Local Nmap
local_nmapScans a target host or CIDR block for open TCP ports using nmap's connect scan, without requiring admin privileges. Reports only open ports; supports custom port ranges.
Instructions
Run an nmap TCP connect scan on a target.
Uses TCP connect scan (-sT, no admin needed) with host discovery skipped (-Pn) and reports only open ports. SYN scans and OS detection require root and are not used. Nmap must be installed separately.
Targets are limited to one host or a CIDR block of at most 256 addresses (/24 for IPv4, /120 for IPv6): with -Pn nmap probes every address in the block, so a larger prefix would exhaust the 120 s time budget without finishing. nmap's octet-range (10.0.0-255.1), wildcard and comma-list target syntax is rejected for the same reason; scan several small blocks instead. Rejected inputs are reported in the result's error field.
Disabled by default (it can scan arbitrary internal hosts from this machine). Enable via allow_active_tools in config.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ports | No | Port spec: comma-separated ports and/or ranges, e.g. '22,80,443' or '1-1024'. Default scans nmap's top 1000 ports. | |
| target | Yes | One IP address, one hostname, or a CIDR block of at most /24 (IPv4) or /120 (IPv6) |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| note | No | Additional context about the result | |
| error | No | Why the tool could not produce a result: input validation failure, tool disabled by configuration, binary not installed, or no service answered. Empty when the command executed. | |
| stderr | Yes | Standard error of the command, or the failure message when the command did not run | |
| stdout | Yes | Standard output of the command (curl output is capped at 10,000 characters) | |
| command | Yes | The exact command line that was executed, or the tool name if the command never ran | |
| success | Yes | True when the command ran and exited with status 0 | |
| platform | Yes | Operating system the command ran on (Darwin, Linux or Windows) | |
| returncode | Yes | Process exit status. 0 = success; 2 = input rejected before running; 124 = timed out; 126 = disabled by config or permission denied; 127 = binary not found |