Install any skill in seconds. Free to start, no credit card required.
Get Started Free →ONVIF device security scanner for testing authentication and brute-forcing credentials. Use when you need to assess security of IP cameras or ONVIF-enabled devices.
.claude/skills/aiskillstore-onvifscan/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-05 | ✗→✓ | ▲ Improved | -41% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -47% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 86% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -36% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -24% | 0% |
You are helping the user scan ONVIF devices for security issues including authentication bypasses and weak credentials using the onvifscan tool.
Onvifscan is an ONVIF device security scanner that can:
When the user asks to scan ONVIF devices, test IP cameras, or assess IoT device security:
auth: Authentication and access control testing (recommended to start)brute: Credential brute-forcing on password-protected endpointsonvifscan <subcommand> <url> [options]Tests ONVIF endpoints for authentication requirements:
bashonvifscan auth http://192.168.1.100
Options:
-v, --verbose: Show full XML responses-a, --all: Test ALL endpoints including potentially destructive ones--format text|json|quiet: Output formatAttempts credential brute-forcing on protected endpoints:
bashonvifscan brute http://192.168.1.100
Options:
--usernames <file>: Custom usernames wordlist (default: built-in onvif-usernames.txt)--passwords <file>: Custom passwords wordlist (default: built-in onvif-passwords.txt)--format text|json|quiet: Output formatQuick auth check on a device:
bashonvifscan auth 192.168.1.100
Auth check with verbose output:
bashonvifscan auth http://192.168.1.100:8080 -v
Brute force with custom wordlists:
bashonvifscan brute 192.168.1.100 --usernames custom-users.txt --passwords custom-pass.txt
http:// - it will be added automatically-a flag with caution - may test destructive endpointswordlists/ directory| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 18,109 | 12,605 | -30% | 1 | 1 | 0% | 1,446 | 1,249 | -14% | 0 | 0 | — |
case-02 | fail→fail | 12,574 | 10,538 | -16% | 1 | 1 | 0% | 639 | 1,457 | +128% | 0 | 0 | — |
case-03 | fail→fail | 12,500 | 9,842 | -21% | 1 | 1 | 0% | 927 | 1,465 | +58% | 0 | 0 | — |
case-04 | pass→pass | 14,869 | 2,885 | -81% | 1 | 1 | 0% | 1,705 | 1,125 | -34% | 0 | 0 | — |
case-05 | fail→pass | 14,454 | 3,397 | -76% | 1 | 1 | 0% | 1,964 | 1,167 | -41% | 0 | 0 | — |
case-06 | fail→fail | 11,340 | 20,037 | +77% | 1 | 1 | 0% | 1,010 | 1,700 | +68% | 0 | 0 | — |
case-07 | fail→fail | 10,866 | 19,191 | +77% | 1 | 1 | 0% | 1,345 | 1,665 | +24% | 0 | 0 | — |
case-08 | fail→pass | 17,536 | 2,479 | -86% | 1 | 1 | 0% | 2,076 | 1,109 | -47% | 0 | 0 | — |
case-09 | fail→pass | 17,665 | 13,232 | -25% | 1 | 1 | 0% | 1,020 | 1,899 | +86% | 0 | 0 | — |
case-10 | fail→fail | 16,708 | 34,968 | +109% | 1 | 1 | 0% | 1,818 | 3,356 | +85% | 0 | 0 | — |
case-15 | pass→pass | 18,013 | 8,272 | -54% | 1 | 1 | 0% | 2,230 | 1,227 | -45% | 0 | 0 | — |
case-11 | fail→pass | 16,300 | 13,458 | -17% | 1 | 1 | 0% | 1,741 | 1,121 | -36% | 0 | 0 | — |
case-12 | fail→pass | 19,373 | 14,039 | -28% | 1 | 1 | 0% | 1,399 | 1,064 | -24% | 0 | 0 | — |
case-13 | pass→pass | 17,377 | 6,636 | -62% | 1 | 1 | 0% | 1,946 | 1,648 | -15% | 0 | 0 | — |
case-14 | fail→pass | 12,965 | 11,384 | -12% | 1 | 1 | 0% | 1,918 | 1,608 | -16% | 0 | 0 | — |
case-16 | pass→pass | 17,569 | 17,157 | -2% | 1 | 1 | 0% | 2,070 | 1,092 | -47% | 0 | 0 | — |
case-17 | fail→pass | 18,209 | 17,450 | -4% | 1 | 1 | 0% | 2,174 | 1,434 | -34% | 0 | 0 | — |
case-18 | pass→pass | 24,788 | 7,971 | -68% | 1 | 1 | 0% | 2,309 | 1,203 | -48% | 0 | 0 | — |
case-19 | fail→pass | 6,505 | 2,456 | -62% | 1 | 1 | 0% | 985 | 960 | -3% | 0 | 0 | — |
case-20 | pass→pass | 15,997 | 13,299 | -17% | 1 | 1 | 0% | 1,986 | 2,230 | +12% | 0 | 0 | — |
case-21 | pass→pass | 24,996 | 23,163 | -7% | 1 | 1 | 0% | 3,521 | 4,193 | +19% | 0 | 0 | — |
case-22 | pass→pass | 15,031 | 7,208 | -52% | 1 | 1 | 0% | 2,417 | 1,661 | -31% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +36 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.