pwnclaw-security-scanTest your AI agent for security vulnerabilities using PwnClaw. Runs 50+ attacks (prompt injection, jailbreaks, social engineering, MCP poisoning, and more) and provides fix instructions. Use when your agent needs a security check or hardening.
Install via ClawdBot CLI:
clawdbot install Gemini2027/pwnclaw-security-scanTest your AI agent against 112 real-world attacks across 14 categories. Get a security score and actionable fix instructions.
Ask your human to visit https://www.pwnclaw.com and run a free security scan:
If your human starts a test and gives you the test token, you can run it yourself:
https://www.pwnclaw.com/api/test/{token} → get the next prompthttps://www.pwnclaw.com/api/test/{token} with { "response": "your answer" } → submit and get nextIf your agent has an HTTP endpoint, your human just enters the URL in PwnClaw. PwnClaw sends attacks directly — no scripting needed.
| Plan | Scans | Attacks | Price |
|------|-------|---------|-------|
| Free | 3/month | 15 per scan | $0 |
| Pro | 30/month | 50 per scan | €29/mo |
| Team | Unlimited | 50 per scan | €99/mo |
PwnClaw generates specific security rules based on your vulnerabilities. Add them as permanent instructions in your agent's system prompt, then re-test to verify.
Generated Mar 1, 2026
A company deploys an AI agent for customer support handling sensitive data like account details and payment information. They use PwnClaw to test for vulnerabilities like prompt injection and data exfiltration to prevent breaches and ensure compliance with data protection regulations.
A healthcare provider integrates an AI assistant to help patients with medical queries and appointment scheduling. Running PwnClaw scans checks for social engineering and jailbreak attacks to safeguard patient privacy and maintain trust in the healthcare system.
An educational platform uses an AI tutor to interact with students and provide learning materials. They employ PwnClaw to detect vulnerabilities like MCP poisoning and refusal bypass, ensuring the agent remains safe and educational without exposing students to harmful content.
A large enterprise automates internal workflows with AI agents handling tasks like document processing and communication. PwnClaw is used to test for multi-agent attacks and privilege escalation to secure corporate data and prevent operational disruptions.
Offers a free tier with limited scans to attract individual developers and small teams, then upsells to Pro and Team plans for higher volume and advanced features. Revenue comes from monthly subscriptions, with pricing in euros to target European and global markets.
Provides customized security audits and hardening services for large organizations, leveraging PwnClaw's automated scans as a tool. Revenue is generated through project-based contracts and ongoing support, focusing on industries with high security needs like finance and healthcare.
Maintains the tool as open-source on GitHub for transparency and community trust, while monetizing through premium support, training, and integration services. This model builds credibility and drives adoption among tech-savvy users who value auditability.
💬 Integration Tip
For quick setup, use the automatic mode by providing your agent's HTTP endpoint in the PwnClaw dashboard, which requires no coding and is ideal for beginners.
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities across the system. Use when user asks to "run security check", "audit clawdbot", "check security hardening", or "what vulnerabilities does my Clawdbot have". This skill uses Clawdbot's internal capabilities and file system access to inspect configuration, detect misconfigurations, and recommend remediations. It is designed to be extensible - new checks can be added by updating this skill's knowledge.
Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.
Security check for ClawHub skills powered by Koi. Query the Clawdex API before installing any skill to verify it's safe.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.