{"_id":"@ellistevo/openclaw-pentest","name":"@ellistevo/openclaw-pentest","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@ellistevo/openclaw-pentest","version":"1.0.0","description":"AI-driven penetration testing CLI - point it at your app and it tries to break in","main":"src/index.js","bin":{"openclaw-pentest":"src/cli.js"},"scripts":{"start":"node src/cli.js","test":"node src/cli.js --help"},"keywords":["penetration-testing","security","pentest","xss","sqli","openclaw","ai-security"],"author":{"name":"ellistevo"},"license":"MIT","dependencies":{"chalk":"^4.1.2","commander":"^12.1.0","node-fetch":"^2.7.0","ora":"^5.4.1"},"gitHead":"22dbacfe9302b81235375615585caba8f35b9db7","_id":"@ellistevo/openclaw-pentest@1.0.0","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-lbI8iBJAnzlCcOjP6Tu6uEJ101iTyFgID9qYMNDJ9i42ZbIsvg76F/hxRWHy/wPDT9hAJS0yBxrCBrt4Tiv9Lw==","shasum":"349dff0e465eac66bad467f16b128ed0d5300f89","tarball":"https://registry.npmjs.org/@ellistevo/openclaw-pentest/-/openclaw-pentest-1.0.0.tgz","fileCount":19,"unpackedSize":30695,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQD8uHvh34OpUp++1WpIcTOmpAPvqZAReCnHpBAhGdvynQIhAMw0rcpAfM0uYECbO5NTYaNlAl7bEomFqXvut1ugN54G"}]},"_npmUser":{"name":"ellistevo","email":"steven.peter.elliott@gmail.com"},"directories":{},"maintainers":[{"name":"ellistevo","email":"steven.peter.elliott@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/openclaw-pentest_1.0.0_1770599378191_0.8762402734250305"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-09T01:09:38.125Z","1.0.0":"2026-02-09T01:09:38.329Z","modified":"2026-02-09T01:09:38.528Z"},"maintainers":[{"name":"ellistevo","email":"steven.peter.elliott@gmail.com"}],"description":"AI-driven penetration testing CLI - point it at your app and it tries to break in","keywords":["penetration-testing","security","pentest","xss","sqli","openclaw","ai-security"],"author":{"name":"ellistevo"},"license":"MIT","readme":"# @ellistevo/openclaw-pentest\n\nAI-driven penetration testing CLI. Point it at your app and it tries to break in.\n\n## ⚠️ Disclaimer\n**Only test applications you own or have explicit written permission to test. Unauthorized testing is illegal.**\n\n## Install & Run\n\n```bash\nnpx @ellistevo/openclaw-pentest https://myapp.com\n```\n\nOr install globally:\n```bash\nnpm install -g @ellistevo/openclaw-pentest\nopenclaw-pentest https://myapp.com\n```\n\n## Tests Performed\n\n| Test | What it checks |\n|------|---------------|\n| **info-disclosure** | Server headers, stack traces in error pages |\n| **exposed-files** | .env, .git, backups, phpinfo, actuator, swagger, etc. |\n| **security-headers** | HSTS, CSP, X-Frame-Options, etc. |\n| **cors** | Wildcard/reflected origins, credential leaks |\n| **xss** | Reflected XSS via common parameters |\n| **sqli** | SQL injection error-based detection |\n| **open-redirect** | Unvalidated redirects via URL parameters |\n| **directory-traversal** | LFI/path traversal attacks |\n| **auth-bypass** | Unauthenticated admin access, JWT detection |\n| **rate-limiting** | Missing rate limits on general + login endpoints |\n| **prompt-injection** | AI endpoint detection + injection attempts |\n| **csrf** | Missing CSRF tokens, SameSite cookies |\n\n## Options\n\n```\n-o, --output <dir>   Output directory (default: ./pentest-report)\n-t, --timeout <ms>   Request timeout (default: 10000)\n--skip <tests>        Comma-separated tests to skip\n--only <tests>        Comma-separated tests to run\n-v, --verbose         Verbose output\n--json-only           Only generate JSON report\n```\n\n## Output\n\nReports are saved to `./pentest-report/`:\n- `report.html` — Beautiful dark-themed HTML report\n- `report.json` — Machine-readable JSON\n\n## Safety\n\nAll tests are non-destructive. No data is modified, no accounts are created, no files are uploaded. The tool only sends HTTP requests and analyzes responses.\n","readmeFilename":"README.md","_rev":"1-06c7cee73f461d891b803a5a55df0600"}