Nmap Parse in Claude Code?

Run `npx skills add SpecterOps/skills --skill nmap-parse -a claude-code`. Or copy the skill folder (plugins/ops-reconnaissance/skills/nmap-parse in SpecterOps/skills) into .claude/skills/nmap-parse in your project. Claude Code loads it when a task matches its description.

How do I install Nmap Parse in Codex?

Run `npx skills add SpecterOps/skills --skill nmap-parse -a codex`. Or copy the skill folder (plugins/ops-reconnaissance/skills/nmap-parse in SpecterOps/skills) into .agents/skills/nmap-parse in your project. Codex loads it when a task matches its description.

Can I use Nmap Parse in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill nmap-parse -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nmap-parse, .gemini/skills/nmap-parse, .github/skills/nmap-parse and .opencode/skills/nmap-parse in your project.

What does Nmap Parse need to run?

SKILL.md names no scripts, command-line tools or credentials: Nmap Parse is instructions for the agent only.

Does Nmap Parse access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nmap Parse safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nmap Parse use?

Nmap Parse is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nmap Parse use?

About 738 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nmap Parse?

Skills that share tags, products or a category with Nmap Parse: Nmap (BrownFineSecurity/iothackbot, 858 stars), Nmap Recon (CommonHuman-Lab/nyxstrike, 156 stars), Operate Network Recon (cyberful/cyberful, 134 stars) and Recon Nmap (AgentSecOps/SecOpsAgentKit, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nmap Parse?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 702 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.