analyze
01Skill Claude CodeCodex
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Skill Claude CodeCodex
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze.
Skill Claude CodeCodex
Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying questions, no auxiliary-agent…
Skill Claude CodeCodex
Manage the engagement brain. Subcommands: 'init' to set up, 'brief ' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.
Skill Claude CodeCodex
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A).
Skill Claude CodeCodex
Run the finding correlation engine to discover attack chains from individual findings.
Skill Claude CodeCodex
Show cost tracking and ROI for this engagement.
Skill Claude CodeCodex
Check if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck e.g. /dupcheck XSS in search endpoint.
Skill Claude CodeCodex
Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.
Skill Claude CodeCodex
Active vulnerability hunting on a target. Loads scope, reads brain, detects tech stack, runs targeted tests with concrete payloads. Usage: /hunt target.com [--vuln-class idor|xss|ssrf|sqli|ssti|oauth|rce|race|graphql|upload|business-logic|llm-ai].
Skill Claude CodeCodex
Record a platform response and update learning. Usage: /learn [--bounty 500] [--vuln-type XSS].
Skill Claude CodeCodex
Generate a text-based attack surface mindmap. Shows tech stack → vuln class → endpoint relationships. Usage: /mindmap.
Skill Claude CodeCodex
Monitor targets for changes. Usage: /monitor baseline (first run), /monitor check (detect changes), /monitor scope (check platform for scope updates).
Skill Claude CodeCodex
Create a new engagement workspace. Usage: /new [--type web-app|api|mobile|smart-contract].
Skill Claude CodeCodex
Prepare the battlefield — recon, scanning, and surface ranking. Stops before hunting. Run /hunt or /autopilot after. Usage: /pipeline or /pipeline.
Skill Claude CodeCodex
Score a report draft before submission. Usage: /quality.
Skill Claude CodeCodex
Run a quick security scan on a target. Consults the Brain first, validates scope, runs passive recon + vuln scan in parallel.
Skill Claude CodeCodex
Log a finding or pattern to persistent brain memory. Auto-fills from session context. Usage: /remember.
Skill Claude CodeCodex
Generate submission-ready reports for all confirmed findings. Runs dedup, PoC builder, quality check, and report writer. Usage: /report bounty or /report pentest.
Skill Claude CodeCodex
Resume a previous hunt. Shows hunt history, untested endpoints, memory-informed suggestions. Usage: /resume target.com.
Skill Claude CodeCodex
Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: /sast [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30] [--skip-static] [--best-of N].
Skill Claude CodeCodex
Show engagement dashboard with program info, scope, brain state, findings, agent activity, and cost estimate.
Skill Claude CodeCodex
Draft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review.
Skill Claude CodeCodex
Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com.
Skill Claude CodeCodex
Sync program scope, policy, and hacktivity from a bug bounty platform. Usage: /sync hackerone tesla or /sync bugcrowd uber.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: