Bug Bounty (Grade F) logo

Bug Bounty (Grade F)Security-tested testing-security skill for Claude AI. Grade F. Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hu

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

This tool provides a comprehensive workflow for bug bounty hunting, including recon, pre-hunt learning, vulnerability hunting, LLM/AI security testing, and reporting. It covers a wide range of vulnerabilities and techniques, such as subdomain enumeration, asset discovery, fingerprinting, source code audit, and bug chaining. The tool aims to assist in identifying and validating potential security issues, with a focus on actual harm and exploitability.

Key features

  • Recon: subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit
  • Pre-hunt learning: disclosed reports, tech stack research, mind maps, threat modeling
  • Vulnerability hunting: IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI
  • LLM/AI security testing: chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10
  • Reporting: 7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation

Pricing

Model
Free
Category
Skills
Rating
No reviews yet

Use cases

Initial Recon and Vulnerability Hunting

Use the tool to perform initial reconnaissance, identify potential vulnerabilities, and prioritize targets for further investigation.

AI-Powered Security Testing

Utilize the tool's LLM/AI security testing capabilities to identify potential security issues in AI-powered systems and chatbots.

Streamlining Bug Bounty Reporting

Leverage the tool's reporting features to efficiently validate and document findings, and create high-quality bug bounty reports.

Pros & Cons

Pros

  • Comprehensive workflow covering all stages of bug bounty hunting
  • Wide range of vulnerabilities and techniques covered
  • Focus on actual harm and exploitability to prioritize findings
  • Useful for both beginners and experienced bug bounty hunters

Cons

  • Steep learning curve due to the extensive scope of the tool
  • May require significant time investment to fully understand and utilize
  • Some users may find the emphasis on actual harm and exploitability too restrictive

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

How it works?

The tool follows a 6‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any finding is submitted. There are two ways to drive the workflow: 1. **Plain English** – Describe what you’re testing, and the relevant skill loads are automatically applied. 2. **/hunt scaffold + cbh CLI** – Provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a 6‑phase architecture diagram, and a skill‑to‑phase mapping, plus the cbh command‑line interface.

Asked by Linda Petersen · Nov 16, 2025

What's inside?

The bundle contains 82 skills, auto‑loaded by topic with no need for explicit invocation. Coverage spans the external attack surface, including: - Web application hunting (13 skills: XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect, etc.) - Authentication & identity (7 skills: auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO) - API & infrastructure (15 skills: GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE) - Advanced & concurrency (6 skills: race‑condition, HTTP smuggling, deserialization, cache‑poison) - Framework‑specific (4 skills: Next.js, Node.js, Laravel, Spring Boot) - Enterprise identity & cloud (3 skills: M365/Entra, Okta, cloud‑IAM‑deep) - Infrastructure & appliance (4 skills: VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM) - Red‑team tradecraft (4 skills: redteam‑mindset, APK pipeline, supply‑chain recon, mid‑engagement IR) - Recon & OSINT (4 skills: web2‑recon, offensive‑osint, subdomain) - Workflow, reporting & specialized (11 skills: methodology, triage‑validation, evidence‑hygiene, VRT‑aware reporting) A full searchable catalog is available in docs/skills.md. The bundle also ships 15 slash commands (e.g., /hunt, /recon, /report) and a deterministic engagement engine that maps a target’s attack surface and routes each finding to the appropriate skill.

Asked by Lucas Petit · Nov 12, 2025

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads. No invocation by name.

Asked by Mohammed Al-Amin · Oct 29, 2025

Ask a question

Skills alternatives

Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)

(0)
Free
D
Docs Writer (Grade A)Skills

Security-tested devops skill for Claude AI. Grade A. **WORKFLOW SKILL** — Maintains repository documentation accuracy and freshness across the docs site, agent files, and changelog. WHEN: "update docs

(0)
Free