Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add allsmog/blackbox-claude-pluginnpx agentmods add plugins/allsmog/blackbox-claude-plugin/blackbox-htbgit clone --depth 1 https://github.com/allsmog/blackbox-claude-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/allsmog/blackbox-claude-plugin/blackbox-htb)<a href="https://agentmods.dev/plugins/allsmog/blackbox-claude-plugin/blackbox-htb"><img src="https://agentmods.dev/badge/plugins/allsmog/blackbox-claude-plugin/blackbox-htb.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
blackbox-htb scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "blackbox-htb",
"version": "1.0.0",
"description": "Black-box and grey-box penetration testing plugin for HackTheBox machine challenges. Provides automated reconnaissance, enumeration, exploitation guidance, and privilege escalation for Linux, Windows, and Active Directory environments.",
"author": {
"name": "Shayaun Nejad",
"url": "https://github.com/allsmog"
},
"repository": "https://github.com/allsmog/blackbox-claude-plugin",
"license": "MIT",
"keywords": [
"HTB",
"HackTheBox",
"penetration-testing",
"black-box",
"grey-box",
"CTF",
"reconnaissance",
"enumeration",
"privilege-escalation",
"Active-Directory",
"nmap",
"crackmapexec",
"linpeas",
"winpeas"
]
}
What it installs
The manifest is a name and a version. 17 skills, 11 commands, 9 agents travel with it, and installing the plugin installs all of them — 2,590 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill cacti-exploitation A 53 tokens
- Skill Active Directory Attacks A 64 tokens
- Skill Common Exploits A 53 tokens
- Skill Web Application Enumeration A 58 tokens
- Skill CTF Writeup Lookup A 92 tokens
- Skill Erlang/OTP Exploitation A 86 tokens
- Skill Source Code Security Patterns A 33 tokens
- Skill php-type-juggling B 44 tokens
- Skill Network Reconnaissance B 51 tokens
- Skill Credential Attacks C 50 tokens
- Skill Windows Privilege Escalation C 65 tokens
- Skill container-escapes C 58 tokens
- Skill Database Credential Extraction C 45 tokens
- Skill FTP Server Exploitation C 72 tokens
- Skill Hash Cracking Workflow C 52 tokens
- Skill Password Hunting E 53 tokens
- Skill Linux Privilege Escalation F 61 tokens
- Command bb-ad A 44 tokens
- Command bb-enum A 33 tokens
- Command bb-setup A 28 tokens
- Command bb-crack A 31 tokens
- Command bb-spray B 9 tokens
- Command bb-web B 40 tokens
- Command bb-recon B 41 tokens
- Command blackbox B 45 tokens
- Command bb-container C 9 tokens
- Command bb-shell C 33 tokens
- Command bb-privesc E 39 tokens
- Agent exploit-suggester A 167 tokens
- Agent exploit-runner A 147 tokens
- Agent shell-manager A 141 tokens
- Agent source-analyzer A 67 tokens
- Agent network-scanner B 145 tokens
- Agent container-analyzer C 127 tokens
- Agent service-enumerator C 151 tokens
- Agent privesc-hunter D 169 tokens
- Agent credential-hunter E 134 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 28 lines scan A 6aef774e6ea6
blackbox-htb is a plugin published in the GitHub repository allsmog/blackbox-claude-plugin (5 stars, last pushed 6mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other plugins, from other repositories
pentest
Full penetration testing framework - 63 attack categories across 11 domains covering OWASP, injection, authentication, cloud, and more.
pownie
Offensive security toolkit for Claude Code — Neo4j intel graph, strategic compaction, multi-agent orchestration, and post-engagement debriefs.
elliot
Elliot — offensive security engagement plugin with Hexstrike MCP integration for Kali Linux. Provides slash commands, auto-activating skills, and subagents for systematic penetration testing workflows.
trenton
Trenton — operational security plugin with Hexstrike MCP integration for Kali Linux. Machine hardening, VPS security, anti-forensics, and footprint elimination.
tyrell
Tyrell — leak database hunter plugin with Hexstrike MCP integration for Kali Linux. Exposed database discovery, data acquisition, cross-plugin pipeline to elliot.
fsociety
fsociety — engagement workspace setup and cross-plugin orchestration. Interactive /setup wizard for targets, goals, scope, and plugin selection.