Agent skill

Scanning Tools

by zebbern in zebbern/claude-code-guide

This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware"…

MITAuto-check: notesSecurity

Install Scanning Tools

skills CLI
$ npx skills add zebbern/claude-code-guide --skill scanning-tools -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zebbern/claude-code-guide scanning-tools --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/scanning-tools .claude/skills/scanning-tools && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scanning-tools
GitHub stars
4.6k
Used in
7 other repos
Token cost
~3.4k tokens
SKILL.md length
630 words
Files
1
Skills in repo
46
Repo updated
First seen
Licence
MIT

At a glance

This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware"…

  • Works in 10 steps: Network Scanning Tools → Vulnerability Scanning Tools → Web Application Scanning Tools → …
  • Asks to perform vulnerability scanning
  • SKILL.md covers Purpose, Prerequisites, Outputs and Deliverables and Core Workflow, plus 3 more sections
  • Calls docker, pip and apt

What it does

Scanning Tools is an agent skill from zebbern/claude-code-guide. This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security scanning tools and methodologies.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.

When your agent uses it

  • Asks to perform vulnerability scanning
  • Scan networks for open ports
  • Assess web application security
  • Scan wireless networks

Example prompts

  • “perform vulnerability scanning”
  • “scan networks for open ports”
  • “assess web application security”
  • “/scanning-tools”

Requirements

  • Python 3
  • Docker

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Network Scanning Tools
  2. Vulnerability Scanning Tools
  3. Web Application Scanning Tools
  4. Wireless Scanning Tools
  5. Malware and Exploit Scanning
  6. Cloud Security Scanning
  7. Compliance Scanning
  8. Scanning Methodology
  9. Tool Selection Guide
  10. Reporting and Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit 4698e3b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • pip
    • apt

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Scanning Tools loads about 3.4k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 630 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:115
    sudo systemctl start nessusd
  • NoteRuns commands with sudoSKILL.md:140
    sudo apt install openvas
  • NoteRuns commands with sudoSKILL.md:141
    sudo gvm-setup
  • NoteRuns commands with sudoSKILL.md:144
    sudo gvm-start
  • NoteRuns commands with sudoSKILL.md:262
    sudo airmon-ng start wlan0
  • NoteRuns commands with sudoSKILL.md:265
    sudo airodump-ng wlan0mon
  • NoteRuns commands with sudoSKILL.md:268
    sudo airodump-ng -c <channel> --bssid <target_bssid> -w capture wlan0mon
  • NoteRuns commands with sudoSKILL.md:271
    sudo aireplay-ng -0 10 -a <bssid> wlan0mon
  • NoteRuns commands with sudoSKILL.md:307
    sudo freshclam
  • NoteRuns commands with sudoSKILL.md:411
    sudo lynis audit system

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zebbern/claude-code-guide at commit 4698e3b, republished under its MIT licence (© zebbern). 630 words, ~3,385 tokens.

Download SKILL.mdSave it as .claude/skills/scanning-tools/SKILL.md (or your agent's skills folder).
name
scanning-tools
description
This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security scanning tools and methodologies.
metadata.author
zebbern
metadata.version
1.1

Security Scanning Tools

Purpose

Master essential security scanning tools for network discovery, vulnerability assessment, web application testing, wireless security, and compliance validation. This skill covers tool selection, configuration, and practical usage across different scanning categories.

