otsafescan-SKILL.md

Identify and assess OT vulnerabilities in industrial networks with passive monitoring and controlled active checks.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/DCx7C5/ai-marketplace --skill otsafescan-skill-md
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: otsafescan-SKILL.md
Source: https://github.com/DCx7C5/ai-marketplace/tree/main/skills/vulnerabilities/scanning/otsafescan
Command: npx skills add https://github.com/DCx7C5/ai-marketplace --skill otsafescan-skill-md

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

OT environments often run legacy controllers with undetected vulnerabilities, creating risk to safety and operations. This Skill provides a safe, auditable approach to identify and prioritize weaknesses without disrupting critical processes.

Core Features & Use Cases

  • Passive vulnerability detection to observe traffic without impacting devices.
  • Native protocol queries and OT-safe scanning for accurate asset information.
  • Risk-prioritized reporting and exportable findings for OT risk management.

Quick Start

Run otsafescan against a test OT network to generate a preliminary vulnerability report.

Frequently Asked Questions about otsafescan-SKILL.md

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan OT networks for vulnerabilities without disrupting critical processes?

To scan OT networks safely, use passive monitoring and native protocol queries to assess vulnerabilities without impacting legacy controllers or critical processes. This approach provides accurate asset information while maintaining operational safety.

What is passive vulnerability detection in ICS environments?

Passive vulnerability detection in ICS environments observes network traffic to identify weaknesses without actively probing devices. This method ensures safety-critical systems and legacy controllers remain undisturbed during risk assessment.

Can I use active scanning on legacy industrial control systems?

Active scanning on legacy industrial control systems is possible using controlled, lab-tested scanning profiles. These configurable safety levels ensure that active checks do not disrupt safety-critical operations.

How do I prioritize OT risks and export vulnerability findings?

Prioritize OT risks by assessing vulnerabilities based on their impact on safety and operations, then generate exportable findings. This creates an auditable report for effective OT risk management.

Does this approach support native protocol queries for accurate asset information?

Yes, native protocol queries are supported to retrieve accurate asset information from OT networks. This ensures precise vulnerability assessment across diverse industrial control systems.

What are the limitations of active checks in safety-critical OT environments?

Active checks in safety-critical OT environments must be limited to controlled, lab-tested scanning profiles to prevent disruption. Configurable safety levels are required to protect legacy devices during vulnerability scanning.