ot-ics

ot-ics is a skill for Claude Code, Codex from zhaoxuya520/reverse-skill. It costs 33 tokens per session (901 once invoked), scanned A, original, MIT.

A safety-first guide for assessing industrial control systems such as PLCs, SCADA servers, HMIs, and engineering stations. It explains how to map industrial networks and protocols while starting with passive and read-only checks.

In plain words
What is it for?
Use it to document Purdue network zones, identify exposed Modbus, DNP3, S7, or EtherNet/IP services, review IT/OT boundaries, inspect mirrored traffic, and assess configurations and firmware under written authorisation.
Why use it?
Industrial systems can control physical processes, so an ordinary aggressive scan or write operation may disrupt equipment or create safety risks.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

not rated 35krepo +671 6d ago A scan Socket: passSnyk: passSkillSpector: pass 33 tokens original MIT

Good fit Use it to document Purdue network zones, identify exposed Modbus, DNP3, S7, or EtherNet/IP services, review IT/OT boundaries, inspect mirrored traffic, and assess configurations and firmware under written authorisation.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/zhaoxuya520/reverse-skill/ot-ics
About the project

Reverse Skill is a routing package for AI coding agents that selects appropriate reverse-engineering, penetration-testing, and security-research methods and tools for a given target. It is used for tasks involving APKs, binaries, frontend JavaScript, packet captures, CTF challenges, and authorized penetration testing. Its catalogue add-ons provide the skills and instructions that guide these workflows.

zhaoxuya520/reverse-skill · 35,183 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add zhaoxuya520/reverse-skill --skill ot-ics
Clone the repo
git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ot-ics

README.md
[![agentmods](https://agentmods.dev/badge/skills/zhaoxuya520/reverse-skill/ot-ics/github.svg)](https://agentmods.dev/skills/zhaoxuya520/reverse-skill/ot-ics)
Your own site
<a href="https://agentmods.dev/skills/zhaoxuya520/reverse-skill/ot-ics"><img src="https://agentmods.dev/badge/skills/zhaoxuya520/reverse-skill/ot-ics/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for ot-ics

Your own site · 80×15
<a href="https://agentmods.dev/skills/zhaoxuya520/reverse-skill/ot-ics"><img src="https://agentmods.dev/badge/skills/zhaoxuya520/reverse-skill/ot-ics.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 33 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 901 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • Socket pass 18 Jul 2026
  • Snyk pass 18 Jul 2026
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00033 $0.00901
Opus 5 $0.00016 $0.00451
Sonnet 5 $0.00007 $0.00180
Haiku 4.5 $0.00003 $0.00090

Measured 6d ago against content hash 81bf7ff97d1e, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

ot-ics scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

3 near-identical copies found in the catalogue:

  • ot-ics — 100% identical, 0 lines differ
  • ot-ics — 100% identical, 0 lines differ
  • ot-ics — 100% identical, 0 lines differ
skills/ot-ics/SKILL.md · 93 lines

What it actually says

OT / ICS Security

ACTION REQUIRED(读完后立刻执行)

  1. NOW: 读取 ../field-journal/precedent-pentest.md工控环境误操作可致物理危害
  2. NOW: 书面授权必须写清:站点、网段、是否允许主动扫描/写寄存器
  3. NOW: case-init;默认 passive-firstready_for_act 前禁止对 PLC 写操作
  4. NEXT: tool-index;多数工控工具需手动与隔离实验网
  5. ACT: 资产与分区识别 → 暴露面 → 只读验证

适用场景

  • 工控/SCADA/DCS 安全评估(授权)
  • Purdue 模型分区与跨区通道
  • Modbus/DNP3/S7/EtherNet/IP 等协议暴露
  • 工程师站、HMI、历史库、跳板主机
  • IT/OT 融合边界(防火墙规则、单向闸)

安全铁律(MUST)

MUST NOT 在未明确允许时:
- 对 PLC 写线圈/寄存器
- 全网高速率扫描生产 OT
- 中断安全仪表系统(SIS)相关路径
优先:只读识别、流量镜像、离线固件/配置分析

