# mbrg/power-pwn

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Repository: https://github.com/mbrg/power-pwn
Canonical: https://ross.abutalabs.com/products/power-pwn
Homepage: https://zenity.io/zenity-security-assessment-hub
Language: Python
License: MIT
License Family: permissive
Topics: pentesting, redteam, hacking, lowcode, nocode, m365, microsoft365, powerapps, hacking-tool, redteaming, ai-red-team, copilotstudio, agentforce, agentspace, chatgpt, agentkit, gpts, powerplatform, blackhat, defcon
Last push: 2025-12-21T15:33:00+00:00

## Health v2 (maintenance only)
Score: 63/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 58, release rhythm 48, longevity 100
- inputs: {"age_days": 1541, "days_push": 255, "days_rel": 266, "gap_med": 61.5, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1201, forks 128 (observed 2026-08-28T04:03:58.233591+00:00)

## What it is
Power Pwn is an offensive and defensive security toolset for Microsoft 365 Power Platform and AI services, including Copilot Studio, custom GPTs, and M365 Copilot. It provides modules for tenant reconnaissance, data dumping, backdoor deployment, phishing simulation, and discovery of misconfigured or publicly exposed AI agents.

## Use cases
- discover misconfigured Copilot Studio bots exposed to unauthenticated users
- enumerate and analyze publicly available custom GPTs
- scan a Power Platform tenant and dump accessible resources
- test Microsoft 365 Copilot for unauthorized data retrieval
- find publicly exposed MCP servers and AI middleware via Shodan
- identify Power Pages misconfigurations leaking Dataverse tables
- simulate phishing campaigns using Power Platform

## When to choose
- you are a red teamer or security researcher assessing Microsoft 365 and Power Platform environments
- you need to audit AI agents like Copilot Studio bots or custom GPTs for exposure and misconfiguration
- you want an open-source toolset covering both Power Platform and enterprise copilot attack surfaces

## When to avoid
- you need a defensive governance or DLP product rather than an assessment toolset
- your environment does not use Microsoft 365, Power Platform, or Copilot services
- you require a fully supported commercial product with vendor guarantees

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, security, osint, llm-inference, chatbot
- domain: security, penetration-testing, artificial-intelligence
- platform: cli, python, cross-platform
- tags: red-team, pentesting, power-platform, copilot-studio, m365, ai-agents, recon, offensive-security, microsoft-365, low-code

## Member repositories
- mbrg/power-pwn (main) score 63

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:58.233591+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:20:42.686647+00:00, confidence not recorded.
  - readme: https://github.com/mbrg/power-pwn (fetched 2026-08-28T04:03:58.233591+00:00, sha 2a10143e2c99)
  - homepage: https://zenity.io/zenity-security-assessment-hub (fetched 2026-08-29T12:28:03.503151+00:00, sha c49bb8765409)
  - site_page: https://zenity.io/company (fetched 2026-08-29T12:28:03.512626+00:00, sha 90c15ce6d042)
- Data as of 2026-08-30T08:39:29.467469+00:00.