Prerequisites

Required Environment
  • Linux-based system (Kali Linux recommended)
  • Network access to target systems
  • Proper authorization for scanning activities
Required Knowledge
  • Basic networking concepts (TCP/IP, ports, protocols)
  • Understanding of common vulnerabilities
  • Familiarity with command-line interfaces

Outputs and Deliverables

  1. Network Discovery Reports - Identified hosts, ports, and services
  2. Vulnerability Assessment Reports - CVEs, misconfigurations, risk ratings
  3. Web Application Security Reports - OWASP Top 10 findings
  4. Compliance Reports - CIS benchmarks, PCI-DSS, HIPAA checks

Core Workflow

Phase 1: Network Scanning Tools
Nmap (Network Mapper)

Primary tool for network discovery and security auditing:

bash
# Host discovery
nmap -sn 192.168.1.0/24              # Ping scan (no port scan)
nmap -sL 192.168.1.0/24              # List scan (DNS resolution)
nmap -Pn 192.168.1.100               # Skip host discovery

# Port scanning techniques
nmap -sS 192.168.1.100               # TCP SYN scan (stealth)
nmap -sT 192.168.1.100               # TCP connect scan
nmap -sU 192.168.1.100               # UDP scan
nmap -sA 192.168.1.100               # ACK scan (firewall detection)

# Port specification
nmap -p 80,443 192.168.1.100         # Specific ports
nmap -p- 192.168.1.100               # All 65535 ports
nmap -p 1-1000 192.168.1.100         # Port range
nmap --top-ports 100 192.168.1.100   # Top 100 common ports

# Service and OS detection
nmap -sV 192.168.1.100               # Service version detection
nmap -O 192.168.1.100                # OS detection
nmap -A 192.168.1.100                # Aggressive (OS, version, scripts)

# Timing and performance
nmap -T0 192.168.1.100               # Paranoid (slowest, IDS evasion)
nmap -T4 192.168.1.100               # Aggressive (faster)
nmap -T5 192.168.1.100               # Insane (fastest)

# NSE Scripts
nmap --script=vuln 192.168.1.100     # Vulnerability scripts
nmap --script=http-enum 192.168.1.100  # Web enumeration
nmap --script=smb-vuln* 192.168.1.100  # SMB vulnerabilities
nmap --script=default 192.168.1.100  # Default script set

# Output formats
nmap -oN scan.txt 192.168.1.100      # Normal output
nmap -oX scan.xml 192.168.1.100      # XML output
nmap -oG scan.gnmap 192.168.1.100    # Grepable output
nmap -oA scan 192.168.1.100          # All formats
Masscan

High-speed port scanning for large networks:

bash
# Basic scanning
masscan -p80 192.168.1.0/24 --rate=1000
masscan -p80,443,8080 192.168.1.0/24 --rate=10000

# Full port range
masscan -p0-65535 192.168.1.0/24 --rate=5000

# Large-scale scanning
masscan 0.0.0.0/0 -p443 --rate=100000 --excludefile exclude.txt

# Output formats
masscan -p80 192.168.1.0/24 -oG results.gnmap
masscan -p80 192.168.1.0/24 -oJ results.json
masscan -p80 192.168.1.0/24 -oX results.xml

# Banner grabbing
masscan -p80 192.168.1.0/24 --banners
Phase 2: Vulnerability Scanning Tools
Nessus

Enterprise-grade vulnerability assessment:

bash
# Start Nessus service
sudo systemctl start nessusd

# Access web interface
# https://localhost:8834

# Command-line (nessuscli)
nessuscli scan --create --name "Internal Scan" --targets 192.168.1.0/24
nessuscli scan --list
nessuscli scan --launch <scan_id>
nessuscli report --format pdf --output report.pdf <scan_id>

Key Nessus features:

  • Comprehensive CVE detection
  • Compliance checks (PCI-DSS, HIPAA, CIS)
  • Custom scan templates
  • Credentialed scanning for deeper analysis
  • Regular plugin updates
OpenVAS (Greenbone)

Open-source vulnerability scanning:

bash
# Install OpenVAS
sudo apt install openvas
sudo gvm-setup

# Start services
sudo gvm-start

# Access web interface (Greenbone Security Assistant)
# https://localhost:9392

# Command-line operations
gvm-cli socket --xml "<get_version/>"
gvm-cli socket --xml "<get_tasks/>"

# Create and run scan
gvm-cli socket --xml '
<create_target>
  <name>Test Target</name>
  <hosts>192.168.1.0/24</hosts>
</create_target>'
Phase 3: Web Application Scanning Tools
Burp Suite

