cursorrules
01Cursor rule Cursor
aggregatereports to keep SUMMARY.md and metadata.json synchronized.
Cursor rule Cursor
aggregatereports to keep SUMMARY.md and metadata.json synchronized.
Instructions file CodexOpenCode
Instructions for Zyrexnn/Cybermes, covering 🛡️ cybermes master operational directives (agents.md), 1. 🎯 persona & core mission, 2. ⚡ core operational principles, 3. 📁 strict target-scoped workspace & deliverables and mandatory rules for file creation.
Plugin Claude Code
Plugin marketplace listing 1 plugin: claude-bughunter.
Plugin Claude Code
82-skill bug-hunting & external red-team bundle for Claude Code — 57 hunt- web/vuln-class + framework skills, enterprise platform attack chains (M365/Entra, Okta, SharePoint, vCenter, SSL-VPN, APK/iOS), recon/OSINT, reporting & validation gates, and Burp MCP integration. Skills auto-load by topic; 15 slash commands in.
Command
Command "autopilot" from Zyrexnn/Cybermes, covering /autopilot, usage, session isolation (important), terminal 1: target a and terminal 2: target b (separate process).
Command
Command "chain" from Zyrexnn/Cybermes, covering /chain, when to use this, usage, the a→b signal table and common high-value chains.
Command
Command "hunt" from Zyrexnn/Cybermes, covering /hunt, step 0 — parse, step 1 — mode dispatcher, step 2a — red team and step 2b — wapt.
Command
Command "intel" from Zyrexnn/Cybermes, covering /intel, what this does, usage, output and data sources.
Command
Inspect or rotate the autopilot ledger JSONL files (findings.jsonl, negatives.jsonl). Caps file size and keeps N rotated backups so memory does not grow unbounded.
Command
Command "pickup" from Zyrexnn/Cybermes, covering /pickup, what this does, usage, implementation and if no previous hunt.
Command
Command "recon" from Zyrexnn/Cybermes, covering /recon, what this does, usage, steps and step 1: subdomain enumeration.
Command
Command "remember" from Zyrexnn/Cybermes, covering /remember, usage and what it is not.
Command
Command "report" from Zyrexnn/Cybermes, covering /report, pre-conditions, usage, what this generates and platform selection.
Command
Command "scope" from Zyrexnn/Cybermes, covering /scope, what this does, usage and rules.
Command
Command "surface" from Zyrexnn/Cybermes, covering /surface, what this does, usage, prerequisites and output.
Command
Command "token-scan" from Zyrexnn/Cybermes, covering /token-scan, usage, step 0: quick kill signals, step 1: optional automated scanner and if present.
Command
Command "triage" from Zyrexnn/Cybermes, covering /triage, when to use, usage, the 7 questions (fast version) and fast kill checklist.
Command
Command "validate" from Zyrexnn/Cybermes, covering /validate, what this does, usage, the 7-question gate and q1: can i demonstrate this step-by-step right now?.
Command
Command "web3-audit" from Zyrexnn/Cybermes, covering /web3-audit, usage, step 0: pre-dive kill signals, find accounting variables and find all early returns in critical functions.
Skill Claude CodeCodex
End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external…
Skill Claude CodeCodex
Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to resolve where tools, wordlists, and clones are installed on the local machine (jhaddix, SecLists, trufflehog, ffuf, dalfox, ghauri); for pure orchestration/routing…
Skill Claude CodeCodex
Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other…
Skill Claude CodeCodex
Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload…
Skill Claude CodeCodex
Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints…