Install
$ agentstack add skill-knoxops-open-devops-skills-deep-scanner ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Input Parameters
| Name | Type | Required | Description | |------|------|----------|-------------| | rundir | string | Yes | Workspace root directory | | resourceid | string | Yes | Single resource ID to scan | | sshkeypath | string | No | SSH key path for remote access |
Execution Flow
Task Context
Before starting execution, initialize task_context.json:
{
"task_id": "",
"current_step": 0,
"current_step_id": null,
"status": "running",
"steps": {
"deep_scan": "pending",
"review_deep_scan": "pending"
},
"updated_at": ""
}
Update this file after each step completes. On error, set step status to "failed" and overall status to "failed".
Step 1: deep_scan
Type: agent Description: Execute deep scan on target machine
Execution
Launch an independent agent with the following prompt file:
Prompt file: $PLUGINS/ico/skills/deep-scanner/prompts/deep-scan.agent.md Agent workflow:
- Prepare the execution environment
- Execute the agent with the prompt
- Write results to:
- File:
analysis/deep_scan_{resource_id}.json
Output
- Schema: schemas/deep-scan.schema.json
- File: analysis/deepscan{resource_id}.json
Progress Tracking
After completing this step, update task_context.json:
- Set
current_step_idto"deep_scan" - Set
steps.deep_scanto"completed"
Step 2: reviewdeepscan
Type: inline Description: Validate deep scan output before completing (BLOCKING)
Execution
Follow these instructions:
Read all deep_scan output files and validate them before completing:
Each deepscan*.json MUST have:
- technical.processes[] (non-empty)
- technical.listening_ports[] (non-empty)
- technical.traffic_graph with edges[] array (iftop data collected)
- technical.crontab_entries[] present
- technical.systemd_timers[] present
- technical.disk_partitions[] present
- technical.external_traffic[] present (ss -tn output)
- business.owner with name, team fields
- business.application non-empty
Do NOT include sshkeypath or any credential paths in output. Fix any issues before completing. BLOCKING.
Progress Tracking
After completing this step, update task_context.json:
- Set
current_step_idto"review_deep_scan" - Set
steps.review_deep_scanto"completed"
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: KnoxOps
- Source: KnoxOps/open-devops-skills
- License: Apache-2.0
- Homepage: https://knoxops.app?invite_token=GITHUB26
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.