OlympHill
Bugcrowd Reporting (Grade A) logo

Bugcrowd Reporting (Grade A)Security-tested testing-security skill for Claude AI. Grade A. Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, m

(0)
Daniel Nikulshynレビュー: Daniel Nikulshyn·更新 2026年7月

概要

VRT category search-and-fallback strategyと並み合わせたBugcrowdReportingタクティクス。これにより、VRTカテゴリ選択、手動の危険度オーバーライドおよびOOSクラウズのアドバイステンプレートを選択できます。これは、VRTの既定値が間違っている場合やIssueトリージャがOOSと判断する場合に特に有効です。このスキルには、ターゲットの選択、リサーチャーサイドヒアルチーンファインディングクロスリファレンスなどの追加機能が含まれています。

主な機能

  • VRTカテゴリ検索とフォールバック戦略
  • 手動の危険度オーバーライド
  • OOSクラウズクレームアドバイステンプレート
  • 連鎖型の見つけ方パターン
  • 品質保証用と実用環境用のターゲット選択
  • リサーチャーサイドヒアルチーン

料金

モデル
Free
カテゴリー
東学サェソー
評価
まだレビューはありません

ユースケース

Bugcrowdでの提出に対する非標準的な影響の適用

VRTの既定の危険度と不一致な提出に対して使用

トリーザーのダウングレードまたはOOSクローズ

トリーサーがissueをOOSと判断したり危険度を下げたりした場合に使用

メリット & デメリット

メリット

  • VRTカテゴリセレクションの精度が向上
  • 手動で危険度のオーバーライドが可能
  • OOSクラウズクレームアドバイステンプレートが提供
  • リサーチャーサイドヒアルチーンのベストプラクティスがサポート

デメリット

  • Bugcrowd固有の用途でのみ利用可能
  • VRTとBugcrowdサブミッションのフローの理解が必要
  • 直接他のbug bounty プラットフォームに適用できません

レビュー

レビューを投稿するにはログインしてください。

まだレビューはありません。最初の一人になりましょう!

Q&A

Why this exists?

Most Claude bug‑hunting setups are either too generic (one big "security" prompt) or too fragmented (bookmarking dozens of disclosed reports). Neither scales past the second target. This bundle was built and validated through authorized engagements that exposed capability gaps: bug‑bounty work revealed missing hypothesis discipline, lack of per‑program reporting tactics, disorganized engagement coordination, and poor evidence hygiene. External red‑team work added gaps such as conservative defaults that retracted real findings, no mid‑engagement situational awareness, and missing enterprise‑platform attack chains (e.g., M365/Entra, SharePoint, SSL‑VPN, vCenter, Android APKs). The bundle addresses these issues with structured methodology, red‑team mindset, up‑to‑date CVE knowledge, and integrated reporting tools.

Asked by Petra Vogel · Jul 22, 2026

How it works?

It follows a six‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any submission. You can drive the process in two ways: by describing what you’re testing in plain English, which automatically loads the relevant skill set, or by using the /hunt scaffold and the cbh CLI, which provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a diagram of the six‑phase architecture, and a skill‑to‑phase mapping.

Asked by Jana Krejčí · Jun 2, 2026

What's inside?

The bundle contains 82 skills, auto‑loaded by topic with no need to invoke them by name. Coverage spans the external attack surface: Web application hunting (13 skills, e.g., XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect), Authentication & identity (7 skills, e.g., auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO), API & infrastructure (15 skills, e.g., GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE), Advanced & concurrency (6 skills, e.g., race‑condition, HTTP smuggling, deserialization, cache‑poison), Framework‑specific (4 skills, e.g., Next.js, Node.js, Laravel, Spring Boot), Enterprise identity & cloud (3 skills, e.g., M365/Entra, Okta, cloud‑IAM), Infrastructure & appliance (4 skills, e.g., VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM), Red‑team tradecraft (4 skills, e.g., redteam‑mindset, APK pipeline, supply‑chain recon, mid‑engagement IR), Recon & OSINT (4 skills), and Workflow, reporting & specialized (11 skills). The catalog is searchable in docs/skills.md, and the bundle also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine that maps a target’s attack surface and routes each finding to the appropriate skill.

Asked by Joanna Kowalski · May 17, 2026

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads.

Asked by Bruno Kaufmann · Apr 26, 2026

質問する

東学サェソーの代替

Manage Headers (Grade A) logo

Manage Headers (Grade A)

東学サェソー

セキュリティテストで検証されたClaude AIの開発スキルの「Aレベル」。「Power Pagesサイトからのブラウザへのセキュリティヘッダーの検査および構成」のためのもの。Content Security Policy、フレームとクリックジャッキング保護

(0)
Free
Using Git Worktrees (Grade A) logo

Using Git Worktrees (Grade A)

東学サェソー

セキュリティテスト済みデータAISHILL(Grade A)。クリュードAIと併用する。

(0)
Free
Ga4 Bigquery Schema (Grade A) logo

Ga4 Bigquery Schema (Grade A)

東学サェソー

セキュリティテスト済みのデータ・AIスキル用Claude AI。 Grade A。GA4 BigQuery Export Schemaの参照情報大全、ネスト構造、検索パターン、パフォーマンスのヒント

(0)
Free
Meta Capi (Grade A) logo

Meta Capi (Grade A)

東学サェソー

Security-checked data-ai skill for Claude AI. Grade A. (Meta Conversions API (CAPI)のセットアップガイド — アーキテクチャ、イベントタイプ、顧客情報のハッシュ、削除、実装例、AEM)

(0)
Free
Callees (Grade A) logo

Callees (Grade A)

東学サェソー

Claude AI向けセキュリティ検証済開発スキル。 Grade A. 関数/メソッドはどこにコールしているかをリストする

(0)
Free
Test Module Name (Grade A) logo

Test Module Name (Grade A)

東学サェソー

セキュリティテスト済みデータ-AIスキル、クラウド AI用 Grade A。 モジュールをテストするモジュールと同じネームスペースのSpecサフィックスでモジュール名を付ける。 クラウド AIのテストモジュールライティングまたはレビューに使用してください。

(0)
Free
Board Of Directors (Grade A) logo

Board Of Directors (Grade A)

東学サェソー

SECURITY TESTED DATA-AI SKILL FOR CLAUDE AI. GRADE A. マジョルな決定を実行者 5 人が協議しながらの実行者 5 人によるディレクトオフィス議論シミュレーション。プランの評価やアーキテクチャーセレクション、機能デザイン評価など、複数視点の専門分析を必要とするあらゆる決定を評価するには使用してください。

(0)
Free
Advpl Mvc Avancado (Grade A) logo

Advpl Mvc Avancado (Grade A)

東学サェソー

セキュリティテスト開発スキル for Claude AI. AランクのMVCアドバンス

(0)
Free