IoTHackBot

A Claude Code plugin with skills and tools for authorized IoT pentesting: network recon, firmware analysis, hardware access and mobile app analysis

Plugin

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Includes offensive techniques: network probes, ONVIF credential brute-forcing and hardware access over JTAG, UART and telnet
  • Runs system tools and commands with network and physical access to devices, some under sudo
All reasons and checks

brownfinesecurity/iothackbot

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add plugins/iothackbot

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run one by one in the Claude Code chat

/plugin marketplace add brownfinesecurity/iothackbot
/plugin install iothackbot@iothackbot-marketplace

Checked against the repository on Sep 24, 2026, commit d443c40.

Text for your agent

Install dependencies: pip install colorama pyserial pexpect requests and system packages nmap, e2fsprogs, f2fs-tools. Clone https://github.com/BrownFineSecurity/iothackbot and start Claude Code with claude --plugin-dir /path/to/iothackbot, or add a local marketplace in ~/.claude/settings.json. Only work on devices you are authorized to test.

Other ways from the author
git clone https://github.com/BrownFineSecurity/iothackbot.git
claude --plugin-dir /path/to/iothackbot

Loads the plugin for the current session from a local copy. Install dependencies first: pip install colorama pyserial pexpect requests and system packages nmap, e2fsprogs, f2fs-tools.

This is third-party code. Review the repository files before installing.

What it does

The plugin gives Claude Code skills and command-line tools for security testing of IoT devices, IP cameras and embedded systems. It covers network recon with nmap, discovery of ONVIF cameras over WS-Discovery, traffic and network-flow analysis from pcap, ONVIF testing for weak authentication and credential brute-forcing, static analysis of UEFI and BIOS firmware through chipsec, file-type detection and filesystem extraction from firmware images, unpacking and decompiling Android apps through apktool and jadx, plus hardware work: a JTAG and SWD debug-interface probe via J-Link, UART console interaction and device telnet shell access. The tools are layered into CLI, core and binary and can be chained into pipelines. The toolkit targets authorized testing; credential brute-forcing and network probes touch third-party devices only with the owner's permission.

Who it is for. For embedded and IoT security professionals: pentesters, firmware researchers and hardware analysis engineers.

Good fit when

  • You need authorized recon of an IoT network and discovery of cameras and devices
  • You need to analyze firmware: identify files, extract the filesystem, check UEFI
  • You need to read data off hardware over JTAG, UART or telnet on your own bench

Not a fit when

  • You have no written permission from the owner to test the device or network
  • You need analysis without installing tools such as nmap, chipsec, J-Link and Android utilities

Example request

Scan my test subnet for ONVIF cameras and check the found devices for weak authentication

Limitations

The toolkit is intended only for authorized testing; the legality of use is on the user. The tools need Python and external packages (colorama, pyserial, pexpect, requests) and system tools such as nmap, e2fsprogs, f2fs-tools, JLinkExe. Hardware work requires a physical connection through J-Link or a serial port. Some operations must run with sudo. The README documents the CLI tools more than the plugin install, so some setup steps have to be reconstructed from the repository layout.

How to disable. Disable the iothackbot plugin in enabledPlugins in ~/.claude/settings.json and remove the marketplace, or delete the skill folders from the .claude directory. Remove the bin directory from PATH.

Security check

  • Includes offensive techniques: network probes, ONVIF credential brute-forcing and hardware access over JTAG, UART and telnet
  • Runs system tools and commands with network and physical access to devices, some under sudo

README in short

The README describes IoTHackBot as an open toolkit and set of Claude Code skills for security testing of IoT, IP cameras and embedded systems. The tools are grouped into network recon, device-specific testing, firmware and file analysis, Android analysis and hardware access over JTAG, UART and telnet. Installation adds dependencies via pip and system packages and puts the bin directory on PATH; as a Claude Code plugin the repo is loaded through claude --plugin-dir or a local marketplace in settings.json. Every tool is layered into CLI, core and binary for automation and pipelines. MIT license.

FAQ

Is this a legal tool?

Yes, for authorized testing, research and work on your own benches. ONVIF brute-forcing, network probes and hardware access apply to third-party devices only with the owner's written permission.

Is a physical connection required?

Not for the network and file skills, which work over the network and with firmware files. The JTAG, UART and telnet skills need physical access to the device via J-Link or a serial port.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIIoTHackBot

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.