工作流

Phase 1 — 分区与资产

□ Purdue L0–L5 草图:现场设备 → 控制 → 监督 → 站点 DMZ → 企业
□ 资产清单:PLC/RTU/HMI/工程师站/历史库/Jump host
□ 协议与端口基线(仅授权网段)

Phase 2 — 被动与只读

□ SPAN/镜像 PCAP → protocol-reverse / Wireshark 工控解析器
□ 配置与工程文件离线审计(TIA/RSLogix 导出等)
□ 默认口令与明文协议(Modbus 无认证)记录为 Finding,不写盘改值

Phase 3 — 受限主动(仅授权)

□ 低速识别,维护窗口
□ 只读功能码优先
□ 每步 Evidence;异常立即停止并通报

Phase 4 — 固件/补丁面

□ 控制器固件版本 → CVE 映射(不盲刷固件)
□ 联合 firmware-pentest 做离线镜像分析

工具链

工具 用途 注意
Wireshark 工控 dissectors 被动解析 镜像流量
Nmap NSE(受限) 识别 速率与时间窗
Claroty/Nozomi 等 资产发现 商业/现场
PLC 厂商工程软件 配置审计 离线优先
binwalk / Ghidra 固件 离线

参考

  • references/ot-safe-assessment.md
  • ../firmware-pentest/ ../protocol-reverse/ ../network via pentest-tools

路由上下文

上游: MASTER R28
下游: 固件深挖 firmware-pentest;协议 protocol-reverse;IT 横向 windows-ad/attack-chain
同级: 不要用普通 Web 扫默认参数打 OT

任务完成自检

  • 是否默认被动/只读并记录授权边界?
  • 是否避免对控制回路写操作(除非明确允许)?
  • Finding 是否含物理/过程影响说明?
  • Checklist / journal?
Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 93 lines · 33 tokens per session scan A 81bf7ff97d1e

Subscribe to this mod's changes

ot-ics is a skill published in the GitHub repository zhaoxuya520/reverse-skill (35,183 stars, last pushed 6d ago), licensed MIT. It adds 33 tokens to every session and 901 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

gke-compute-classes

Configures, optimizes, and troubleshoots GKE ComputeClasses. Use when configuring Spot VMs with on-demand fallback, targeting specific accelerators (GPUs/TPUs) or machine families, restricting ComputeClass access, or debugging pending pods related to node pool auto-creation. Do not use for cluster-level Node Auto…

google/skills · 83 tokens

jetson-diagnostic

Read-only Jetson health snapshot for identity, memory, GPU, thermal, power, storage, services, and top processes.

NVIDIA/skills · 30 tokens

doca-socket-relay

Use this skill when the operator is driving the DOCA Socket Relay to bridge a socket-oriented host application onto a BlueField DPU peer without rewriting it — picking the deployment shape (in-process, sidecar, or BlueField service container), configuring the host-side socket and the DPU-side forwarding endpoint…

NVIDIA/skills · 236 tokens

offensive-z-wave

Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, S2 (modern) ECDH commissioning analysis, replay/injection on unauthenticated nodes, default-key brute-force on test deployments, and home-automation hub pivots. Use when targeting…

SnailSploit/Claude-Red · 113 tokens

hsb-flash

Flash the FPGA on an HSB board connected to an NVIDIA devkit. Supports HSB Lattice boards (FPGA versions 2407, 2412, 2507, 2510) and Leopard Imaging VB1940 "all-in-one" cameras (FPGA versions 2507, 2510). Uses release-specific YAML manifests and board-type-specific program commands. Lattice and VB1940 commands must…

NVIDIA/skills · 94 tokens

jetson-validate-image

Use after jetson-flash-image to run static BSP checks, on-target smoke/regression tests on a flashed DUT, or both. Not for build or flash steps. Triggers: validate bsp, on-target validation.

NVIDIA/skills · 50 tokens