What problem does it solve? Assessing industrial control systems is dangerous without a disciplined methodology: an unauthorized write to a PLC or a high-rate scan of a production OT network can cause physical harm. This Skill enforces a safe, passive-first, authorization-gated workflow for OT/ICS security assessments. ## Core Features & Use Cases - Purdue Model Zoning: Maps assets across Purdue levels L0-L5, covering PLCs, RTUs, HMIs, engineering stations, historians, and jump hosts. - Passive-First Protocol Discovery: Identifies Modbus, DNP3, S7comm, and EtherNet/IP exposure via traffic mirroring and read-only checks before any active probing. - Safety Guardrails: Hard rules against writing coils/registers, fast scanning of production OT, or touching SIS paths without explicit written authorization. - Use Case: During an authorized assessment of a manufacturing plant, use this Skill to build an asset inventory from mirrored traffic, audit offline TIA/RSLogix configurations, and document findings with physical-impact context. ## Quick Start Use the ot-ics skill to plan a passive-first security assessment of the authorized SCADA network segment and identify exposed industrial protocols.