nmap-mcpNetwork scanning MCP server wrapping nmap. Provides 14 purpose-built tools for host discovery, port scanning (SYN/TCP/UDP), service & OS detection, NSE scrip...
Install via ClawdBot CLI:
clawdbot install sbmilburn/nmap-mcpGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/cronCalls external URL not in known-safe list
https://modelcontextprotocol.ioGenerated Mar 21, 2026
IT security teams use this skill to perform authorized scans of corporate internal networks, identifying open ports, services, and potential vulnerabilities on devices like servers and workstations. It helps enforce scope with CIDR allowlists to prevent accidental scans of unauthorized segments, ensuring compliance with internal policies during routine security assessments.
Network administrators leverage the host discovery and port scanning tools to map all active devices within a subnet, such as in a data center or office LAN, for asset tracking and inventory updates. The persistent scan results allow teams to retrieve historical data, monitor changes over time, and maintain accurate records of network assets.
Security consultants employ the NSE script execution and vulnerability scanning capabilities to simulate attacks on client networks, identifying weaknesses like outdated services or misconfigurations. The audit logging feature provides detailed records of scans for reporting and compliance purposes, supporting ethical hacking engagements.
Instructors and students in cybersecurity courses use this skill in controlled lab settings to practice network reconnaissance techniques, such as SYN scans and OS detection, without risking real-world networks. The scope enforcement ensures scans are limited to designated lab ranges, facilitating hands-on learning in a safe environment.
DevOps teams integrate the skill into cloud environments to periodically scan virtual private clouds (VPCs) for exposed services or unauthorized changes, aiding in security posture management. The structured JSON output can be fed into monitoring tools for automated alerts and trend analysis in platforms like AWS or Azure.
Offer recurring network scanning and vulnerability assessment services to businesses, using the skill to automate audits and generate reports. Revenue comes from monthly or annual subscriptions, with tiers based on scan frequency, scope size, and additional analysis support.
Provide one-time or project-based penetration testing and security consulting, leveraging the skill's tools for in-depth network analysis during client engagements. Revenue is generated through fixed project fees or hourly rates, with upsells for follow-up audits and remediation guidance.
License the skill as a component for integration into larger security platforms or SIEM systems, allowing vendors to enhance their products with network scanning capabilities. Revenue streams include upfront licensing fees, royalties per integration, or support contracts for customization and maintenance.
💬 Integration Tip
Ensure the nmap binary has the cap_net_raw capability set for SYN and OS detection scans, and configure the CIDR allowlist in config.yaml to restrict scans to authorized networks only.
Scored Apr 19, 2026
AI Analysis
The skill is a legitimate nmap wrapper with proper scope enforcement (CIDR allowlist), audit logging, and clear documentation for network security auditing. The rule-based signals appear to be false positives from scanning examples or test code, not actual malicious behavior in the skill's operation. No evidence of data exfiltration, credential harvesting, or hidden malicious instructions exists.
Audited Apr 16, 2026 · audit v1.0
Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).
通过 macOS Accessibility API 控制小红书(rednote)App。支持私信、评论回复、视频评论读取、搜索、点赞、收藏、作者数据等。需要 Mac + rednote App 可见 + Terminal 辅助功能权限。
AI-first security intelligence with LLM-powered intent analysis. 743+ findings from 361+ skill audits, 25 pattern rules, 22 attack classes.
OpenAMC 本地 MCP 命令调用技能。通过标准化 CLI 接口,允许 AI Agent 主动向本地 MCP Server 发送查询指令以获取全球金融数据。覆盖 A股/港股(AKShare)、美股(yfinance)、宏观经济(FRED/IMF/EconDB)、美国国会(Congress)及衍生品、外汇、大宗...
Build backend AI with Vercel AI SDK v6 stable. Covers Output API (replaces generateObject/streamObject), speech synthesis, transcription, embeddings, MCP tools with security guidance. Includes v4→v5 migration and 15 error solutions with workarounds. Use when: implementing AI SDK v5/v6, migrating versions, troubleshooting AI_APICallError, Workers startup issues, Output API errors, Gemini caching issues, Anthropic tool errors, MCP tools, or stream resumption failures.
Interact with the BNB Chain Model Context Protocol (MCP) server. Use to query DeFi data, get token prices, search documentation, fetch git diffs, and retrieve smart contract source code on BNB Chain.