H-mmer/pentest-agents

Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

This repository also configures its own agents. See what pentest-agents tells them →

907Stars on the repository
205Mods indexed here, across every type
3mo agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

status

97

H-mmer/pentest-agents

Skill Cursor

Show engagement dashboard with program info, scope, brain state, findings, agent activity, and cost estimate.

not rated 907 +92 3mo ago A 23 tokens

submit

98

H-mmer/pentest-agents

Skill Cursor

Draft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review.

not rated 907 +92 3mo ago A 34 tokens

surface

99

H-mmer/pentest-agents

Skill Cursor

Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com.

not rated 907 +92 3mo ago A 23 tokens

sync

100

H-mmer/pentest-agents

Skill Cursor

Sync program scope, policy, and hacktivity from a bug bounty platform. Usage: /sync hackerone tesla or /sync bugcrowd uber.

not rated 907 +92 3mo ago A 33 tokens

triage

101

H-mmer/pentest-agents

Skill Cursor

Batch-validate ALL findings through the 7-Question Gate. Kills weak findings in bulk. Usage: /triage.

not rated 907 +92 3mo ago A 28 tokens

validate

102

H-mmer/pentest-agents

Skill Cursor

Validate a finding through the 7-Question Gate + 4 gates. Kills weak findings FAST. Usage: /validate.

not rated 907 +92 3mo ago A 31 tokens

hunt-business-logic

103

H-mmer/pentest-agents

Skill Cursor

Hunting skill for business-logic vulnerabilities (CWE-840 Business Logic Errors, CWE-841 Improper Enforcement of Behavioral Workflow, CWE-639 Authorization Bypass via User-Controlled Key in business contexts, CWE-362 race conditions on financial flows). Built from 44 corpus reports plus 8.8K shared-platform reports…

not rated 907 +92 3mo ago B 257 tokens

hunt-idor

104

H-mmer/pentest-agents

Skill Cursor

Hunting skill for Insecure Direct Object Reference / Broken Object Level Authorization (BOLA — OWASP API1:2023). Built from 1,117 public IDOR bug bounty reports across HackerOne, Bugcrowd, Intigriti, GitHub Security Advisories, Huntr, plus 2024-2026 meta verified against NVD — Sam Curry's automotive chain…

not rated 907 +92 3mo ago A 267 tokens

hunt-info-disclosure

105

H-mmer/pentest-agents

Skill Cursor

Hunting skill for Information Disclosure / Sensitive Data Exposure (CWE-200 / CWE-209 / CWE-215 / CWE-538 / CWE-668 / CWE-798). Built from 106 corpus reports plus 8K shared-platform reports across HackerOne, Bugcrowd, Huntr, GitHub Security Advisories, plus 2024-2026 meta verified against NVD — Spring Boot Actuator…

not rated 907 +92 3mo ago C 0 tokens

hunt-llm-ai

106

H-mmer/pentest-agents

Skill Cursor

Hunting skill for LLM and Agentic AI vulnerabilities — direct + indirect prompt injection, ASCII smuggling data exfil, agentic tool-use abuse, system prompt leakage, vector DB cross-tenant, model server RCE, insecure output handling. Built from public bug bounty reports across HackerOne, Huntr, Project Zero, GitHub…

not rated 907 +92 3mo ago A ✓ AI review 383 tokens

hunt-oauth

107

H-mmer/pentest-agents

Skill Cursor

Hunting skill for OAuth 2.0 / 2.1, OpenID Connect (OIDC), SAML SSO, and JWT authentication. Built from 365 public OAuth/SSO bug bounty reports across HackerOne, GitHub Security Advisories, PortSwigger Research, GitHub Security Lab, Detectify, Doyensec, Salt Labs, Semperis, Obsidian Security, Trace37 plus 2024-2026…

not rated 907 +92 3mo ago A 409 tokens

hunt-rce

108

H-mmer/pentest-agents

Skill Cursor

Hunting skill for remote code execution. Built from 1,218 public RCE bug bounty reports across HackerOne, Project Zero, Intigriti, GitHub Security Advisories, and curated awesome- lists, plus 2024-2026 meta verified against NVD — React Server Components (CVE-2025-55182), runc Leaky Vessels (CVE-2024-21626), BentoML…

not rated 907 +92 3mo ago D 234 tokens

hunt-xss

109

H-mmer/pentest-agents

Skill Cursor

Hunting skill for Cross-Site Scripting (XSS) — DOM-based, stored, reflected, mutation-based (mXSS), and modern variants. Built from public bug bounty reports across HackerOne, Intigriti, Bugcrowd, Huntr, and GitHub Security Advisories, plus 2024-2026 meta verified against NVD — DOMPurify nesting mXSS (CVE-2024-47875…

not rated 907 +92 3mo ago C 336 tokens

H-mmer/pentest-agents

Skill Cursor

(%26lt%3Bscript%26gt%3B), URL+html-entity, unicode-escape+URL, base64+URL. WAFs typically decode once; targets decode twice, so a payload that looks benign after a single decode still executes at the sink.

not rated 907 +92 3mo ago A 0 tokens

H-mmer/pentest-agents

Skill Cursor

Skill "pentest-agents-recon-methodology" from H-mmer/pentest-agents, covering recon methodology, phase 1: passive (no direct contact), subdomain enumeration, url discovery and tech detection.

not rated 907 +92 3mo ago A 0 tokens

H-mmer/pentest-agents

Skill Cursor

Skill "pentest-agents-report-writing" from H-mmer/pentest-agents, covering report writing, title formula, structure, style rules and common mistakes.

not rated 907 +92 3mo ago A 0 tokens

H-mmer/pentest-agents

Skill Cursor

A single agent asked to "find vulnerabilities" will hallucinate. The pipeline decomposes the task into focused steps, with external state carrying the synthesis between steps. All agents run on except flow-tracing and gap-analysis, which pin opus for cross-file reasoning depth.

not rated 907 +92 3mo ago A 0 tokens

H-mmer/pentest-agents

Skill Cursor

Skill "pentest-agents-triage-validation" from H-mmer/pentest-agents, covering triage & validation, the 7-question gate (applied to every finding), never-submit list, 4 pre-submission gates and conditional validity (chain required).

not rated 907 +92 3mo ago A 0 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: