IoTHackBot
A Claude Code plugin with skills and tools for authorized IoT pentesting: network recon, firmware analysis, hardware access and mobile app analysis
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Includes offensive techniques: network probes, ONVIF credential brute-forcing and hardware access over JTAG, UART and telnet
- Runs system tools and commands with network and physical access to devices, some under sudo
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add plugins/iothackbotDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run one by one in the Claude Code chat
/plugin marketplace add brownfinesecurity/iothackbot
/plugin install iothackbot@iothackbot-marketplaceInstall dependencies: pip install colorama pyserial pexpect requests and system packages nmap, e2fsprogs, f2fs-tools. Clone https://github.com/BrownFineSecurity/iothackbot and start Claude Code with claude --plugin-dir /path/to/iothackbot, or add a local marketplace in ~/.claude/settings.json. Only work on devices you are authorized to test.
Other ways from the author
git clone https://github.com/BrownFineSecurity/iothackbot.git
claude --plugin-dir /path/to/iothackbotLoads the plugin for the current session from a local copy. Install dependencies first: pip install colorama pyserial pexpect requests and system packages nmap, e2fsprogs, f2fs-tools.
This is third-party code. Review the repository files before installing.
What it does
The plugin gives Claude Code skills and command-line tools for security testing of IoT devices, IP cameras and embedded systems. It covers network recon with nmap, discovery of ONVIF cameras over WS-Discovery, traffic and network-flow analysis from pcap, ONVIF testing for weak authentication and credential brute-forcing, static analysis of UEFI and BIOS firmware through chipsec, file-type detection and filesystem extraction from firmware images, unpacking and decompiling Android apps through apktool and jadx, plus hardware work: a JTAG and SWD debug-interface probe via J-Link, UART console interaction and device telnet shell access. The tools are layered into CLI, core and binary and can be chained into pipelines. The toolkit targets authorized testing; credential brute-forcing and network probes touch third-party devices only with the owner's permission.
Who it is for. For embedded and IoT security professionals: pentesters, firmware researchers and hardware analysis engineers.
Good fit when
- You need authorized recon of an IoT network and discovery of cameras and devices
- You need to analyze firmware: identify files, extract the filesystem, check UEFI
- You need to read data off hardware over JTAG, UART or telnet on your own bench
Not a fit when
- You have no written permission from the owner to test the device or network
- You need analysis without installing tools such as nmap, chipsec, J-Link and Android utilities
Example request
Scan my test subnet for ONVIF cameras and check the found devices for weak authenticationLimitations
The toolkit is intended only for authorized testing; the legality of use is on the user. The tools need Python and external packages (colorama, pyserial, pexpect, requests) and system tools such as nmap, e2fsprogs, f2fs-tools, JLinkExe. Hardware work requires a physical connection through J-Link or a serial port. Some operations must run with sudo. The README documents the CLI tools more than the plugin install, so some setup steps have to be reconstructed from the repository layout.
How to disable. Disable the iothackbot plugin in enabledPlugins in ~/.claude/settings.json and remove the marketplace, or delete the skill folders from the .claude directory. Remove the bin directory from PATH.
Security check
- Includes offensive techniques: network probes, ONVIF credential brute-forcing and hardware access over JTAG, UART and telnet
- Runs system tools and commands with network and physical access to devices, some under sudo
README in short
The README describes IoTHackBot as an open toolkit and set of Claude Code skills for security testing of IoT, IP cameras and embedded systems. The tools are grouped into network recon, device-specific testing, firmware and file analysis, Android analysis and hardware access over JTAG, UART and telnet. Installation adds dependencies via pip and system packages and puts the bin directory on PATH; as a Claude Code plugin the repo is loaded through claude --plugin-dir or a local marketplace in settings.json. Every tool is layered into CLI, core and binary for automation and pipelines. MIT license.
FAQ
Is this a legal tool?
Yes, for authorized testing, research and work on your own benches. ONVIF brute-forcing, network probes and hardware access apply to third-party devices only with the owner's written permission.
Is a physical connection required?
Not for the network and file skills, which work over the network and with firmware files. The JTAG, UART and telnet skills need physical access to the device via J-Link or a serial port.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents