mbrg/power-pwn
An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents observed · 2026-08-28
Health v2 · maintenance only
63/100
- Activity 58
- Release rhythm 48
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 61.5
- age_days: 1541
- days_rel: 266
- days_push: 255
- n_releases_24m: 3
Adoption not part of the score
1201 stars · 128 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Power Pwn is an offensive and defensive security toolset for Microsoft 365 Power Platform and AI services, including Copilot Studio, custom GPTs, and M365 Copilot. It provides modules for tenant reconnaissance, data dumping, backdoor deployment, phishing simulation, and discovery of misconfigured or publicly exposed AI agents.
Use cases
- discover misconfigured Copilot Studio bots exposed to unauthenticated users
- enumerate and analyze publicly available custom GPTs
- scan a Power Platform tenant and dump accessible resources
- test Microsoft 365 Copilot for unauthorized data retrieval
- find publicly exposed MCP servers and AI middleware via Shodan
- identify Power Pages misconfigurations leaking Dataverse tables
- simulate phishing campaigns using Power Platform
When to choose
- you are a red teamer or security researcher assessing Microsoft 365 and Power Platform environments
- you need to audit AI agents like Copilot Studio bots or custom GPTs for exposure and misconfiguration
- you want an open-source toolset covering both Power Platform and enterprise copilot attack surfaces
When to avoid
- you need a defensive governance or DLP product rather than an assessment toolset
- your environment does not use Microsoft 365, Power Platform, or Copilot services
- you require a fully supported commercial product with vendor guarantees
Facets
cli-tool · maturity active
penetration-testing security osint llm-inference chatbot security penetration-testing artificial-intelligence cli python cross-platform red-team pentesting power-platform copilot-studio m365 ai-agents recon offensive-security microsoft-365 low-code
3 sources
- readme: https://github.com/mbrg/power-pwn · fetched 2026-08-28 · 2a10143e2c99
- homepage: https://zenity.io/zenity-security-assessment-hub · fetched 2026-08-29 · c49bb8765409
- site_page: https://zenity.io/company · fetched 2026-08-29 · 90c15ce6d042
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| mbrg/power-pwn | main | 63 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem