hackingtool plugin
hackingtool - Claude Code plugin
A Claude Code plugin wrapping 183 pentest and OSINT tools from Z4nzu/hackingtool, running them locally via Bash, WSL or Docker
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Runs pentest tools and network attacks on hosts, including scanners, exploits and secret handling
- Many commands need elevated privileges and act on real targets; use only with written authorization
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add plugins/hackingtool-claude-code-pluginDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run one by one in the Claude Code chat
/plugin marketplace add akcodez/hackingtool-plugin
/plugin install hackingtool@hackingtool-marketplaceInstall the plugin: /plugin marketplace add AKCODEZ/hackingtool-plugin, then /plugin install hackingtool@hackingtool-marketplace. Before work run ht_preflight.py and confirm the backend is ready.
Other ways from the author
/plugin marketplace add AKCODEZ/hackingtool-plugin
/plugin install hackingtool@hackingtool-marketplaceAfter install, ask for recon or a scan; tools run through ht_run.py.
This is third-party code. Review the repository files before installing.
What it does
The plugin gives Claude Code a single skill backed by 183 pentest and OSINT tools drawn from the Z4nzu/hackingtool project: nmap, subfinder, httpx, nuclei, amass, holehe, maigret, trufflehog, sqlmap, impacket and more. Every call goes through the ht_run.py script, which picks a backend on its own, native Bash on Linux and macOS, WSL on Windows, or purpose-built Docker images, and returns output as structured JSON. Before work it runs ht_preflight.py to check what is available and recommend what to install. For a request such as domain recon or a username check, the agent picks a chain of tools and runs it. Tools are grouped by category: information gathering, port and vulnerability scanning, web attacks, SQL injection, secrets, Active Directory, forensics and others.
Who it is for. For security professionals and pentesters running authorized testing and OSINT from Claude Code.
Good fit when
- You need domain recon: subdomain enumeration, port scanning, web vulnerability checks
- You need OSINT on a username or email via holehe, maigret and similar
- You need to scan a repository or files for leaked secrets
Not a fit when
- You have no written authorization to test the target
- You cannot install Docker, WSL or security tools on the working machine
Example request
Run recon on example.com, which I am authorized to testLimitations
The plugin is intended only for authorized testing, bug bounty, CTF and research; responsibility for the legality of use rests with the user. It needs Python 3.10 or newer, and tools run natively, through WSL, or through Docker, with the Docker backend pulling kalilinux/kali-rolling on first use. Long-running tools block until they finish or time out. Tool readiness flags are heuristic, and some tools need sudo or manual environment setup.
How to disable. Remove the hackingtool plugin via /plugin, then optionally detach the hackingtool-marketplace. Pulled Docker images are removed with Docker's own tools.
Security check
- Runs pentest tools and network attacks on hosts, including scanners, exploits and secret handling
- Many commands need elevated privileges and act on real targets; use only with written authorization
README in short
The README describes a Claude Code plugin that wraps 183 pentest and OSINT tools from the Z4nzu/hackingtool project into a single skill. The ht_run.py script picks a backend, native Bash, WSL or Docker, maps known tools to purpose-built images and returns JSON output, while ht_preflight.py checks the environment. Tools are grouped into more than twenty categories, from information gathering and scanning to web attacks, forensics and Active Directory, with readiness flags. The plugin installs via the hackingtool-marketplace. MIT licensed, like the upstream Z4nzu/hackingtool.
FAQ
Is this legal?
The plugin targets authorized testing, bug bounty, CTF and research. Testing targets you do not own without written authorization is not allowed, and responsibility for use rests with the user.
Do I have to install all 183 tools?
No. Through ht_run.py the plugin picks and runs the specific tool for the task, pulling images and binaries as needed.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents