wsdiscovery
50WS-Discovery デバイスの検出
デバイスインベントリが不完全な場合、ONVIF カメラや IoT デバイスの検出には時間がかかることがあります。このスキルは、承認済みの WS-Discovery スキャンをガイドし、デバイスのメタデータとサービスエンドポイントを要約します。
ファームウェアのファイルタイプを解析
ファームウェアイメージには、手作業では調査しにくいファイルシステムやセキュリティアーティファクトが隠れていることがよくあります。このスキルは、ファイルタイプを特定し、管理された抽出を計画するための ffind 解析をガイドします。
インストール前に停止して確認を求めてください。
計画を確認し、ファイルを変更する前にユーザーの明示的な同意を得てください。
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "ffind" from https://skillstore.io/skills/brownfinesecurity-ffind.md and its manifest at https://skillstore.io/api/skills/brownfinesecurity-ffind/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
「ffind」を使用しています。 ファームウェアイメージを解析し、アーティファクトタイプを要約します。
期待される結果:
結果には、検出されたファイルカテゴリ、件数、注目すべきパス、抽出可能と思われるファイルシステムが一覧表示されます。
「ffind」を使用しています。 2つのファームウェアファイルを調査し、結果を比較します。
期待される結果:
応答では、両方のイメージに存在するファイルタイプ、各イメージに固有のタイプ、抽出対象となる可能性が高いものを強調します。
「ffind」を使用しています。 ファイルシステム抽出ワークフローを準備します。
期待される結果:
応答では、昇格権限を使うコマンドの前に承認を求め、制限付き権限を持つ専用の出力ディレクトリを推奨します。
Eighteen external-command alerts are false positives caused by Markdown formatting, not Ruby backtick execution. Four sudo instructions are confirmed because extraction runs firmware tooling with root privileges; two temporary extraction paths add shared-directory risk. No prompt injection, exfiltration, or hidden execution instructions were found.
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
https://skillstore.io/skills/brownfinesecurity-ffind/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/brownfinesecurity-ffind?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/brownfinesecurity-ffind?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/brownfinesecurity-ffind/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/brownfinesecurity-ffind.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>BrownFineSecurity. (2026). ffind security audit report (audit version 10) [Author version unspecified]. Skillstore. https://skillstore.io/skills/brownfinesecurity-ffind/audits/10@techreport{brownfinesecurity-brownfinesecurity-ffind-2026,
author = {BrownFineSecurity},
title = {ffind security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/brownfinesecurity-ffind/audits/10},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ffind security audit report (audit version 10)"
version: "unspecified"
type: report
authors:
- name: "BrownFineSecurity"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/brownfinesecurity-ffind/audits/10"
identifiers:
- type: other
value: "skillstore:brownfinesecurity-ffind:audit:10"
description: "Skillstore immutable audit report identifier"
より深いリバースエンジニアリングの前に、埋め込まれたファイルシステム、アーカイブ、証明書、スクリプトを特定します。
ファームウェアビルドに想定されるファイルタイプと抽出可能なパーティションが含まれているか確認します。
調査中に、未知のイメージ内のファイルタイプをすばやく要約します。
Analyze this firmware image with ffind and summarize the detected file types: <path>.
Use ffind to inspect <path> and include common file types, not only security artifacts.
Check whether <path> contains extractable filesystems. Ask before using elevated privileges or writing output files.
Analyze these firmware images with ffind, compare detected artifact types, and call out extraction candidates: <paths>.
ライセンス
MIT
Skillstore リビジョン
r2
バージョンに関する注意
作者はバージョンを宣言していません。
参照
a39a91716eadede5f4cdefd78178fed4e837a128
メンテナンスの新しさ
2026/7/25
利用状況
10 ダウンロード · 269 閲覧
ファイル構成
📄 SKILL.md
WS-Discovery デバイスの検出
デバイスインベントリが不完全な場合、ONVIF カメラや IoT デバイスの検出には時間がかかることがあります。このスキルは、承認済みの WS-Discovery スキャンをガイドし、デバイスのメタデータとサービスエンドポイントを要約します。
ApktoolでAndroid APKを解析
Android APKの解析では、apktool、マニフェスト、リソースの確認手順を何度も繰り返す必要がある場合があります。このスキルは、Claude、Codex、Claude Codeに対して、安全な展開、検査、再パッケージ化のワークフローを案内します。
JadxでAndroid APKを解析
Android APKのセキュリティレビューは、バイトコードやリソースを検査しにくい場合に時間がかかります。このスキルは、認可された評価のためにjadxによるデコンパイルと重点的なソースレビューをガイドします。
IoT Telnet シェルの監査
認可されたセキュリティテスト中に、IoT telnet シェルを一貫して調査するのは困難です。このスキルは、telnet ヘルパー、列挙スクリプト、ログ記録ガイダンス、デバイス評価向けの構造化されたワークフローを提供します。
CHIPSECでUEFIファームウェアを解析
ファームウェアダンプは、再現可能なツールなしではレビューが困難です。このスキルは、脅威チェック、インベントリ作成、構造デコード、レポート作成のためのオフラインCHIPSECワークフローを案内します。
認可済みの Nmap 偵察を実行
手動のネットワークスキャンではポートを見落としたり、証跡が整理されないことがあります。このスキルは、認可済みの Nmap スキャン、出力の整理、サービス概要の作成を支援します。
ファームウェアセキュリティを分析する
作成者 sickn33
ファームウェアレビューでは、多くの場合、多数のツールと慎重な証拠の取り扱いが必要です。このスキルは、許可された抽出、エミュレーション、脆弱性レビュー、レポート作成をガイドします。
Velociraptorでエンドポイントを調査する
作成者 AgentSecOps
インシデント対応担当者は、進行中の調査においてエンドポイントを迅速に可視化する必要があります。このスキルは、認可されたフォレンジック作業向けに、Velociraptor VQLパターン、コレクターのガイダンス、ハントテンプレートを提供します。
osqueryでエンドポイントを調査する
作成者 AgentSecOps
インシデント対応担当者は、ツールを切り替えずに迅速なエンドポイント証拠を必要とします。このスキルは、Claude、Codex、Claude Codeをosqueryによるトリアージ、ハンティング、監視へ導きます。
Audit Software Releases with Evidence
作成者 glenskii
Release decisions often rely on incomplete evidence and inconsistent standards. This skill applies structured controls, deterministic scoring, and mandatory gates to assess readiness.
Audit Python Web Apps Before Release
作成者 glenskii
Python teams need repeatable checks for common application security controls. This skill provides configurable pytest coverage with clear evidence, boundaries, and release decisions.
ISO 27001セキュリティガバナンスの実装
作成者 davila7
HealthcareおよびMedTechチームには、リスク、管理策、インシデント、監査を結び付ける体系的なISO 27001セキュリティプログラムが必要です。このスキルは、ISO 27001およびISO 27002を使用して、ISMS計画、リスクアセスメント、管理策の選定、認証準備を支援します。