Bugcrowd Reporting (Grade A) logo

Bugcrowd Reporting (Grade A)针对Claude AI的安全测试技能,已通过安全验证。A级。补充报告撰写的Bugcrowd特定报告策略:当不存在精确匹配时的VRT类别搜索与回退策略,

(0)
Daniel Nikulshyn审阅者 Daniel Nikulshyn·更新 2026年7月

概览

Bugcrowd特定的报告策略,配合报告撰写使用。本技能提供选择VRT类别、手动严重性覆盖以及针对超出范围(OOS)条款的驳回模板的策略。适用于Bugcrowd提交,尤其在VRT默认似乎不正确或审阅员将问题标记为OOS时使用。技能包括目标选择、研究者端卫生措施以及链式发现交叉引用技术。可与报告撰写和审阅验证技能配合使用。

主要功能

  • VRT类别搜索与回退策略
  • 手动严重性覆盖
  • OOS条款驳回模板
  • 链式发现交叉引用模式
  • 针对 QA 与生产项目的目标选择
  • 研究者端卫生措施

价格

模型
Free
评分
暂无评价

使用场景

Bugcrowd 提交的非标准影响

当提交的Bugcrowd报告其影响与VRT默认严重性不匹配时使用。

审阅员降级或 OOS 关闭

当审阅员将问题标记为 OOS 或降级其严重性,需要提供额外上下文进行驳回时使用。

优点 & 缺点

优点

  • 提升VRT类别选择的准确性
  • 通过手动覆盖选项增强严重性评估
  • 提供OOS条款驳回模板
  • 支持研究者端卫生措施和最佳实践

缺点

  • 仅限于Bugcrowd特定使用场景
  • 需要熟悉VRT以及Bugcrowd的提交流程
  • 可能无法直接适用于其他漏洞奖励平台

评测

登录以留下评测。

暂无评测。来当第一个吧!

问答

Why this exists?

Most Claude bug‑hunting setups are either too generic (one big "security" prompt) or too fragmented (bookmarking dozens of disclosed reports). Neither scales past the second target. This bundle was built and validated through authorized engagements that exposed capability gaps: bug‑bounty work revealed missing hypothesis discipline, lack of per‑program reporting tactics, disorganized engagement coordination, and poor evidence hygiene. External red‑team work added gaps such as conservative defaults that retracted real findings, no mid‑engagement situational awareness, and missing enterprise‑platform attack chains (e.g., M365/Entra, SharePoint, SSL‑VPN, vCenter, Android APKs). The bundle addresses these issues with structured methodology, red‑team mindset, up‑to‑date CVE knowledge, and integrated reporting tools.

Asked by Petra Vogel · Jul 22, 2026

How it works?

It follows a six‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any submission. You can drive the process in two ways: by describing what you’re testing in plain English, which automatically loads the relevant skill set, or by using the /hunt scaffold and the cbh CLI, which provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a diagram of the six‑phase architecture, and a skill‑to‑phase mapping.

Asked by Jana Krejčí · Jun 2, 2026

What's inside?

The bundle contains 82 skills, auto‑loaded by topic with no need to invoke them by name. Coverage spans the external attack surface: Web application hunting (13 skills, e.g., XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect), Authentication & identity (7 skills, e.g., auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO), API & infrastructure (15 skills, e.g., GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE), Advanced & concurrency (6 skills, e.g., race‑condition, HTTP smuggling, deserialization, cache‑poison), Framework‑specific (4 skills, e.g., Next.js, Node.js, Laravel, Spring Boot), Enterprise identity & cloud (3 skills, e.g., M365/Entra, Okta, cloud‑IAM), Infrastructure & appliance (4 skills, e.g., VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM), Red‑team tradecraft (4 skills, e.g., redteam‑mindset, APK pipeline, supply‑chain recon, mid‑engagement IR), Recon & OSINT (4 skills), and Workflow, reporting & specialized (11 skills). The catalog is searchable in docs/skills.md, and the bundle also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine that maps a target’s attack surface and routes each finding to the appropriate skill.

Asked by Joanna Kowalski · May 17, 2026

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads.

Asked by Bruno Kaufmann · Apr 26, 2026

提问

育言活动 的替代品

Manage Headers (Grade A) logo
Manage Headers (Grade A)育言活动

专为 Claude AI 设计的安全测试开发技巧, Grade A。检查并配置 Power Pages 站点向浏览器发送的安全 headers — 内容安全策略,框架和点击劫持保护

(0)
Free
Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)育言活动

安全试验的数据-AI技能 - Claude AI。A级。即将开始需要与当前工作环境隔离的功能工作,或执行实施计划前-创建隔离的git工作tree

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)育言活动

为Claude AI提供了经过安全测试的数据ai技能。 Grade A. GA4 BigQuery导出模式参考 - 完整字段参考、嵌套结构、查询模式和性能提示

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)育言活动

安全测试的数据-AI技能,专为Claude AI打造。Grade A. Meta Conversions API (CAPI) 设置指南-架构、事件类型、客户信息哈希、去重复、实现示例、AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)育言活动

经过安全测试的 Claude AI 开发技能。Grade A。列出函数/方法调用的直接调用图

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)育言活动

安全测试数据-ai技能,Grade A. 名为Haskell测试模块,以同一命名空间中的测试模块命名,并在其后添加 Spec 辅助。 在编写或审阅Haskell测试模块时使用。

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)育言活动

经安全检测的数据 AI 技能,适用于 Claude AI。A级。模拟五位专家董事会就重大决策进行审议。用于评估计划、架构选择、功能设计或任何决策。

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)育言活动

安全测试的开发技能,适用于 Claude AI。Grade A。通过 PE(入口点)实现高级 MVC —— 在标准 MVC 界面(CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)中添加自定义网格。

(0)
Free