Skill Claude CodeCodex
What else is listening, and whether it is even theirs. Use for "port and service discovery" and closely related asks.
Skill Claude CodeCodex
What else is listening, and whether it is even theirs. Use for "port and service discovery" and closely related asks.
Skill Claude CodeCodex
What changed, what it covered, and what it could not see. Use for "recon summary and handoff" and closely related asks.
Skill Claude CodeCodex
The yield is in what they thought they deleted. Use for "repository and secret recon" and closely related asks.
Skill Claude CodeCodex
Run a named flow — a bundled response to a situation — against the bug bounty target the human names. Use for "what should I run on X", "what now", "suggest a flow", "this host returns 404 on everything", "the host is a dead end", "no signup on this target", "this is a JS app / SPA", "there's an OpenAPI spec", "we…
Skill Claude CodeCodex
Execute the target's saved standing order — the hunter's pre-approved evening (or morning) sequence in runbook.md — as ONE authorized bundle ending in a single consolidated brief. Use for "run the runbook on acme", "run my evening runbook", "execute the standing order", "do the usual pass", or any request to run the…
Skill Claude CodeCodex
Find the names, prove they resolve, keep the ones that are real. Use for "subdomain enumeration" and closely related asks.
Skill Claude CodeCodex
Adjudicate the dangling record without claiming it. Use for "subdomain takeover" and closely related asks.
Skill Claude CodeCodex
Analyze a bug-bounty application through its known or suspected web framework, CMS, API/gateway, identity provider, BaaS, enterprise product, server, or versioned component. Use when the hunter names a technology (for example Next.js, Django, Spring, WordPress, GraphQL, Keycloak, Supabase, Jenkins), asks what a…
Skill Claude CodeCodex
Identity and version, or do not write it down. Use for "technology fingerprinting" and closely related asks.
Skill Claude CodeCodex
Collect and reduce historical and live URLs for one named host or a selected set of live hosts. Use for "url collection" and closely related asks.
Skill Claude CodeCodex
Hunt a specific vulnerability class (or family) on one entrypoint of the bug bounty target the human names. Use for "test for SQLi/XSS/IDOR/SSRF/XXE/CSRF/SSTI/RCE", "hunt on ", "check access control / authz / BOLA", "look for business logic bugs", "test the login/password reset/OAuth flow", "race condition"…
MCP server Claude CodeCodexCursor +2
Lets the agent drive a real browser: open pages, click, type, take screenshots and read the accessibility tree, using Playwright. Runs locally from the @playwright/mcp npm package.
MCP server Claude CodeCodexCursor +2
MCP server "burp", hosted remotely at 127.0.0.1, as configured in tarekmo0/HunterStick.
Instructions file CodexOpenCode
Instructions for tarekmo0/HunterStick, covering hunterstick — operating instructions, session start, the router — say the thing, don't cite the path, understand the ask before you route it and non-negotiable rules.
Instructions file
Instructions for tarekmo0/HunterStick: The instructions for this project live in AGENTS.md. Read it now, in full, before doing anything else.