
Bug Bounty (Grade F)针对 Claude AI 的安全测试技能,已通过安全检测。等级 F。完整的漏洞赏金工作流——侦察(子域枚举、资产发现、指纹识别、HackerOne 范围、源码审计),pre-hu
概览
主要功能
- 侦察:子域枚举、资产发现、指纹识别、HackerOne 范围、源码审计
- pre‑hunt 学习:已披露报告、技术栈研究、思维导图、威胁建模
- 漏洞挖掘:IDOR、SSRF、XSS、认证绕过、CSRF、竞争条件、SQL 注入、XXE、文件上传、业务逻辑、GraphQL、HTTP 走私、缓存投毒、OAuth、时序侧信道、OIDC、SSTI、子域接管、云配置错误、ATO 链、代理 AI
- LLM/AI 安全测试:聊天机器人 IDOR、提示注入、间接注入、ASCII 走私、数据渗漏通道、通过代码工具实现 RCE、系统提示提取、ASI01‑ASI10
- 报告:7 问题关卡、4 个验证关卡、人性化写作、按漏洞类别的模板、CVSS 3.1、PoC 生成
价格
- 模型
- Free
- 分类
- 育言活动
- 评分
- 暂无评价
使用场景
初始侦察与漏洞挖掘
使用该工具进行初始侦察,识别潜在漏洞,并对后续调查的目标进行优先级排序。
AI 驱动的安全测试
利用该工具的 LLM/AI 安全测试能力,识别 AI 系统和聊天机器人中的潜在安全问题。
简化漏洞赏金报告
利用该工具的报告功能,高效验证和记录发现,并生成高质量的漏洞赏金报告。
优点 & 缺点
优点
- 涵盖漏洞赏金狩猎全部阶段的完整工作流
- 覆盖范围广泛的漏洞和技术
- 关注实际危害和可利用性,以对发现进行优先级排序
- 对新手和有经验的漏洞赏金猎人均有帮助
缺点
- 由于工具范围广泛,学习曲线陡峭
- 可能需要投入大量时间才能完全理解和使用
- 部分用户可能觉得对实际危害和可利用性的强调过于严格
评测
登录以留下评测。
暂无评测。来当第一个吧!
问答
How it works?
The tool follows a 6‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any finding is submitted. There are two ways to drive the workflow: 1. **Plain English** – Describe what you’re testing, and the relevant skill loads are automatically applied. 2. **/hunt scaffold + cbh CLI** – Provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a 6‑phase architecture diagram, and a skill‑to‑phase mapping, plus the cbh command‑line interface.
Asked by Linda Petersen · Nov 16, 2025
什么东西在里面?
包裹包含82个技能,根据主题自动加载,无需显式调用。覆盖范围包括: - Web应用程序狩猎(13个技能:XSS、SQLi、SSRF、IDOR、LFI、SSTI、XXE、CSRF、CORS、open-redirect等) - 认证与身份(7个技能:auth-bypass、session、OAuth、SAML、MFA-bypass、ATO) - API与基础设施(15个技能:GraphQL、gRPC、WebSocket、API-misconfig、host-header、RCE) - 高级并发(6个技能:race-condition、HTTP smuggling、序列化、缓存中毒) - Framework特定(4个技能:Next.js、Node.js、Laravel、Spring Boot) - 企业身份与云(3个技能:M365/Entra、Okta、云IAM-深) - 基础设施与-appliance(4个技能:VMware vCenter、企业VPN、SharePoint、ASP.NET/NTLM) - 红队技巧(4个技能:红队心态、 APK管道、供应链recon、mid-engagement IR) - 探索与OSINT(4个技能:web2-recon、offensive-osint、subdomain) - 工作流程、报告与专业(11个技能:方法论、排查验证、证据卫生、VRT-aware报告) 在docs/skills.md中可以查找完全可搜索的目录。该包还带了15个斜线命令(例如,/hunt、/recon、/report)和一个确定性的参与引擎,根据目标的攻击面映射每个发现到适当的技能
Asked by Lucas Petit · Nov 12, 2025
What is this?
claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads. No invocation by name.
Asked by Mohammed Al-Amin · Oct 29, 2025
提问
育言活动 的替代品

安全试验的数据-AI技能 - Claude AI。A级。即将开始需要与当前工作环境隔离的功能工作,或执行实施计划前-创建隔离的git工作tree

为Claude AI提供了经过安全测试的数据ai技能。 Grade A. GA4 BigQuery导出模式参考 - 完整字段参考、嵌套结构、查询模式和性能提示

安全测试的数据-AI技能,专为Claude AI打造。Grade A. Meta Conversions API (CAPI) 设置指南-架构、事件类型、客户信息哈希、去重复、实现示例、AEM

经过安全测试的 Claude AI 开发技能。Grade A。列出函数/方法调用的直接调用图

安全测试数据-ai技能,Grade A. 名为Haskell测试模块,以同一命名空间中的测试模块命名,并在其后添加 Spec 辅助。 在编写或审阅Haskell测试模块时使用。

经安全检测的数据 AI 技能,适用于 Claude AI。A级。模拟五位专家董事会就重大决策进行审议。用于评估计划、架构选择、功能设计或任何决策。

安全测试的开发技能,适用于 Claude AI。Grade A。通过 PE(入口点)实现高级 MVC —— 在标准 MVC 界面(CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)中添加自定义网格。
经过安全测试的 DevOps 技能,适用于 Claude AI。Grade A。**WORKFLOW SKILL** — 在 docs site、agent files 和 changelog 中保持仓库文档的准确性和新鲜度。WHEN: "update docs"




