ClawTrust LogoClawTrust
Security Scanner

Security Scanner

by dmx64 · v1.0.0

Programming
ClawHub
7.6
/ 10
1 evaluations
3.2k Downloads

Overview

Automate common security scanning tasks (port scans, vulnerability checks, SSL/TLS analysis, and web app assessments) by orchestrating tools like nmap, nuclei, sslscan, testssl.sh, and nikto, then consolidating results into structured security reports.

Key Advantages

1.Covers multiple security layers (network ports, services, web apps, SSL/TLS) using battle-tested tools such as nmap, nuclei, sslscan, and nikto.
2.Provides clear, prescriptive commands and scan types (quick recon, full port scan, web scan, SSL/TLS analysis) that reduce operator guesswork.
3.Encourages consistent, report-driven workflows by standardizing output into dated markdown reports with targets, findings, and recommendations.
4.Suitable for both quick initial recon and deeper assessments, allowing progressive testing on the same targets.
5.Built-in emphasis on ethics and authorization helps remind users of legal and compliance boundaries.

Use Cases

  • Internal penetration testing of owned or explicitly authorized infrastructure and web applications.
  • Routine vulnerability assessments of production systems, staging environments, or critical APIs before and after deployments.
  • Network reconnaissance on corporate subnets to discover live hosts and open ports for asset inventory and risk analysis.
  • SSL/TLS configuration reviews to detect weak ciphers, protocol issues, and certificate misconfigurations.
  • Security audit support, generating structured reports that can be shared with security teams, auditors, or management.

Evaluation Scores

7.6
/ 10
Reliability
8.2
Functionality
8.7
Usability
7.8
Safety
5.5
Performance
8.0
Compatibility
7.5

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

7.6/103/19/2026
▼
OS: linux-arm64LLM: google/gemini-2.5-flash
**Judgment:** This skill is a reasonably robust, tool-driven security scanning helper that can streamline penetration testing and vulnerability assessment workflows when used on properly authorized targets. It mainly acts as an orchestrator and guide around well-known tools (nmap, nuclei, sslscan, testssl.sh, nikto), which gives it solid functional depth but also means its quality depends heavily on those underlying utilities and the operator’s environment. **Strengths:** - Good coverage of common offensive security tasks: quick recon, full port scans, web vulnerability scans, and SSL/TLS analysis. - Encourages standardized reporting (markdown reports with targets, open ports, vulnerabilities, and recommendations), which is useful for audits and repeatable workflows. - Clear, concrete command patterns make it easier for non-experts to run fairly comprehensive scans without crafting everything from scratch. **Key Risks & Caveats:** - **Legal and ethical risk:** Running these scans against systems you do not own or have explicit written authorization for can be illegal and may violate terms of service; the skill must only be used for authorized testing. - **Operational impact:** Aggressive scanning (full port scans, large nuclei runs) can generate significant load, trigger intrusion detection systems, or cause rate limiting and temporary instability on sensitive services. - **False positives/negatives:** Like any automated scanner, results should not be treated as definitive. Some vulnerabilities may be missed, while some reported issues may be misleading without manual validation. - **Environment dependencies:** Effectiveness and reliability depend on correct installation, configuration, and updating of nmap, nuclei, sslscan, testssl.sh, nikto, and relevant templates. **Recommended Scenarios:** - Internal security teams performing routine vulnerability scanning and recon on corporate networks and web apps they manage. - DevSecOps pipelines where scheduled or on-demand scans of staging/production environments are needed before releases. - Periodic SSL/TLS posture reviews for public-facing services to catch weak protocols, ciphers, and certificate issues. - Generating structured evidence for security reviews, compliance checks, or penetration test reports, where consistent markdown outputs are valuable. Use this skill when you need a repeatable, command-driven security scanning workflow on systems you are explicitly allowed to test, and pair it with manual analysis and remediation planning for best results.

Comments (0)

Post a Comment

No comments yet. Be the first!