recon-nmap
Run Authorized Network Reconnaissance with Nmap
Manual network discovery can miss exposed services and inconsistent configurations. This skill provides structured Nmap workflows for authorized discovery, enumeration, vulnerability checks, and reporting.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "recon-nmap" from https://skillstore.io/skills/agentsecops-recon-nmap.md and its manifest at https://skillstore.io/api/skills/agentsecops-recon-nmap/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "recon-nmap". Plan a low-impact inventory for an approved office subnet during a maintenance window.
Expected outcome:
- Scope: one approved subnet with excluded infrastructure documented before testing.
- Sequence: conservative discovery, targeted service checks, then manual validation.
- Controls: rate caps, timestamps, source logging, and immediate stop conditions.
Using "recon-nmap". Summarize an authorized scan that found web, SSH, and database services.
Expected outcome:
The report groups hosts by service, marks uncertain versions, identifies validation priorities, and separates observations from confirmed vulnerabilities.
Using "recon-nmap". Prepare a segmentation validation workflow for production and management zones.
Expected outcome:
The workflow defines approved source paths, expected blocked ports, conservative timing, evidence capture, exception handling, and stakeholder review.
Security Audit
CriticalMost static hits in templates and Markdown are false positives caused by code fences, placeholders, defensive examples, and documentation links. Confirmed findings include privileged Nmap execution, active-scanning commands, offensive NSE guidance, scan-evasion techniques, mutable CI dependencies, and a remote installer piped to Bash. The skill requires substantial restriction and remediation before public marketplace distribution.
Confirmed security concerns (121)
Show all 121 confirmed findings
Capability review items (15)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Network access (27)
๐ Filesystem access (3)
๐ Env variables (23)
โก Contains scripts (2)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/agentsecops-recon-nmap/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/agentsecops-recon-nmap?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/agentsecops-recon-nmap?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/agentsecops-recon-nmap/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/agentsecops-recon-nmap.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
AgentSecOps. (2026). recon-nmap security audit report (audit version 9) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/agentsecops-recon-nmap/audits/9BibTeX citation
@techreport{agentsecops-agentsecops-recon-nmap-2026,
author = {AgentSecOps},
title = {recon-nmap security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/agentsecops-recon-nmap/audits/9},
note = {Author version 0.1.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "recon-nmap security audit report (audit version 9)"
version: "0.1.0"
type: report
authors:
- name: "AgentSecOps"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/agentsecops-recon-nmap/audits/9"
identifiers:
- type: other
value: "skillstore:agentsecops-recon-nmap:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Inventory an approved network
Create a conservative discovery and service inventory plan for an explicitly authorized address range.
Triage exposed services
Prioritize approved hosts and services for deeper validation during a documented security assessment.
Validate network controls
Design repeatable checks for segmentation, firewall exposure, and approved CI security gates.
Try These Prompts
I have written authorization for [scope] during [window]. Create a low-impact host discovery plan with rate limits, outputs, and stop conditions.
Review these authorized Nmap results: [results]. Summarize live hosts, open services, uncertain detections, and the safest validation steps.
Build an authorized enumeration plan for [host list]. Cover [services], safe NSE checks, timing controls, evidence collection, and false-positive validation.
Create a phased segmentation test for [zones]. Include approved paths, rate caps, output formats, stop conditions, evidence requirements, and manual review gates.
Best Practices
- Obtain written authorization and confirm scope, timing, exclusions, and emergency contacts before scanning.
- Start with conservative discovery and rate limits, then increase depth only after reviewing impact.
- Validate service and vulnerability findings manually before assigning severity or recommending remediation.
Avoid
- Do not scan public, third-party, or production systems without explicit written permission.
- Do not run exploit, brute-force, denial-of-service, or evasion scripts as default checks.
- Do not treat version matches or NSE alerts as confirmed vulnerabilities without verification.
Frequently Asked Questions
Does this skill install Nmap?
Can it scan any Internet host?
Does an NSE alert confirm a vulnerability?
Which output formats are covered?
Can scans disrupt services?
How should scan scope be controlled?
Developer Details
Author
AgentSecOpsLicense
MIT
Author version
v0.1.0
Skillstore revision
r2
Ref
9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2
Maintenance freshness
7/24/2026
Usage
8 downloads ยท 411 views
File structure