Pilot Penetration Testing Setup
/install pilot-penetration-testing-setup
Penetration Testing Setup
Deploy 4 agents that perform recon, scan vulnerabilities, validate exploits, and generate reports.
Roles
| Role | Hostname | Skills | Purpose |
|---|---|---|---|
| recon | \x3Cprefix>-recon |
pilot-discover, pilot-stream-data, pilot-archive | DNS enumeration, port scanning, service fingerprinting |
| scanner | \x3Cprefix>-scanner |
pilot-task-parallel, pilot-metrics, pilot-dataset | Vulnerability scans, CVE checks, misconfiguration detection |
| exploiter | \x3Cprefix>-exploiter |
pilot-task-chain, pilot-audit-log, pilot-receipt | Safe proof-of-concept validation, exploitability confirmation |
| reporter | \x3Cprefix>-reporter |
pilot-webhook-bridge, pilot-share, pilot-slack-bridge | Report generation with findings, risk ratings, remediation |
Setup Procedure
Step 1: Ask the user which role this agent should play and what prefix to use.
Step 2: Install the skills for the chosen role:
# For recon:
clawhub install pilot-discover pilot-stream-data pilot-archive
# For scanner:
clawhub install pilot-task-parallel pilot-metrics pilot-dataset
# For exploiter:
clawhub install pilot-task-chain pilot-audit-log pilot-receipt
# For reporter:
clawhub install pilot-webhook-bridge pilot-share pilot-slack-bridge
Step 3: Set the hostname:
pilotctl --json set-hostname \x3Cprefix>-\x3Crole>
Step 4: Write the setup manifest:
mkdir -p ~/.pilot/setups
cat > ~/.pilot/setups/penetration-testing.json \x3C\x3C 'MANIFEST'
\x3CINSERT ROLE MANIFEST FROM BELOW>
MANIFEST
Step 5: Tell the user to initiate handshakes with direct communication peers.
Manifest Templates Per Role
recon
{
"setup": "penetration-testing", "setup_name": "Penetration Testing",
"role": "recon", "role_name": "Reconnaissance Agent",
"hostname": "\x3Cprefix>-recon",
"description": "Performs passive and active reconnaissance — DNS enumeration, port scanning, service fingerprinting.",
"skills": {
"pilot-discover": "Enumerate DNS records, subdomains, and service endpoints.",
"pilot-stream-data": "Stream port scan results and fingerprints in real time.",
"pilot-archive": "Archive recon snapshots for baseline comparison."
},
"peers": [{"role": "scanner", "hostname": "\x3Cprefix>-scanner", "description": "Receives recon results for vulnerability scanning"}],
"data_flows": [{"direction": "send", "peer": "\x3Cprefix>-scanner", "port": 1002, "topic": "recon-result", "description": "Recon results with target profile and services"}],
"handshakes_needed": ["\x3Cprefix>-scanner"]
}
scanner
{
"setup": "penetration-testing", "setup_name": "Penetration Testing",
"role": "scanner", "role_name": "Vulnerability Scanner",
"hostname": "\x3Cprefix>-scanner",
"description": "Runs automated vulnerability scans, checks CVE databases, identifies misconfigurations.",
"skills": {
"pilot-task-parallel": "Run multiple scan tools in parallel across target services.",
"pilot-metrics": "Track scan coverage, finding counts, and severity distribution.",
"pilot-dataset": "Store CVE matches and vulnerability metadata."
},
"peers": [{"role": "recon", "hostname": "\x3Cprefix>-recon", "description": "Sends recon results"}, {"role": "exploiter", "hostname": "\x3Cprefix>-exploiter", "description": "Receives vulnerability findings"}],
"data_flows": [
{"direction": "receive", "peer": "\x3Cprefix>-recon", "port": 1002, "topic": "recon-result", "description": "Recon results with target profile and services"},
{"direction": "send", "peer": "\x3Cprefix>-exploiter", "port": 1002, "topic": "vulnerability", "description": "Vulnerability findings with CVE and severity"}
],
"handshakes_needed": ["\x3Cprefix>-recon", "\x3Cprefix>-exploiter"]
}
exploiter
{
"setup": "penetration-testing", "setup_name": "Penetration Testing",
"role": "exploiter", "role_name": "Exploit Validator",
"hostname": "\x3Cprefix>-exploiter",
"description": "Validates discovered vulnerabilities with safe proof-of-concept tests, confirms exploitability.",
"skills": {
"pilot-task-chain": "Chain validation steps: verify, exploit, document evidence.",
"pilot-audit-log": "Log all validation attempts with timestamps and results.",
"pilot-receipt": "Confirm receipt of vulnerability findings from scanner."
