nsauditor-ai

nsauditor-ai is a skill for Claude Code, Codex from opencue/cuecards. It costs 312 tokens per session (8,820 once invoked), scanned B, original, MIT.

An AI-assisted network security auditing tool for scanning hosts, identifying services and operating systems, matching findings to known vulnerabilities, and mapping them to MITRE ATT&CK techniques.

In plain words
What is it for?
It is for scanning a hostname or IP address, reviewing detected services and findings, and assessing network security.
Why use it?
It brings host discovery and vulnerability assessment into one audit process, helping reveal exposed services and security weaknesses.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: installed under .agents/ (shared by several agents); mentions Codex.

Good fit It is for scanning a hostname or IP address, reviewing detected services and findings, and assessing network security.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/opencue/cuecards/nsauditor-ai
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add opencue/cuecards --skill nsauditor-ai
Clone the repo
git clone --depth 1 https://github.com/opencue/cuecards

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for nsauditor-ai

README.md
[![agentmods](https://agentmods.dev/badge/skills/opencue/cuecards/nsauditor-ai.svg)](https://agentmods.dev/skills/opencue/cuecards/nsauditor-ai)
Your own site
<a href="https://agentmods.dev/skills/opencue/cuecards/nsauditor-ai"><img src="https://agentmods.dev/badge/skills/opencue/cuecards/nsauditor-ai.svg" alt="Measured on agentmods" height="20"></a>
Per session 312 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 8,820 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00312 $0.08820
Opus 5 $0.00156 $0.04410
Sonnet 5 $0.00062 $0.01764
Haiku 4.5 $0.00031 $0.00882

Measured 4d ago against content hash 0193c2036b75, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade B, and why

nsauditor-ai scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Cloud metadata endpointmediumServer-side request forgery

One request to 169.254.169.254 can return temporary IAM credentials.

metadata endpoints (169.254.169.254) — this is SSRF protection, not a bug.

Downgraded: this mod is about security review, or the phrase is quoted, so it is likely naming the pattern rather than instructing it.

.agents/skills/nsauditor-ai/SKILL.md · 540 lines

How it starts

The opening of the file, as written. The whole thing — 540 lines — stays where its author put it; the contents beside it link to each section on GitHub.

NSAuditor AI — Agent Skill

Version: 0.1.10 · Source: github.com/nsasoft/nsauditor-ai · npm: nsauditor-ai · License: MIT (CE)

NSAuditor AI is a modular, AI-assisted network security audit platform with 27+ scanner plugins, CVE matching, MITRE ATT&CK mapping, and Zero Data Exfiltration by design. This skill teaches you how to operate it via MCP tools and CLI.


MCP Tools Reference

NSAuditor AI exposes tools via Model Context Protocol (stdio transport). Available tools depend on the license tier (Community / Pro / Enterprise).

Community Edition Tools (always available)

scan_host

Run a full plugin scan against a target host. Executes ALL enabled plugins in priority order (discovery → service probes → OS detection → result fusion).

Parameter Type Required Default Description
host string Target hostname or IP address
timeout number 30000 Per-plugin timeout in ms

Returns: { summary, host, services[], findings[] } — see references/schemas.md

Example:

{ "host": "192.168.1.1", "timeout": 10000 }

Important:

  • For RFC 1918 / private IPs, the MCP server must have NSA_ALLOW_ALL_HOSTS=1 set.
  • The server blocks loopback (127.x, ::1), link-local (169.254.x, fe80:), and cloud metadata endpoints (169.254.169.254) — this is SSRF protection, not a bug.
  • Plugins with unmet requirements auto-skip (e.g., SSH scanner skips if port 22 is closed).

list_plugins

List all available scanner plugins with metadata.

Parameter Type Required Description
(none)

Returns: Array of { id, name, description, priority, protocols[], ports[], requirements }

When to use: Before a scan to understand available plugins, or to help the user select specific plugins for a targeted probe.


probe_service (Pro license required)

Run a single plugin against a specific host:port for deep-dive investigation.

Read the full file on GitHub · 540 lines

Files

What ships with it

8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 540 lines · 312 tokens per session scan B 0193c2036b75

Subscribe to this mod's changes

nsauditor-ai is a skill published in the GitHub repository opencue/cuecards (5 stars, last pushed yesterday), licensed MIT. It adds 312 tokens to every session and 8,820 once invoked, about $0.0016 per session on Opus 5. A static security scan graded it B with 1 finding (cloud metadata endpoint). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

loongsuite-pilot-insight

A reporting workflow for turning LoongSuite Pilot and AI coding-agent logs into structured reports about events, teams, data quality, development efficiency, and AI use. It defines the meaning of the log fields and the measurements used in dashboards.

alibaba/loongsuite-pilot · 91 tokens

loongsuite-pilot-ops

Skill "loongsuite-pilot-ops" from alibaba/loongsuite-pilot, covering loongsuite-pilot-ops, quick start, todo: add quick start commands and usage.

alibaba/loongsuite-pilot · 15 tokens

atomic-visual-options

Planning-phase visual comparison aid. Renders 2-4 side-by-side variants per decision dimension as a single throwaway, self-contained HTML file and captures the user's pick as typed terminal codes (e.g. "A2 B3"). Auto-fires on phrases like "show me a few options", "mock up some variants", "let me see this side by…

damusix/atomic-claude · 150 tokens

atomic-wiki

Conversational wiki and capture-bucket routing. Fires when the user wants a place, space, or folder for notes, research, tickets, raw dumps, or knowledge capture — checks the block in /.claude/CLAUDE.md; if the cwd is under a registered realm, creates the folder as a bucket via atomic wiki bucket add rather than a…

damusix/atomic-claude · 204 tokens

atomic-review

Compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment is one line: location, problem, fix. Use when user says "review this PR", "code review", "review the diff", or invokes /atomic-review. Auto-triggers when reviewing pull requests.

damusix/atomic-claude · 63 tokens

atomic-tdd

Test-first discipline. Auto-triggers on "let's implement X", "add feature Y", "fix bug Z", "write a test for", "implement", "build out", and similar pre-code-change phrases. Iron rule: failing test exists before production code. Skip only for pure docs/config changes with an explicit "skipped because:" note. Explicit…

damusix/atomic-claude · 142 tokens