claude-bughunter 🧩 Skill Open source
Skill bundle for authorized bug hunting and external red-team work, with scope gates and reporting
- GitHub stars
- 4.7k
- Stars this week
- +86
- Forks
- 713
- Licence
- MIT
- Last push
- 2026-10-02
- Maintainer
- elementalsouls
/plugin marketplace add elementalsouls/Claude-BugHunterThird-party agent skills run with your permissions. Read the source before installing, and prefer pinned versions.
Works with
About claude-bughunter
What it does
Claude BugHunter is a large skill bundle that turns a coding agent into a bug-hunting and external red-team assistant, scoped to work you are authorized to do. It covers the external attack surface: web applications, APIs, GraphQL, OAuth and JWT, plus internet-facing enterprise platforms and cloud misconfiguration. Skills load automatically from what you describe in plain English, carrying detection patterns, payload tables and chain templates distilled from disclosed bug bounty reports. It ends the workflow with triage, evidence hygiene and platform-aware report writing, and a seven-question gate that checks scope and accepted impact before anything is submitted.
What it does inside
- Methodology skills for a phased hunting workflow and a red-team operator mindset
- Web vulnerability skills for classes such as XSS, SQLi, SSRF, IDOR, SSTI, XXE, CSRF, CORS and open redirect
- Enterprise platform skills covering identity fabrics, virtualization, VPN appliances and cloud IAM with recent CVE chains
- Recon and OSINT skills for subdomain enumeration, certificate transparency, JS analysis and secret scanning
- Reporting and validation skills with VRT-aware severity, a seven-question gate and PII redaction
- Slash commands and an engagement engine that scaffold an engagement folder and route findings to the right skill
Works with
Claude Code has the full experience. The knowledge skills also load in OpenCode, OpenAI Codex CLI and Google Antigravity; the slash commands and engagement engine are Claude Code only.
How to install
/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsouls
Maintenance and safety
The bundle is MIT-licensed and actively maintained. It is explicitly for assets you own or have written authorization to test, with in-scope gates built into the reporting skills, and it excludes post-exploitation tooling, malware development and mass-targeting. The scope still reaches into enterprise CVE chains and cloud escalation, so use it only under a real engagement or bug bounty program. The README notes that Anthropic's runtime cyber safeguards may block dual-use work unless you enroll in their Cyber Verification Program.
Who should use it
It suits authorized bug bounty hunters, web application pentesters and external red teamers who want their agent to carry disciplined method and reporting. It is not for unauthorized testing or internal Active Directory work, which it deliberately leaves out.
Pros
- Wide coverage of web and enterprise attack surface
- Built-in scope and accepted-impact gates before submission
- Runs on several agent harnesses
Cons
- Only for assets you own or are authorized to test
- Enterprise CVE chains demand a real engagement and care
Similar agent skills
All security skills →SkillSpector 🧩 SkillOpen source
NVIDIA's scanner for Agent Skills: finds prompt injection, exfiltration and supply-chain risks
Trail of Bits Skills 🧩 SkillFree
Security auditing skills from the Trail of Bits research team
CTF Skills 🧩 SkillOpen source
Agent Skills for solving CTF challenges across web, pwn, crypto, reverse, forensics and OSINT
Anthropic Agent Skills 🧩 SkillFree
Anthropic's official collection of Agent Skills, including document, design and developer skills
Superpowers 🧩 SkillFree
A skills library that makes coding agents plan, test-first and debug systematically
Frontend Design skill 🧩 SkillFree
Guides the agent to build distinctive, production-grade UIs instead of generic "AI-looking" designs