PortKeep Port Security
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_15292d5a/yjkj-portkeep.
About this skill
Problem
In self-hosted environments, open ports are often a hidden security surface: nginx, databases, proxies, and short-lived APIs may listen on different nodes at the same time. Whether a port should be open, whether a service is involved in C2 traffic, and whether declared ports have drifted are usually hard to verify by hand. portkeep turns these questions into a repeatable port-governance workflow.
How It Works
- Scan and audit:
portkeep scandiscovers listening ports;portkeep auditevaluates threat intel, CVEs, and firewall posture, then reports scores and C2 matches. - Claims and drift:
portkeep claim 3000 "api"registers an expected port;portkeep driftcompares declared and actual ports, exiting with code1on drift for cron-friendly checks. - Threat intel: six sources work without API keys, including CISA-KEV, EPSS, Feodo Tracker, blocklist.de, Emerging Threats, and DShield/SANS; abuse.ch-based sources require
ABUSE_CH_AUTH_KEY. - Multi-node monitoring: add remote nodes with
node add, run background monitoring withdaemon start, and use--jsonor--quietfor automation.
Caveats
This fits ops teams with reachable nodes that want port exposure checks in CI or cron. It is not a full IDS/EDR replacement and does not perform application-layer vulnerability remediation.
Use Cases
- Before deploying a service, use `portkeep scan` and `audit` to review listening ports, C2 matches, and CVE exposure.
- Register port `3000` as an API claim, then use `claim next` to find the next available port and avoid conflicts.
- Run `drift` in `cron` so declared and actual port mismatches return a non-zero exit code for alerts.
- Add multiple remote nodes, start `daemon start` for background monitoring, and review port change history.
Best For
- Ops engineers maintaining self-hosted APIs and middleware who need open ports in routine audits.
- Security engineers reducing server exposure who want threat intel for C2 and CVE risk.
- Platform engineers managing multi-node SSH environments who need cross-machine port drift monitoring.
- SREs writing inspection scripts who want JSON output and exit codes for automation.
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.
Detects e-bikes and electric scooters in restricted areas from surveillance video or images, tallies violations, and triggers alerts.