wsdiscovery
Discover ONVIF and WS-Discovery Devices
Finding ONVIF cameras and compatible IoT devices manually is slow. This skill guides WS-Discovery scans and explains device metadata in clear formats.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "wsdiscovery" from https://skillstore.io/skills/brownfinesecurity-wsdiscovery.md and its manifest at https://skillstore.io/api/skills/brownfinesecurity-wsdiscovery/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "wsdiscovery". Scan an authorized camera at 192.168.1.100 using text output.
Expected outcome:
- One WS-Discovery endpoint responded at the requested address.
- The summary lists its device type, identifier, model details, metadata version, and management service endpoint.
Using "wsdiscovery". Investigate why an approved recorder does not appear in discovery.
Expected outcome:
- No WS-Discovery response was received from the target.
- Check routing, multicast filtering, firewall rules, device discovery settings, and WS-Discovery support.
Using "wsdiscovery". Summarize an authorized local multicast discovery scan.
Expected outcome:
The inventory groups responding cameras, recorders, printers, and media devices by address, type, manufacturer, model, firmware, and service endpoint.
Security Audit
Medium RiskThe skill intentionally executes WS-Discovery scans and supports host or multicast discovery. Markdown backticks and private example addresses are mostly scanner false positives, but authorization safeguards are absent.
Confirmed security concerns (6)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (13)
🌐 Network access (4)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/brownfinesecurity-wsdiscovery/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/brownfinesecurity-wsdiscovery?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/brownfinesecurity-wsdiscovery?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/brownfinesecurity-wsdiscovery/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/brownfinesecurity-wsdiscovery.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
BrownFineSecurity. (2026). wsdiscovery security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/brownfinesecurity-wsdiscovery/audits/9BibTeX citation
@techreport{brownfinesecurity-brownfinesecurity-wsdiscovery-2026,
author = {BrownFineSecurity},
title = {wsdiscovery security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/brownfinesecurity-wsdiscovery/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "wsdiscovery security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "BrownFineSecurity"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/brownfinesecurity-wsdiscovery/audits/9"
identifiers:
- type: other
value: "skillstore:brownfinesecurity-wsdiscovery:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Inventory Security Cameras
Discover approved ONVIF cameras and record their models, firmware versions, serial numbers, and service endpoints.
Troubleshoot Device Discovery
Use verbose responses to investigate why an authorized camera or recorder is missing from management software.
Inspect IoT Metadata
Review WS-Discovery types, scopes, device identifiers, and XAddr services during integration testing.
Try These Prompts
Confirm that {target} is authorized, then run a text WS-Discovery scan. Summarize each responding device and its service endpoints.Scan {authorized_target} with JSON output. Present a concise inventory of addresses, models, firmware versions, serial numbers, and XAddr services.Run a verbose WS-Discovery scan against {authorized_target}. Explain the returned XML fields and identify missing or inconsistent ONVIF metadata.Within the approved local network, query 239.255.255.250. Group responding devices by type and flag outdated firmware or incomplete metadata for review.
Best Practices
- Confirm ownership, written authorization, and target scope before every scan.
- Start with a specific host and use multicast only when broad local discovery is approved.
- Protect verbose responses and inventories because they can contain serial numbers, locations, firmware details, and management endpoints.
Avoid
- Do not scan public, third-party, or unapproved addresses.
- Do not insert untrusted target text into a shell command without validation and argument separation.
- Do not publish verbose XML or device inventories that expose sensitive infrastructure details.
Frequently Asked Questions
What devices can this skill discover?
Does it require network access?
Which output formats are available?
Can it discover every camera?
Does it change device settings?
Is multicast discovery safe to run anywhere?
Developer Details
Author
BrownFineSecurityLicense
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Ref
a39a91716eadede5f4cdefd78178fed4e837a128
Maintenance freshness
7/24/2026
Usage
7 downloads · 200 views
File structure
📄 SKILL.md