Cursor rule Cursor
Reference file for chain-builder agent and autopilot. Do not duplicate this content elsewhere.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Cursor rule Cursor
Reference file for chain-builder agent and autopilot. Do not duplicate this content elsewhere.
Cursor rule Cursor
These rules are ALWAYS active. Breaking them wastes time and tanks your validity ratio.
Cursor rule Cursor
ALL agents, skills, and orchestrators that need a username, handle, email, password, token, or cookie for a bug bounty platform MUST read it from these env vars at runtime.
Cursor rule Cursor
This file is the "do not repeat" register. Every rule below came from a real session where an agent wasted time, got corrected by the user, inflated a report, or missed a bug. These lessons are target-agnostic — they apply to any program.
Cursor rule Cursor
Reference file for validator agent. Do not duplicate this content elsewhere.
Cursor rule Cursor
Cursor rule "pentest-agents-payloads" from H-mmer/pentest-agents, covering payload reference, xss payloads, basic, waf bypass and context-specific.
Cursor rule Cursor
Field-tested techniques from real engagements. Reference file for all hunting agents.
Cursor rule Cursor
Update this file whenever an engagement proves a vendor has closed a bug class or a fingerprint signature drifts. Entries here prevent re-probing patched vectors across future engagements.
Cursor rule Cursor
Reference file for all hunter agents when a WAF blocks initial payloads. Do not give up after 3-5 payloads. Work through the categories systematically.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: