PenClaw, from Audn.AI, rents you a hosted OpenClaw tenant running an abliterated 120B model as an autonomous pentester: $20/mo Pro on a shared H100, $999/mo Ultimate on an 8×H200. The homepage promises “No Limits. No Objections. No refusals.” Every route to the model runs through a one-time selfie plus government ID check (enforced during the free trial), a preset store that demands proof you own the target, an egress firewall that aborts out-of-scope traffic, and a scenario catalogue whose sensitive tiers are greyed out as “not available in this release.” The refusals moved from the weights to the account. Meanwhile the $999 tier advertises “unlimited Kimi K3.0 abliterated,” which today is a gated HuggingFace repo containing a README and a .gitattributes, for a model whose weights are not public until tomorrow.
The best artifact in this story is an empty folder. audnai/penclaw-Kimi-K3.0-abliterated-GGUF was created on HuggingFace on 18 July, has 81 likes, zero downloads, and contains exactly two files: README.md and .gitattributes. Access is gated behind manual approval, so you cannot read the README without applying. It went to Hacker News the same day as “Abliterated Kimi K3 for blackbox software red teaming”, where it took six points and no comments.
Kimi K3’s weights go public on 27 July, which is tomorrow. The repo is a placeholder for a refusal-ablated build of a model nobody outside Moonshot has yet, and it is already a listed feature of a $999/mo plan.
That frames the whole product, which is a bet that the interesting part of an offensive agent is the part that says yes.
What you actually rent
Strip the marketing and PenClaw is a managed OpenClaw instance with an uncensored model bolted to the inference path. Your $20 buys a persistent cloud tenant, a share of an H100 80GB with up to 39 other people, a 128K context window, roughly 195 tokens/sec, and no metering. You drive it from WhatsApp, Telegram, Discord, Signal or Slack. It ships a browser Linux desktop, a Cursor-style cloud IDE, an OpenAI-compatible API endpoint, and “Meta-Claw,” described on the site as “an AI agent with sudo access that retrofits your OpenClaw instance in real time.”
The model is Pingu Unchained 4, a descendant of the 120B GPT-OSS fine-tune Audn.AI founder ozgurozkan showed on HN in November 2025 as “fine-tuned and poisoned.” A companion CLI called audncode, aliased to openclaude, is billed as “a fork of Claude Code” shipping the same weights to your laptop. Version numbers wander between properties: penclaw.ai advertises Pingu Unchained 4, while the audncode page shows a first-run banner reading model: pingu-unchained-10 (/model kong | godzilla).
Around it sits a marketplace of 50+ security MCP servers (Nmap, Nuclei, SQLmap, Burp, BloodHound, Shodan, Ghidra) plus 733 community entries, and a one-click pipeline that takes any GitHub MCP repo, deploys it to Vercel or Render, and wires it into your instance. The site’s phrasing for that pipeline, repeated three times: “no rejections, always works.”
The refusals moved to the front desk
Here is where the pitch and the product part company.
The Red-Team Preset Store asks you to “pick a scenario × surface, prove you own the target, and launch a sandboxed, scope-fenced red-team run.” Runs are “authorized, non-destructive, and held to the scope you confirm,” with “an egress firewall [that] aborts the run on any out-of-scope traffic.” The catalogue’s upper tiers are switched off:
Scenarios above the standard safety tier probe whether a target refuses disallowed content — the agent is a classifier, never an author. These require a T&S reviewer, an isolated classification harness, and an encrypted evidence store, and are not available in this release. They appear dark and cannot be launched.
And the pricing block explains the KYC in terms that concede the entire argument:
PenClaw runs a highly potent, uncensored security model, so — like OpenAI and Anthropic do for their most capable models — we grant product access only after a one-time selfie + government ID check.
Audn.AI has been consistent about this. Answering a question on that 2025 HN thread, ozgurozkan wrote that Pingu “doesn’t use content filters, but it does use cryptographically signed audit logs… it’s unrestricted in capability but not anonymous or unsafe.”