Comprehensive web application testing:

# Proxy configuration
1. Set browser proxy to 127.0.0.1:8080
2. Import Burp CA certificate for HTTPS
3. Add target to scope

# Key modules:
- Proxy: Intercept and modify requests
- Spider: Crawl web applications
- Scanner: Automated vulnerability detection
- Intruder: Automated attacks (fuzzing, brute-force)
- Repeater: Manual request manipulation
- Decoder: Encode/decode data
- Comparer: Compare responses

Core testing workflow:

  1. Configure proxy and scope
  2. Spider the application
  3. Analyze sitemap
  4. Run active scanner
  5. Manual testing with Repeater/Intruder
  6. Review findings and generate report
OWASP ZAP

Open-source web application scanner:

bash
# Start ZAP
zaproxy

# Automated scan from CLI
zap-cli quick-scan https://target.com

# Full scan
zap-cli spider https://target.com
zap-cli active-scan https://target.com

# Generate report
zap-cli report -o report.html -f html

# API mode
zap.sh -daemon -port 8080 -config api.key=<your_key>

ZAP automation:

bash
# Docker-based scanning
docker run -t owasp/zap2docker-stable zap-full-scan.py \
  -t https://target.com -r report.html

# Baseline scan (passive only)
docker run -t owasp/zap2docker-stable zap-baseline.py \
  -t https://target.com -r report.html
Nikto

Web server vulnerability scanner:

bash
# Basic scan
nikto -h https://target.com

# Scan specific port
nikto -h target.com -p 8080

# Scan with SSL
nikto -h target.com -ssl

# Multiple targets
nikto -h targets.txt

# Output formats
nikto -h target.com -o report.html -Format html
nikto -h target.com -o report.xml -Format xml
nikto -h target.com -o report.csv -Format csv

# Tuning options
nikto -h target.com -Tuning 123456789  # All tests
nikto -h target.com -Tuning x          # Exclude specific tests
Phase 4: Wireless Scanning Tools
Aircrack-ng Suite

Wireless network penetration testing:

bash
# Check wireless interface
airmon-ng

# Enable monitor mode
sudo airmon-ng start wlan0

# Scan for networks
sudo airodump-ng wlan0mon

# Capture specific network
sudo airodump-ng -c <channel> --bssid <target_bssid> -w capture wlan0mon

# Deauthentication attack
sudo aireplay-ng -0 10 -a <bssid> wlan0mon

# Crack WPA handshake
aircrack-ng -w wordlist.txt -b <bssid> capture*.cap

# Crack WEP
aircrack-ng -b <bssid> capture*.cap
Kismet

Passive wireless detection:

bash
# Start Kismet
kismet

# Specify interface
kismet -c wlan0

# Access web interface
# http://localhost:2501

# Detect hidden networks
# Kismet passively collects all beacon frames
# including those from hidden SSIDs
Phase 5: Malware and Exploit Scanning
ClamAV

Open-source antivirus scanning:

bash
# Update virus definitions
sudo freshclam

# Scan directory
clamscan -r /path/to/scan

# Scan with verbose output
clamscan -r -v /path/to/scan

# Move infected files
clamscan -r --move=/quarantine /path/to/scan

# Remove infected files
clamscan -r --remove /path/to/scan

# Scan specific file types
clamscan -r --include='\.exe$|\.dll$' /path/to/scan

# Output to log
clamscan -r -l scan.log /path/to/scan
Metasploit Vulnerability Validation

Validate vulnerabilities with exploitation:

bash
# Start Metasploit
msfconsole

# Database setup
msfdb init
db_status

# Import Nmap results
db_import /path/to/nmap_scan.xml

# Vulnerability scanning
use auxiliary/scanner/smb/smb_ms17_010
set RHOSTS 192.168.1.0/24
run

# Auto exploitation
vulns                           # View vulnerabilities
analyze                         # Suggest exploits
Phase 6: Cloud Security Scanning
Prowler (AWS)

AWS security assessment:

bash
# Install Prowler
pip install prowler

# Basic scan
prowler aws

# Specific checks
prowler aws -c iam s3 ec2

# Compliance framework
prowler aws --compliance cis_aws

# Output formats
prowler aws -M html json csv

# Specific region
prowler aws -f us-east-1

# Assume role
prowler aws -R arn:aws:iam::123456789012:role/ProwlerRole
ScoutSuite (Multi-cloud)

Multi-cloud security auditing:

bash
# Install ScoutSuite
pip install scoutsuite

# AWS scan
scout aws

# Azure scan
scout azure --cli

# GCP scan
scout gcp --user-account

# Generate report
scout aws --report-dir ./reports
Phase 7: Compliance Scanning
Lynis

Security auditing for Unix/Linux:

bash
# Run audit
sudo lynis audit system

# Quick scan
sudo lynis audit system --quick

# Specific profile
sudo lynis audit system --profile server

# Output report
sudo lynis audit system --report-file /tmp/lynis-report.dat

# Check specific section
sudo lynis show profiles
sudo lynis audit system --tests-from-group malware
OpenSCAP

Security compliance scanning:

bash
# List available profiles
oscap info /usr/share/xml/scap/ssg/content/ssg-<distro>-ds.xml

# Run scan with profile
oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_pci-dss \
  --report report.html \
  /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml

# Generate fix script
oscap xccdf generate fix \
  --profile xccdf_org.ssgproject.content_profile_pci-dss \
  --output remediation.sh \
  /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
Phase 8: Scanning Methodology

Structured scanning approach:

  1. Planning

    • Define scope and objectives
    • Obtain proper authorization
    • Select appropriate tools
  2. Discovery

    • Host discovery (Nmap ping sweep)
    • Port scanning
    • Service enumeration
  3. Vulnerability Assessment

    • Automated scanning (Nessus/OpenVAS)
    • Web application scanning (Burp/ZAP)
    • Manual verification
  4. Analysis

    • Correlate findings
    • Eliminate false positives
    • Prioritize by severity
  5. Reporting

    • Document findings
    • Provide remediation guidance
    • Executive summary
Phase 9: Tool Selection Guide

Choose the right tool for each scenario:

ScenarioRecommended Tools
Network DiscoveryNmap, Masscan
Vulnerability AssessmentNessus, OpenVAS
Web App TestingBurp Suite, ZAP, Nikto
Wireless SecurityAircrack-ng, Kismet
Malware DetectionClamAV, YARA
Cloud SecurityProwler, ScoutSuite
ComplianceLynis, OpenSCAP
Protocol AnalysisWireshark, tcpdump
Show full SKILL.md (238 more words)Show less
Phase 10: Reporting and Documentation

Generate professional reports:

bash
# Nmap XML to HTML
xsltproc nmap-output.xml -o report.html

# OpenVAS report export
gvm-cli socket --xml '<get_reports report_id="<id>" format_id="<pdf_format>"/>'

# Combine multiple scan results
# Use tools like Faraday, Dradis, or custom scripts

# Executive summary template:
# 1. Scope and methodology
# 2. Key findings summary
# 3. Risk distribution chart
# 4. Critical vulnerabilities
# 5. Remediation recommendations
# 6. Detailed technical findings

Quick Reference

Nmap Cheat Sheet
Scan TypeCommand
Ping Scannmap -sn <target>
Quick Scannmap -T4 -F <target>
Full Scannmap -p- <target>
Service Scannmap -sV <target>
OS Detectionnmap -O <target>
Aggressivenmap -A <target>
Vuln Scriptsnmap --script=vuln <target>
Stealth Scannmap -sS -T2 <target>
Common Ports Reference
PortService
21FTP
22SSH
23Telnet
25SMTP
53DNS
80HTTP
443HTTPS
445SMB
3306MySQL
3389RDP

Constraints and Limitations

  • Always obtain written authorization
  • Respect scope boundaries
  • Follow responsible disclosure practices
  • Comply with local laws and regulations
Technical Limitations
  • Some scans may trigger IDS/IPS alerts
  • Heavy scanning can impact network performance
  • False positives require manual verification
  • Encrypted traffic may limit analysis
Best Practices
  • Start with non-intrusive scans
  • Gradually increase scan intensity
  • Document all scanning activities
  • Validate findings before reporting

Troubleshooting

Scan Not Detecting Hosts

Solutions:

  1. Try different discovery methods: nmap -Pn or nmap -sn -PS/PA/PU
  2. Check firewall rules blocking ICMP
  3. Use TCP SYN scan: nmap -PS22,80,443
  4. Verify network connectivity
Slow Scan Performance

Solutions:

  1. Increase timing: nmap -T4 or -T5
  2. Reduce port range: --top-ports 100
  3. Use Masscan for initial discovery
  4. Disable DNS resolution: -n
Web Scanner Missing Vulnerabilities

Solutions:

  1. Authenticate to access protected areas
  2. Increase crawl depth
  3. Add custom injection points
  4. Use multiple tools for coverage
  5. Perform manual testing

© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/scanning-tools of zebbern/claude-code-guide.

Open the folder on GitHubat commit 4698e3b

Used in 7 other repositories

We found 17 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in zebbern/claude-code-guide, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Scanning Tools next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scanning Tools compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scanning Tools this skillzebbern/claude-code-guide4.6k7 repos~3.4kAutomated safety check: NotesMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from zebbern/claude-code-guide

All 46 skills in this repo
  • Localization Toolkit

    zebbern/claude-code-guide

    This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…

    4.6k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Audit Flow

    zebbern/claude-code-guide

    Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

    4.6k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Chart Image

    zebbern/claude-code-guide

    Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.

    4.6k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Code To Diagram

    zebbern/claude-code-guide

    Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.

    4.6k GitHub stars~972 tokensUpdated today
    Auto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.6k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Data Viz Renderer

    zebbern/claude-code-guide

    Generate self-contained HTML/SVG infographics from JSON data, including stat cards, bar charts, flow diagrams, and mixed dashboards.

    4.6k GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Scanning Tools

What does Scanning Tools do?

This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware"…. Scanning Tools is an agent skill from zebbern/claude-code-guide. This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance".

When should I use Scanning Tools?

Scanning Tools fits situations like: asks to perform vulnerability scanning; scan networks for open ports; assess web application security; scan wireless networks.

How do I install Scanning Tools in Claude Code?

Run `npx skills add zebbern/claude-code-guide --skill scanning-tools -a claude-code`. Or copy the skill folder (skills/scanning-tools in zebbern/claude-code-guide) into .claude/skills/scanning-tools in your project. Claude Code loads it when a task matches its description.

How do I install Scanning Tools in Codex?

Run `npx skills add zebbern/claude-code-guide --skill scanning-tools -a codex`. Or copy the skill folder (skills/scanning-tools in zebbern/claude-code-guide) into .agents/skills/scanning-tools in your project. Codex loads it when a task matches its description.

Can I use Scanning Tools in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill scanning-tools -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scanning-tools, .gemini/skills/scanning-tools, .github/skills/scanning-tools and .opencode/skills/scanning-tools in your project.

What does Scanning Tools need to run?

Going by SKILL.md and its folder, Scanning Tools needs the command-line tools its instructions call (docker, pip and apt). Our summary lists: Python 3; Docker.

Does Scanning Tools access the network?

SKILL.md contains no URLs. Its commands use docker and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Scanning Tools safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Scanning Tools use?

Scanning Tools is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scanning Tools use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Scanning Tools?

Skills that share tags, products or a category with Scanning Tools: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scanning Tools?

zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,648 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 7, 2026.

Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.