
scada-hmi-security-assessment
by LocoLoboZ
Perform evidence-based security assessments and compliance audits for SCADA/HMI systems in OT environments.
- Generate audit-ready security reports for ICS/SCADA human-machine interfaces.
- Map HMI configuration vulnerabilities to IEC 62443 or NIST SP 800-82 standards.
- Identify evidence gaps in OT network architecture and access control logs.
Secure checkout via Stripe
Included in download
- Generate audit-ready security reports for ICS/SCADA human-machine interfaces.
- Map HMI configuration vulnerabilities to IEC 62443 or NIST SP 800-82 standards.
- terminal automation included
- Ready for including Claude Code
See it in action
A real example of what this skill takes in and produces.
Sample input
We need to assess our plant web-based HMI running on the OT network before an IEC 62443 audit. The HMI is isolated in a test environment. Run the full assessment covering authentication, communication, web security, and hardening checks, and produce a structured report.
Sample output
The skill produces a structured assessment output with 21 checks across four categories, each labelled with its check ID, name, IEC 62443 SR reference, and test procedure. The automated agent scans for open SCADA protocol ports, analyses any supplied PCAP for insecure protocols, and reviews an HMI configuration file for disabled authentication, missing session timeouts, and absent TLS. The final report includes a findings register with severity ratings (Critical, High, Medium), a category-level pass/fail summary, and an IEC 62443 Security Level Achieved versus Target comparison.
Perform evidence-based security assessments and compliance audits for SCADA/HMI systems in OT environments.
Secure checkout via Stripe
Also available in a bundle
Included in download
- Generate audit-ready security reports for ICS/SCADA human-machine interfaces.
- Map HMI configuration vulnerabilities to IEC 62443 or NIST SP 800-82 standards.
- terminal automation included
- Ready for including Claude Code
- Instant install
See it in action
A real example of what this skill takes in and produces.
Sample input
We need to assess our plant web-based HMI running on the OT network before an IEC 62443 audit. The HMI is isolated in a test environment. Run the full assessment covering authentication, communication, web security, and hardening checks, and produce a structured report.
Sample output
The skill produces a structured assessment output with 21 checks across four categories, each labelled with its check ID, name, IEC 62443 SR reference, and test procedure. The automated agent scans for open SCADA protocol ports, analyses any supplied PCAP for insecure protocols, and reviews an HMI configuration file for disabled authentication, missing session timeouts, and absent TLS. The final report includes a findings register with severity ratings (Critical, High, Medium), a category-level pass/fail summary, and an IEC 62443 Security Level Achieved versus Target comparison.
About This Skill
Professional Security Auditing for SCADA & HMI Systems
Maintaining security in Operational Technology (OT) environments is critical but complex. This skill provides a structured, developer-centric framework for conducting evidence-based security assessments of SCADA systems, HMIs, and engineering workstations.
What it does
Evaluates SCADA Human-Machine Interface security across four assessment categories - authentication, communication security, web HMI vulnerabilities, and OS hardening - producing a structured findings report with IEC 62443 and NIST SP 800-82 compliance mapping. Works from HMI system inventory, authorised test environment access, optional network PCAP files, and HMI configuration JSON exports. Includes 21 structured checks (AUTH-01 to HARD-05) mapped to IEC 62443 SR references, a full HMISecurityAssessment class for guided manual walkthroughs, and an automated CLI agent for port scanning, PCAP protocol analysis, and configuration file review using only Python stdlib. Suited to OT security engineers, ICS assessors, and compliance teams preparing for IEC 62443 or NERC CIP audits in manufacturing, energy, and process industries. This is a working baseline skill, ready for use and modification to suit your specific use case as needed.
Why use this skill
- Safety-First Analysis: Built specifically for ICS/OT constraints, ensuring remediation plans respect operational availability.
- Audit Readiness: Aligns findings with industry standards like IEC 62443, NIST SP 800-82, and NERC CIP.
- Evidence-Based Reporting: Distinguishes between confirmed facts and evidence gaps, preventing "hallucinated" security conclusions.
- Tool Agnostic: Adaptable to any HMI platform (Ignition, FactoryTalk, WinCC) or monitoring stack (SIEM/EDR) provided by the user.
Structured Output
The skill produces modular technical outputs including a detailed Findings Register, an Evidence Gap Analysis, and a Remediation Plan with prioritised risk treatment actions.
Use Cases
- Generate audit-ready security reports for ICS/SCADA human-machine interfaces.
- Map HMI configuration vulnerabilities to IEC 62443 or NIST SP 800-82 standards.
- Identify evidence gaps in OT network architecture and access control logs.
- Create safe, OT-specific remediation plans that prioritize system availability.
- Run a structured IEC 62443-aligned security assessment of a web-based SCADA HMI before a compliance audit
- Use the automated agent to scan HMI network ports and analyse PCAP traffic for insecure SCADA protocols
- Audit HMI authentication configuration for default credentials, missing lockout policies, and absent MFA
How to Install
mkdir -p ~/.claude/skills && curl -sL https://www.agensi.io/api/install/scada-hmi-security-assessment | tar xz -C ~/.claude/skills/Free skills install directly. Paid skills require purchase - use the download button above after buying.
Reviews
No reviews yet - be the first to share your experience.
Only users who have downloaded or purchased this skill can leave a review.
Early access skill
Be the first to review this skill.
Only users who have downloaded or purchased this skill can leave a review.
Security Scanned
Passed automated security review
Permissions
Allowed Hosts
File Scopes
Tags
Works with any agent that supports the Universal SKILL.md Standard, including Claude Code, Codex CLI, Cursor, VS Code Copilot, Gemini CLI, OpenClaw, and 20+ compatible agents.
Creator
I design and publish skills built from real professional practice across three areas: cyber security consulting, business operations, and AI workflow engineering. My cyber security skills draw on active advisory work spanning governance, risk, compliance, assurance, and executive reporting. They are built for practitioners who need structured, defensible outputs - not generic templates. My business operations skills cover the day-to-day work of running a consulting practice: bookkeeping, financial tracking, expense reconciliation, and marketing content - designed to reduce repetitive overhead and keep outputs consistent. My AI platform and workflow skills are built for people who want to get more out of Claude and similar platforms - covering prompt engineering, skill architecture, automation pipelines, and agent enhancement. Every skill I publish has been tested in production use before it reaches the marketplace. If it is here, it works.
Also available in a bundle
Frequently Asked Questions
Learn More About AI Agent Skills
More Premium Skills
designing-hybrid-context-layers
Architects the right retrieval strategy for every query — teaching your agent when to use RAG, a knowledge graph, or a temporal index instead of defaulting to vector search for everything.
consumer-motivation-analyzer
Go beyond surface-level feedback to uncover the psychological drivers and hidden motivations behind buyer behavior.
Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
keyword-research
Transform URLs or product lists into SEO keyword research packs with Google Ads data and intent-based clustering.