Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/allsmog/pwn-claude-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/allsmog/pwn-claude-plugin/pwn-recon)<a href="https://agentmods.dev/commands/allsmog/pwn-claude-plugin/pwn-recon"><img src="https://agentmods.dev/badge/commands/allsmog/pwn-claude-plugin/pwn-recon/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/allsmog/pwn-claude-plugin/pwn-recon"><img src="https://agentmods.dev/badge/commands/allsmog/pwn-claude-plugin/pwn-recon.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00021 | $0.00612 |
| Opus 5 | $0.00010 | $0.00306 |
| Sonnet 5 | $0.00004 | $0.00122 |
| Haiku 4.5 | $0.00002 | $0.00061 |
Grade A, and why
pwn-recon scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
PWN Recon - Binary Reconnaissance
Execute the reconnaissance phase on a target binary to gather essential information before exploitation.
Execution Steps
Step 1: Validate Binary
file <binary>
Verify binary exists and is an ELF executable.
Step 2: Check Protections
checksec --file=<binary>
Or via Python if checksec not available:
python3 -c "from pwn import *; print(ELF('<binary>').checksec())"
Document all protections: RELRO, Canary, NX, PIE, FORTIFY.
Step 3: Extract Strings
strings -n 8 <binary> | head -50
strings <binary> | grep -iE '(flag|password|secret|admin|shell|/bin|system)'
Step 4: Analyze Symbols
# If not stripped
nm <binary> 2>/dev/null | grep -E ' [TtWw] ' | head -30
# Check for win functions
nm <binary> 2>/dev/null | grep -iE '(win|flag|shell|backdoor)'
# PLT entries
objdump -d <binary> | grep '@plt>:' | head -20
Step 5: Check for Seccomp
seccomp-tools dump <binary> 2>/dev/null || echo "No seccomp or seccomp-tools not installed"
Output Format
## Reconnaissance
### Findings
- Architecture: ELF 64-bit LSB executable, x86-64
- Linking: dynamically linked
- Stripped: No (symbols available)
- Protections:
- RELRO: Partial
- Stack Canary: No
- NX: Enabled
- PIE: Disabled
- Interesting strings: "/bin/sh", "flag.txt"
- Key symbols: main, vuln, win
- Dangerous PLT: gets@plt, printf@plt
### Commands Run
- `file ./binary` → ELF 64-bit LSB executable...
- `checksec --file=./binary` → [output]
- `strings ./binary | grep flag` → flag.txt
### Implications
- No PIE: Fixed addresses for ROP
- No Canary: Direct buffer overflow possible
- NX enabled: Cannot execute stack shellcode
- gets@plt: Likely buffer overflow vector
- win function: Possible ret2win target
### Next Steps
1. Disassemble vuln() to find buffer size
2. Disassemble win() to understand requirements
3. Calculate offset to return address
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 97 lines · 21 tokens per session scan A 7770d0f1f819
pwn-recon is a command published in the GitHub repository allsmog/pwn-claude-plugin (2 stars, last pushed 6mo ago), licensed MIT. It adds 21 tokens to every session and 612 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
bb-ad
Active Directory enumeration and attack techniques. Includes LDAP enumeration, Kerberos attacks (Kerberoasting, AS-REP Roasting), SMB attacks, and domain privilege escalation. Use this when targeting Windows domain environments.
bb-enum
Service-specific enumeration based on discovered ports. Automatically selects appropriate enumeration techniques for each service. Use after /bb-recon to deeply enumerate discovered services.
bb-crack
Crack password hashes with automatic type detection and wordlist discovery. Supports MD5, SHA, NTLM, bcrypt, and more.
bb-setup
Verify penetration testing environment and tool installation. Use this before starting an HTB machine to ensure all required tools are available.
bb-spray
Credential spraying across discovered services.
bb-web
Comprehensive web application testing for HTTP/HTTPS services. Includes directory fuzzing, vulnerability scanning, technology fingerprinting, and common exploit checks. Use this when a web service is discovered.