Instructions file CodexOpenCode
AGENTS.md instructions for H-mmer/pentest-agents, covering pentest-agents repository maintenance, role, source map, generated output and scaffold contract.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Instructions file CodexOpenCode
AGENTS.md instructions for H-mmer/pentest-agents, covering pentest-agents repository maintenance, role, source map, generated output and scaffold contract.
Instructions file
Claude Code instructions for H-mmer/pentest-agents, covering pentest-agents repository maintenance, repository role, source map, generated artifacts and scaffold contract.
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering chain table — capability → next bug, the chain walk algorithm, capability → next bug table, terminal impacts (stop chaining, report) and known deep chains (real-world examples).
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering hunting rules, rule 0: the only question that matters, theoretical bug = wasted time. kill these immediately, rule 1: read full scope first and rule 2: kill weak findings fast.
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering platform identities — canonical env var map, hackerone, bugcrowd, intigriti and yeswehack.
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering mistakes log — lessons from real engagements, top 10 most common mistakes (read first), agent-behavior, gate floors are not work and write files to disk — terminal output is not a deliverable.
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering never-submit list & conditionally valid findings, never-submit list (instant kill without chain) and conditionally valid (chain required).
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering payload reference, xss payloads, basic, waf bypass and context-specific.
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering proven attack techniques, graphql resolver-level auth bypass, with no auth, with fake auth and drf authentication semantics proof.
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering patched — do not test, cloud subdomain-takeover cooldowns, framework fingerprint signatures, keycloak vs spring authorization server and azure app service vs s3 static hosting.
Instructions file GitHub Copilot
Instructions for H-mmer/pentest-agents, covering waf bypass iteration protocol, detection first, check headers, trigger a block and read the error page and check wafw00f if available.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: