2
    scada-hmi-security-assessment

    scada-hmi-security-assessment

    by LocoLoboZ

    Perform evidence-based security assessments and compliance audits for SCADA/HMI systems in OT environments.

    Updated May 2026
    Security scanned
    One-time purchase
    including Claude Code

    $20

    · or 100 credits

    One-time purchase

    30-day refund guarantee

    Secure checkout via Stripe

    Also available in a bundle

    Included in download

    • Generate audit-ready security reports for ICS/SCADA human-machine interfaces.
    • Map HMI configuration vulnerabilities to IEC 62443 or NIST SP 800-82 standards.
    • terminal automation included
    • Ready for including Claude Code
    • Instant install

    See it in action

    A real example of what this skill takes in and produces.

    Sample input

    We need to assess our plant web-based HMI running on the OT network before an IEC 62443 audit. The HMI is isolated in a test environment. Run the full assessment covering authentication, communication, web security, and hardening checks, and produce a structured report.

    Sample output

    The skill produces a structured assessment output with 21 checks across four categories, each labelled with its check ID, name, IEC 62443 SR reference, and test procedure. The automated agent scans for open SCADA protocol ports, analyses any supplied PCAP for insecure protocols, and reviews an HMI configuration file for disabled authentication, missing session timeouts, and absent TLS. The final report includes a findings register with severity ratings (Critical, High, Medium), a category-level pass/fail summary, and an IEC 62443 Security Level Achieved versus Target comparison.

    About This Skill

    Professional Security Auditing for SCADA & HMI Systems

    Maintaining security in Operational Technology (OT) environments is critical but complex. This skill provides a structured, developer-centric framework for conducting evidence-based security assessments of SCADA systems, HMIs, and engineering workstations.

    What it does

    Evaluates SCADA Human-Machine Interface security across four assessment categories - authentication, communication security, web HMI vulnerabilities, and OS hardening - producing a structured findings report with IEC 62443 and NIST SP 800-82 compliance mapping. Works from HMI system inventory, authorised test environment access, optional network PCAP files, and HMI configuration JSON exports. Includes 21 structured checks (AUTH-01 to HARD-05) mapped to IEC 62443 SR references, a full HMISecurityAssessment class for guided manual walkthroughs, and an automated CLI agent for port scanning, PCAP protocol analysis, and configuration file review using only Python stdlib. Suited to OT security engineers, ICS assessors, and compliance teams preparing for IEC 62443 or NERC CIP audits in manufacturing, energy, and process industries. This is a working baseline skill, ready for use and modification to suit your specific use case as needed.

    Why use this skill

    • Safety-First Analysis: Built specifically for ICS/OT constraints, ensuring remediation plans respect operational availability.
    • Audit Readiness: Aligns findings with industry standards like IEC 62443, NIST SP 800-82, and NERC CIP.
    • Evidence-Based Reporting: Distinguishes between confirmed facts and evidence gaps, preventing "hallucinated" security conclusions.
    • Tool Agnostic: Adaptable to any HMI platform (Ignition, FactoryTalk, WinCC) or monitoring stack (SIEM/EDR) provided by the user.

    Structured Output

    The skill produces modular technical outputs including a detailed Findings Register, an Evidence Gap Analysis, and a Remediation Plan with prioritised risk treatment actions.

    Reviews

    No reviews yet - be the first to share your experience.

    Only users who have downloaded or purchased this skill can leave a review.

    Security Scanned

    Passed automated security review

    Permissions

    Terminal / Shell

    Allowed Hosts

    external domains: user-supplied target ip only (opt-in http credential check via --http-check flag) network access: tcp socket connections to user-supplied target on ics ports (102, 502, 44818, 20000, 1962, 2404). http connections via urllib.request to http://{target}:{port}/ only when --http-check flag is explicitly passed

    File Scopes

    performing-scada-hmi-security-assessment/**

    Works with any agent that supports the Universal SKILL.md Standard, including Claude Code, Codex CLI, Cursor, VS Code Copilot, Gemini CLI, OpenClaw, and 20+ compatible agents.

    Creator

    I design and publish skills built from real professional practice across three areas: cyber security consulting, business operations, and AI workflow engineering. My cyber security skills draw on active advisory work spanning governance, risk, compliance, assurance, and executive reporting. They are built for practitioners who need structured, defensible outputs - not generic templates. My business operations skills cover the day-to-day work of running a consulting practice: bookkeeping, financial tracking, expense reconciliation, and marketing content - designed to reduce repetitive overhead and keep outputs consistent. My AI platform and workflow skills are built for people who want to get more out of Claude and similar platforms - covering prompt engineering, skill architecture, automation pipelines, and agent enhancement. Every skill I publish has been tested in production use before it reaches the marketplace. If it is here, it works.

    Frequently Asked Questions

    More Premium Skills

    $20