onvifscan
Assess ONVIF Device Security
ONVIF cameras can expose services or use weak credentials. This skill guides authorized authentication checks and controlled credential tests with onvifscan.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "onvifscan" from https://skillstore.io/skills/brownfinesecurity-onvifscan.md and its manifest at https://skillstore.io/api/skills/brownfinesecurity-onvifscan/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "onvifscan". Check whether my lab camera requires ONVIF authentication.
Expected outcome:
The assessment starts with the standard authentication check. Report each endpoint as protected, exposed, unreachable, or inconclusive.
Using "onvifscan". Test approved credentials without risking an account lockout.
Expected outcome:
The plan confirms authorization, attempt limits, delay settings, stop conditions, and the approved wordlists before any credential test.
Using "onvifscan". Review a camera on a nonstandard port with detailed responses.
Expected outcome:
The scan uses the supplied port and verbose mode. The summary highlights authentication status and relevant ONVIF response details.
Security Audit
High RiskMost static findings are false positives caused by Markdown backticks or private-network examples. Six examples direct external scanner execution, while credential brute-forcing and potentially destructive tests lack mandatory authorization controls.
Confirmed security concerns (2)
Capability review items (6)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (21)
🌐 Network access (9)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/brownfinesecurity-onvifscan/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/brownfinesecurity-onvifscan?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/brownfinesecurity-onvifscan?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/brownfinesecurity-onvifscan/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/brownfinesecurity-onvifscan.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
BrownFineSecurity. (2026). onvifscan security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/brownfinesecurity-onvifscan/audits/9BibTeX citation
@techreport{brownfinesecurity-brownfinesecurity-onvifscan-2026,
author = {BrownFineSecurity},
title = {onvifscan security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/brownfinesecurity-onvifscan/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "onvifscan security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "BrownFineSecurity"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/brownfinesecurity-onvifscan/audits/9"
identifiers:
- type: other
value: "skillstore:brownfinesecurity-onvifscan:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Audit Camera Authentication
Check whether managed cameras expose ONVIF endpoints without required authentication.
Validate Credential Controls
Run approved, rate-limited credential tests with client-provided wordlists and scope.
Test Device Hardening
Compare authentication behavior across firmware builds in an isolated test environment.
Try These Prompts
I am authorized to test [target]. Prepare a basic ONVIF authentication check and explain the expected result categories.
I am authorized to test [target:port]. Plan a verbose authentication scan and summarize which response details may indicate exposed services.
Plan a rate-limited credential test for [target] using [username file] and [password file]. Confirm authorization and lockout limits before execution.
Design an ONVIF assessment for [targets]. Separate safe checks from potentially destructive tests, define stop conditions, and require confirmation before execution.
Best Practices
- Obtain written authorization and define target scope before every scan.
- Start with authentication checks and use credential testing only when explicitly approved.
- Set attempt limits, stop conditions, and recovery plans before testing production devices.
Avoid
- Do not scan internet hosts or third-party devices without explicit permission.
- Do not enable all-endpoints testing on production devices without separate confirmation.
- Do not use large wordlists when lockout behavior and device capacity are unknown.
Frequently Asked Questions
What devices can this skill assess?
Does the skill include onvifscan?
Is the authentication check non-destructive?
Can it test weak credentials?
Does it verify authorization?
Which output formats are supported?
Developer Details
Author
BrownFineSecurityLicense
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Ref
a39a91716eadede5f4cdefd78178fed4e837a128
Maintenance freshness
7/24/2026
Usage
6 downloads · 228 views
File structure
📄 SKILL.md