AI Agent Hub
Back to skills
PortKeep Port Security icon

PortKeep Port Security

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md to install @user_15292d5a/yjkj-portkeep.

About this skill

Problem

In self-hosted environments, open ports are often a hidden security surface: nginx, databases, proxies, and short-lived APIs may listen on different nodes at the same time. Whether a port should be open, whether a service is involved in C2 traffic, and whether declared ports have drifted are usually hard to verify by hand. portkeep turns these questions into a repeatable port-governance workflow.

How It Works

  • Scan and audit: portkeep scan discovers listening ports; portkeep audit evaluates threat intel, CVEs, and firewall posture, then reports scores and C2 matches.
  • Claims and drift: portkeep claim 3000 "api" registers an expected port; portkeep drift compares declared and actual ports, exiting with code 1 on drift for cron-friendly checks.
  • Threat intel: six sources work without API keys, including CISA-KEV, EPSS, Feodo Tracker, blocklist.de, Emerging Threats, and DShield/SANS; abuse.ch-based sources require ABUSE_CH_AUTH_KEY.
  • Multi-node monitoring: add remote nodes with node add, run background monitoring with daemon start, and use --json or --quiet for automation.

Caveats

This fits ops teams with reachable nodes that want port exposure checks in CI or cron. It is not a full IDS/EDR replacement and does not perform application-layer vulnerability remediation.

Use Cases

  • Before deploying a service, use `portkeep scan` and `audit` to review listening ports, C2 matches, and CVE exposure.
  • Register port `3000` as an API claim, then use `claim next` to find the next available port and avoid conflicts.
  • Run `drift` in `cron` so declared and actual port mismatches return a non-zero exit code for alerts.
  • Add multiple remote nodes, start `daemon start` for background monitoring, and review port change history.

Best For

  • Ops engineers maintaining self-hosted APIs and middleware who need open ports in routine audits.
  • Security engineers reducing server exposure who want threat intel for C2 and CVE risk.
  • Platform engineers managing multi-node SSH environments who need cross-machine port drift monitoring.
  • SREs writing inspection scripts who want JSON output and exit codes for automation.