iotnet
IoTネットワークトラフィックの評価
IoTチームには、パケットキャプチャとライブトラフィックから得られる明確な証拠が必要です。このスキルは、Claude、Codex、Claude CodeによるIoTプロトコルと脆弱性の分析をガイドします。
インストール前に停止して確認を求めてください。
計画を確認し、ファイルを変更する前にユーザーの明示的な同意を得てください。
自分のエージェントでインストール
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "iotnet" from https://skillstore.io/skills/brownfinesecurity-iotnet.md and its manifest at https://skillstore.io/api/skills/brownfinesecurity-iotnet/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
エージェントが読めるリソース
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
テストする
「iotnet」を使用しています。 スマートサーモスタットのラボから取得したパケットキャプチャを分析してください。
期待される結果:
レポートではMQTTとSSDPトラフィックを特定し、TLSの欠如を指摘し、暗号化の有効化とより強力な認証を推奨します。
「iotnet」を使用しています。 単一のカメラIPアドレスからのトラフィックを確認してください。
期待される結果:
出力ではONVIFとRTSPトラフィックをグループ化し、平文の認証情報にフラグを付け、手動確認が必要なパケットを一覧化します。
「iotnet」を使用しています。 テストVLANからの承認済みライブキャプチャを要約してください。
期待される結果:
要約には、プロトコル数、不審なデバイス動作、優先順位付きの修復チェックリストが含まれます。
セキュリティ監査
高リスクMost reported shell-execution patterns are false positives caused by Markdown code fences and inline parameter names. Four sudo instructions are confirmed because live capture runs IoTNet with elevated privileges, and the workflow lacks explicit authorization and privacy safeguards for inspecting network traffic.
確認済みのセキュリティ上の懸念 (1)
機能レビュー項目 (4)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (29)
🌐 ネットワークアクセス (1)
このレポートを共有・引用
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
レポートリンクをコピー
https://skillstore.io/skills/brownfinesecurity-iotnet/audits/10?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdownバッジ
[](https://skillstore.io/skills/brownfinesecurity-iotnet?utm_source=security_passport_badge)HTMLバッジ
<a href="https://skillstore.io/skills/brownfinesecurity-iotnet?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/brownfinesecurity-iotnet/security.svg" alt="Skillstore security assessment" loading="lazy"></a>埋め込みカード
<iframe src="https://skillstore.io/embed/skills/brownfinesecurity-iotnet.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>学術引用 (APA · BibTeX · CFF)
APA形式の引用
BrownFineSecurity. (2026). iotnet security audit report (audit version 10) [Author version unspecified]. Skillstore. https://skillstore.io/skills/brownfinesecurity-iotnet/audits/10BibTeX形式の引用
@techreport{brownfinesecurity-brownfinesecurity-iotnet-2026,
author = {BrownFineSecurity},
title = {iotnet security audit report (audit version 10)},
institution = {Skillstore},
year = {2026},
number = {10},
url = {https://skillstore.io/skills/brownfinesecurity-iotnet/audits/10},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "iotnet security audit report (audit version 10)"
version: "unspecified"
type: report
authors:
- name: "BrownFineSecurity"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/brownfinesecurity-iotnet/audits/10"
identifiers:
- type: other
value: "skillstore:brownfinesecurity-iotnet:audit:10"
description: "Skillstore immutable audit report identifier"
Skillstore スコア
このスコアの理由 証拠の信頼度: 中作成できるもの
ラボキャプチャの監査
導入前に、キャプチャ済みのデバイストラフィックを確認して、安全でないプロトコル、暗号化の欠如、弱い認証を特定します。
現場ネットワークのトリアージ
選択したインターフェースから短時間の承認済みトラフィックサンプルをキャプチャし、デバイス通信のリスクを要約します。
コンプライアンス証拠の文書化
クライアント向けレポート用に、PCAPファイルから明確な所見と修復メモを作成します。
これらのプロンプトを試す
[path] のPCAPを分析してください。検出されたIoTプロトコル、脆弱性、推奨される修正を報告してください。
デバイス [IP address] について [path] を分析してください。通常の通信と、リスクのある平文通信または弱い認証を分けてください。
[interface] で [duration] 秒間、承認済みトラフィックをキャプチャしてください。安全なフィルターを使用し、IoTセキュリティ上の問題を要約してください。
[custom rules file] と [display filter] を使用して [PCAP paths] を分析してください。重要度の高い所見と修復のための証拠を優先してください。
ベストプラクティス
- このスキルは、分析する権限があるネットワークとパケットキャプチャに対してのみ使用してください。
- ライブキャプチャが不要な場合は、オフラインPCAP分析を優先してください。
- すべての所見について、フィルター、キャプチャ時間、ルールファイルを記録してください。
回避
- 明示的な許可なしにネットワーク上でライブキャプチャを実行しないでください。
- サンプルのIPアドレスやコマンドを本番環境のポリシーとして扱わないでください。
- 認証情報や個人情報が含まれている可能性のあるパケットデータを公開しないでください。
よくある質問
このスキルはiotnetをインストールしますか?
ライブトラフィックを分析できますか?
PCAPファイルを分析できますか?
どのプロトコルを特定できますか?
手動のセキュリティレビューを置き換えますか?
なぜ昇格権限に言及しているのですか?
開発者情報
ライセンス
MIT
Skillstore リビジョン
r2
バージョンに関する注意
作者はバージョンを宣言していません。
参照
a39a91716eadede5f4cdefd78178fed4e837a128
メンテナンスの新しさ
2026/7/25
利用状況
7 ダウンロード · 175 閲覧
ファイル構成
📄 SKILL.md