A specialized tool for managing authorized Command and Control simulation workflows and measuring defensive detection effectiveness.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install pentest-c2-operator
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install pentest-c2-operator using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Pentest C2 Operator is a sophisticated security testing tool designed for the Openclaw Skills environment. It enables security researchers to set up authorized C2 simulation workflows and rigorously measure how well defensive systems detect these activities. By focusing on PTES stages 5-6 and MITRE ATT&CK tactics, this skill provides a structured approach to infrastructure tracking and persistence analysis.
This skill bridges the gap between simulated attacks and defensive reporting by providing deterministic data that can be consumed by other agents or analysts. By leveraging this within the Openclaw Skills ecosystem, developers and security engineers can automate the tedious aspects of C2 tracking while maintaining strict adherence to legal and ethical boundaries.
Ensure you have the required Python environment configured. To integrate this with your Openclaw Skills setup, use the following command structure:
# Run the C2 operator script with required parameters
python skills/pentest-c2-operator/scripts/c2_operator.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run
For live execution, the --i-have-authorization flag must be explicitly passed to bypass safety checks.
This skill organizes data into structured JSON artifacts to ensure maximum interoperability across the Openclaw Skills framework.
| Artifact | Description |
|---|---|
c2-infrastructure.json |
Detailed log of infrastructure components and communication channels used in the simulation. |
persistence-mechanisms.json |
An inventory of the techniques used to maintain access on the target system. |
c2-report.json |
The final summary report containing findings, MITRE mappings, and reproducible PoC notes. |
Loading
A specialized security testing skill designed to identify authentication bypass vulnerabilities and account takeover risks.

A professional security testing skill designed to enumerate and audit API endpoints against the OWASP API Security Top 10.

An automated security assessment tool for mapping and validating Active Directory identity attack paths and privilege escalation routes.

Orchestrate authorized Nmap host discovery, service enumeration, and automated security reporting.

An advanced AI creative assistant that generates high-conversion thumbnail prompts and design briefs tailored for Douyin content creators.

A real-time AI spending tracker that visualizes LLM token consumption as interactive, customizable pixel art bead boards.








