That is a defensible position, and it is the opposite of what the front page sells. A buyer reading “No Limits. No Objections.” is being sold freedom from the model. What they get is a harness with a scope fence, an egress kill switch, a disabled scenario tier, and their passport on file. Every one of those is a guardrail, enforced by Audn.AI’s servers rather than by weights, which also makes every one of them revocable by Audn.AI.
What abliteration actually buys
Assume you want the uncensored model anyway. Is it better at the job?
The cleanest evidence is a same-lineage study from July comparing aligned instruction-tuned models against their publicly released refusal-ablated descendants in the Gemma and Qwen families, across vulnerability detection, CWE attribution, line localization, root-cause localization and patch validation. Abliteration helps. On Java repair validation with Vul4J, the Gemma-based ablated model got 67.8% of patches judged usable against 29.9% aligned, and 32.8% compiling against 9.0%.
Then look at the Qwen localization numbers, where ablation lifts line-level F1 from 2.08% to 3.91% and Top-1 accuracy from 4.10% to 6.95%. Removing the refusal direction converts a refusal into an answer. It does very little to make the answer right.
There’s a second problem with paying to remove refusals in 2026: on offensive cyber work, the refusals are barely there. AISI’s open-weight cyber assessment found safeguards “largely unimpeded,” with DeepSeek’s occasional refusals resolved by a couple of retries, and the Kimi K3 assessment found safeguards that did nothing at all to stop exploit development. The wall you are buying a $999/mo ladder for is about ankle height.
Small print against big print
Three things in the copy deserve pricing in.
The privacy FAQ says “the model runs locally on our infrastructure — nothing is sent to third-party APIs.” The featured marketplace tile two clicks away is “Computer Use (Claude Vision),” which the description says works because “Claude Opus 4.6 sees the screen and clicks, types, scrolls autonomously.” Brave Search, Shodan, Hunter.io, Intelligence X and Supermemory are also one-click installs. Both statements cannot hold.
The use-cases section, on a site whose product is authorization discipline, advertises a Reddit bot with the line: “Reddit didn’t exactly allow this — we built it anyway.”
And the arithmetic. Forty Pro seats at $20 is $800/mo against an H100 whose median on-demand rate is about $2.99/hr, or roughly $2,180/mo, before the desktop VMs, the storage and the Render deployments. Audn.AI says it has “50+ verified customers.” Somebody is subsidising the GPU, and “unlimited” is doing a lot of work.
Verdict
The interesting claim buried under the swagger is the accountability trade: hand the operator an uncensored model, bind it to a verified legal identity, log everything, fence the scope. That is a real design, worth arguing about, and closer to how licensed offensive tooling has always worked than most of the open-weight discourse admits.
It is being marketed as its own opposite. An always-on cloud agent with a sudo-capable configuration bot, one-click installation of arbitrary GitHub MCP servers, 733 community skills and no refusal behaviour is a large attack surface pointed at whoever controls the prompt, and OpenClaw’s security record is thin comfort about the base layer. Before you hand your passport to an “uncensored” pentester, work out which of the two pitches on that homepage you are actually buying.
Sources
- PenClaw homepage, Marketplace and Red-Team Preset Store (accessed 26 July 2026)
- audncode and Audn.AI; Pingu Unchained
- HuggingFace: audnai/penclaw-Kimi-K3.0-abliterated-GGUF (created 18 July 2026, gated, 2 files)
- Li et al., Beyond Refusal: A Same-Lineage Study of Aligned and Abliterated LLMs for Vulnerability Analysis, arXiv:2607.05842 (7 July 2026)
- GitHub: audn-ai/penclaw, MIT-licensed
- H100 cloud pricing comparison, getdeploying
Coverage
- Hacker News: Show HN: Pingu Unchained, an Unrestricted LLM for High-Risk AI Security Research (November 2025); Show HN: Penclaw.ai (February 2026); Abliterated Kimi K3 for blackbox software red teaming; Show HN: Abliterated GLM 5.2, fine-tuned for security and red-team work
- CrowdStrike, HiddenLayer and Barracuda on OpenClaw’s security posture