shuvonsec/claude-bug-bounty

DirSkills catalogs 16 skills from this repository, across 4 categories: Automation, DevOps, Quality, Writing.

4.2K stars767 forksView on GitHub
🔍
2w ago

Argus

Argus runs six automated scanners for web and LLM vulnerabilities: CORS misconfig, CRLF/host-header injection, NoSQL injection, JWT attacks, blind bug confirmation via OOB, and LLM red-teaming. Use it on JSON APIs, login endpoints, JWT auth, or any parameter that might reach the server.
Automation
4.2K767
🐞
2w ago

Bug Bounty

Bug Bounty guides a complete bug bounty workflow from reconnaissance and vulnerability hunting through validation and report writing, including LLM/AI security testing and A-to-B bug chaining. Use it for any bug bounty task, from starting a new target to writing the final submission.
Quality
4.2K767
🐞
2w ago

Bug Bounty

Bug Bounty provides a complete bug bounty workflow covering reconnaissance, vulnerability hunting, AI/LLM security testing, bug chaining, and report writing. Use it for starting new targets, hunting specific vuln classes, auditing source code, validating findings, or writing reports.
Quality
4.2K767
🎯
2w ago

Bug Bounty Methodology

Bug Bounty Methodology structures a hunting session around a five-phase workflow and a critical-thinking framework, so an agent can choose a goal, select techniques, and derive next actions. Use it at the start of a bug bounty session, when switching targets, or when unsure what to do next.
Quality
4.2K767
📝
2w ago

Bug Bounty Report Writing

Bug Bounty Report Writing provides templates, tone guidelines, CVSS scoring, and checklists for writing bug bounty reports for HackerOne, Bugcrowd, Intigriti, and Immunefi. Use it after validating a finding and before submitting.
Writing
4.2K767
🛡️
2w ago

CI/CD Security

CI/CD Security audits CI/CD pipelines for workflow injection, secret exfiltration, self-hosted runner poisoning, OIDC token theft, and supply chain attacks. Use it when a target has public repos or CI/CD infrastructure.
DevOps
4.2K767
🔓
2w ago

Client Reverse

Client Reverse helps bug bounty hunters recover client-side request-signing and anti-bot token logic so they can replay protected API requests outside the browser. Use it when Burp or mitmproxy replay fails with 401/403 and you need to isolate the signer before hunting IDOR or auth issues.
Automation
4.2K767
🔑
2w ago

Credential Attack

Credential Attack provides a password spray pipeline for bug bounty: wordlist generation, breach checks, employee OSINT, and login spraying (HTTP form, OAuth, O365, Okta). Use it when credential testing is in scope or to avoid rate-limit and lockout pitfalls.
Automation
4.2K767
🛡️
2w ago

GraphQL Security Audit

GraphQL Security Audit tests GraphQL endpoints for vulnerabilities such as introspection leaks, field suggestion abuse, batching DoS, IDOR via aliasing, auth bypasses, injection, subscription abuse, and depth bombs. Use it when a target exposes a GraphQL endpoint during security assessments.
Quality
4.2K767
🛡️
2w ago

Meme Coin Audit

Meme Coin Audit detects rug pulls in EVM and Solana token contracts, including honeypots, hidden mint, fee manipulation, LP drains, bonding curve exploits, and authority retention. Use it for pre-investment due diligence or token security reviews.
Quality
4.2K767
📱
2w ago

Mobile App Pentest

Mobile App Pentest tests Android/iOS apps by installing them, proxying traffic through Burp/mitmproxy, and driving the UI to capture API requests. It escalates to apktool/jadx and Frida/objection when traffic is pinned or absent to find hardcoded secrets and hidden endpoints.
Quality
4.2K767
🛡️
2w ago

Security Arsenal

Security Arsenal provides security payloads, bypass tables, wordlists, and bug bounty submission rules. Use it when testing for common web vulnerabilities or checking if a finding is submittable.
Quality
4.2K767
🔍
2w ago

Triage Validation

Triage Validation applies a 7-question gate, 4 pre-submission gates, and a never-submit list to bug bounty findings before writing any report. Use it to filter out invalid, out-of-scope, or unproven issues and reduce N/A submissions.
Quality
4.2K767
🔍
2w ago

Web2 Recon

Web2 Recon maps a target's attack surface by enumerating subdomains, discovering live hosts, crawling URLs, analyzing JavaScript, and fuzzing directories. Use it when starting recon on a web2 target or when asked about asset discovery, subdomain enumeration, or attack surface mapping.
Automation
4.2K767
🐛
2w ago

Web2 Vulnerability Classes

Web2 Vulnerability Classes provides a complete reference for 26 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. Use it when hunting a specific vulnerability class or studying what makes bugs pay.
Quality
4.2K767
🛡️
2w ago

Web3 Audit

Web3 Audit catalogs 10 DeFi bug classes with grep patterns, Foundry PoC templates, and pre-dive kill signals for smart contract bug bounties.
Quality
4.2K767