bugcrowd commands

52 tagged bugcrowd, measured the same way as everything else here.

Browse within: ai-security 52bug-bounty 52claude-ai 37cti 37application-security 15bugbounty 15

bypass-403

01

Awarexone/Agentic-Bug-Hunter

Command

Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 | /bypass-403 -l.

4.7k +30 today A 0 tokens original MIT

spray

02

Awarexone/Agentic-Bug-Hunter

Command

Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray --mode --users --passes.

4.7k +30 today A 0 tokens original MIT

web3-audit

03

Awarexone/Agentic-Bug-Hunter

Command

Smart contract security audit — runs through 10 bug class checklist (accounting desync, access control, incomplete path, off-by-one, oracle errors, ERC4626, reentrancy, flash loan, signature replay, proxy/upgrade). Applies pre-dive kill signals first. Generates Foundry PoC template for confirmed findings. Usage…

4.7k +30 today A 0 tokens original MIT

hunt

04

elementalsouls/Claude-BugHunter

Command

Active vulnerability hunting. Two-track dispatcher — asks Red Team vs WAPT, hands off to hunt-dispatch skill and sibling commands. Usage: /hunt target.com | /hunt .target.com | /hunt targets.txt [--vuln-class X] [--source-code P] [--chrome].

3.9k 2d ago A 63 tokens original MIT

recon

05

elementalsouls/Claude-BugHunter

Command

Run full recon pipeline on a target — subdomain enum (Chaos API + subfinder), live host discovery (dnsx + httpx), URL crawl (katana + waybackurls + gau), gf pattern classification, nuclei scan. Outputs to recon/ / directory. Usage: /recon target.com.

3.9k 2d ago A 65 tokens original MIT

token-scan

06

elementalsouls/Claude-BugHunter

Command

Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP lock bypass, authority retention, bonding curve exploits, fake renounce, sandwich amplification). Manual 8-class grep audit (with an optional automated scanner if present). Usage: /token-scan [--chain solana].

3.9k 2d ago A 79 tokens original MIT