},
"peers": [{"role": "scanner", "hostname": "\x3Cprefix>-scanner", "description": "Sends vulnerability findings"}, {"role": "reporter", "hostname": "\x3Cprefix>-reporter", "description": "Receives validated findings"}],
"data_flows": [
{"direction": "receive", "peer": "\x3Cprefix>-scanner", "port": 1002, "topic": "vulnerability", "description": "Vulnerability findings with CVE and severity"},
{"direction": "send", "peer": "\x3Cprefix>-reporter", "port": 1002, "topic": "validated-finding", "description": "Validated findings with proof-of-concept evidence"}
],
"handshakes_needed": ["\x3Cprefix>-scanner", "\x3Cprefix>-reporter"]
}
reporter
{
"setup": "penetration-testing", "setup_name": "Penetration Testing",
"role": "reporter", "role_name": "Pentest Reporter",
"hostname": "\x3Cprefix>-reporter",
"description": "Generates pentest reports with findings, risk ratings, remediation steps, and executive summary.",
"skills": {
"pilot-webhook-bridge": "Deliver reports to client portals and ticketing systems.",
"pilot-share": "Share report drafts with stakeholders for review.",
"pilot-slack-bridge": "Notify security team of completed assessments."
},
"peers": [{"role": "exploiter", "hostname": "\x3Cprefix>-exploiter", "description": "Sends validated findings with evidence"}],
"data_flows": [
{"direction": "receive", "peer": "\x3Cprefix>-exploiter", "port": 1002, "topic": "validated-finding", "description": "Validated findings with proof-of-concept evidence"},
{"direction": "send", "peer": "external", "port": 443, "topic": "pentest-report", "description": "Pentest report via webhook and Slack"}
],
"handshakes_needed": ["\x3Cprefix>-exploiter"]
}
Data Flows
recon -> scanner: recon-result events (port 1002)scanner -> exploiter: vulnerability events (port 1002)exploiter -> reporter: validated-finding events (port 1002)reporter -> external: pentest-report via webhook (port 443)
Handshakes
# recon \x3C-> scanner:
pilotctl --json handshake \x3Cprefix>-scanner "setup: penetration-testing"
pilotctl --json handshake \x3Cprefix>-recon "setup: penetration-testing"
# scanner \x3C-> exploiter:
pilotctl --json handshake \x3Cprefix>-exploiter "setup: penetration-testing"
pilotctl --json handshake \x3Cprefix>-scanner "setup: penetration-testing"
# exploiter \x3C-> reporter:
pilotctl --json handshake \x3Cprefix>-reporter "setup: penetration-testing"
pilotctl --json handshake \x3Cprefix>-exploiter "setup: penetration-testing"
Workflow Example
# On scanner — subscribe to recon results:
pilotctl --json subscribe \x3Cprefix>-recon recon-result
# On exploiter — subscribe to vulnerabilities:
pilotctl --json subscribe \x3Cprefix>-scanner vulnerability
# On reporter — subscribe to validated findings:
pilotctl --json subscribe \x3Cprefix>-exploiter validated-finding
# On recon — publish a recon result:
pilotctl --json publish \x3Cprefix>-scanner recon-result '{"target":"app.example.com","open_ports":[22,80,443,8080]}'
# On exploiter — publish a validated finding:
pilotctl --json publish \x3Cprefix>-reporter validated-finding '{"cve":"CVE-2023-46589","validated":true,"impact":"RCE"}'
Dependencies
Requires pilot-protocol skill, pilotctl binary, clawhub binary, and a running daemon.
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install pilot-penetration-testing-setup - 安装完成后,直接呼叫该 Skill 的名称或使用
/pilot-penetration-testing-setup触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
Pilot Penetration Testing Setup 是什么?
Deploy an automated penetration testing pipeline with 4 agents. Use this skill when: 1. User wants to set up a penetration testing or security assessment pip... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 72 次。
如何安装 Pilot Penetration Testing Setup?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install pilot-penetration-testing-setup」即可一键安装,无需额外配置。
Pilot Penetration Testing Setup 是免费的吗?
是的,Pilot Penetration Testing Setup 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Pilot Penetration Testing Setup 支持哪些平台?
Pilot Penetration Testing Setup 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Pilot Penetration Testing Setup?
由 Calin Teodor(@teoslayer)开发并维护,当前版本 v1.0.0。