nmap-mcpNetwork scanning MCP server wrapping nmap. Provides 14 purpose-built tools for host discovery, port scanning (SYN/TCP/UDP), service & OS detection, NSE scrip...
Install via ClawdBot CLI:
clawdbot install sbmilburn/nmap-mcpGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/cronCalls external URL not in known-safe list
https://modelcontextprotocol.ioGenerated Mar 21, 2026
IT security teams use this skill to perform authorized scans of corporate internal networks, identifying open ports, services, and potential vulnerabilities on devices like servers and workstations. It helps enforce scope with CIDR allowlists to prevent accidental scans of unauthorized segments, ensuring compliance with internal policies during routine security assessments.
Network administrators leverage the host discovery and port scanning tools to map all active devices within a subnet, such as in a data center or office LAN, for asset tracking and inventory updates. The persistent scan results allow teams to retrieve historical data, monitor changes over time, and maintain accurate records of network assets.
Security consultants employ the NSE script execution and vulnerability scanning capabilities to simulate attacks on client networks, identifying weaknesses like outdated services or misconfigurations. The audit logging feature provides detailed records of scans for reporting and compliance purposes, supporting ethical hacking engagements.
Instructors and students in cybersecurity courses use this skill in controlled lab settings to practice network reconnaissance techniques, such as SYN scans and OS detection, without risking real-world networks. The scope enforcement ensures scans are limited to designated lab ranges, facilitating hands-on learning in a safe environment.
DevOps teams integrate the skill into cloud environments to periodically scan virtual private clouds (VPCs) for exposed services or unauthorized changes, aiding in security posture management. The structured JSON output can be fed into monitoring tools for automated alerts and trend analysis in platforms like AWS or Azure.
Offer recurring network scanning and vulnerability assessment services to businesses, using the skill to automate audits and generate reports. Revenue comes from monthly or annual subscriptions, with tiers based on scan frequency, scope size, and additional analysis support.
Provide one-time or project-based penetration testing and security consulting, leveraging the skill's tools for in-depth network analysis during client engagements. Revenue is generated through fixed project fees or hourly rates, with upsells for follow-up audits and remediation guidance.
License the skill as a component for integration into larger security platforms or SIEM systems, allowing vendors to enhance their products with network scanning capabilities. Revenue streams include upfront licensing fees, royalties per integration, or support contracts for customization and maintenance.
💬 Integration Tip
Ensure the nmap binary has the cap_net_raw capability set for SYN and OS detection scans, and configure the CIDR allowlist in config.yaml to restrict scans to authorized networks only.
Scored Apr 19, 2026
AI Analysis
The skill is a legitimate nmap wrapper with proper scope enforcement (CIDR allowlist), audit logging, and clear documentation for network security auditing. The rule-based signals appear to be false positives from scanning examples or test code, not actual malicious behavior in the skill's operation. No evidence of data exfiltration, credential harvesting, or hidden malicious instructions exists.
Audited Apr 16, 2026 · audit v1.0
Use the mcporter CLI to list, configure, auth, and call MCP servers/tools directly (HTTP or stdio), including ad-hoc servers, config edits, and CLI/type generation.
Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
Look up concert setlists and live-music history via setlist.fm. Use when the user asks what songs an artist played at a show, their tour setlists, what was p...
Use this skill whenever you need to store, retrieve, search, or view persistent context using the Alchemyst AI MCP server at mcp.getalchemystai.com/mcp/sse....
Performs safe, platform-aware system cleanup without dependencies, supports dry-run, targeted groups, and optional elevated cleanup on request.
Create and manage AI-powered smart forms, surveys, and quizzes through the Dashform MCP server. Supports open-ended, single-choice, multiple-choice, and rati...