ShulkwiSEC/bb-huge

bb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents

This repository also configures its own agents. See what bb-huge tells them →

22Stars on the repository
200Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Identify and exploit flaws in the core business rules and logic of web applications. This skill focuses on manipulation of application workflows, pricing, inventory limitations, and multi-step processes. Use this skill when bug hunting or testing e-commerce, banking, or SaaS platforms where standard technical…

not rated 22 2mo ago A 81 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Business logic flaws are application vulnerabilities where valid functions are abused in unintended ways: price manipulation via hidden field tampering, workflow step-skipping, function call limit bypass (coupon reuse), process timing exploitation (race conditions on balance updates), and request forging via…

not rated 22 2mo ago A 98 tokens original MIT

business-logic-vuln

75

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.

not rated 22 2mo ago A 41 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.

not rated 22 2mo ago A 37 tokens copy · 100% MIT

business-logic

77

ShulkwiSEC/bb-huge

Skill Claude Code

Application-level business logic security testing for any domain. Takes an understanding-first approach: map the intended workflows before probing them. Covers: value/quantity logic abuse (negative, zero, overflow, rounding on any numeric field), workflow and state machine bypass (skipping required steps, forcing…

not rated 22 2mo ago A 207 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques.

not rated 22 2mo ago A 27 tokens copy · 81% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Utilize the native Windows binary certutil.exe to download malicious payloads and optionally decode Base64 encoded files as a Living-off-the-Land (LotL) technique. This skill details how attackers bypass application whitelisting and fetch stage-2 implants.

not rated 22 2mo ago A 61 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Use when hunting CI/CD bot comment command vulnerabilities where issuecomment or pullrequestreviewcomment triggers invoke privileged workflows without verifying the commenter's identity or authorization. Trigger on: "bot command injection", "issuecomment trigger", "@github-actions", "slash command CI", "CI bot…

not rated 22 2mo ago B 106 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Classical cipher analysis playbook. Use when encountering substitution ciphers, Vigenere, transposition, XOR, or encoded text in CTF challenges that requires frequency analysis, Kasiski examination, or known-plaintext cryptanalysis.

not rated 22 2mo ago A 53 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Build production-grade Claude Code CLI skills with fallback architecture, TypeScript implementation, and creativity directives. Based on Critical Thinking Bug Bounty Podcast Episode 166 — "Building Claude Skills as a Bug Bounty Hunter.".

not rated 22 2mo ago B 54 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Identify and exploit Clickjacking (UI Redressing) vulnerabilities where a malicious website iframes a target application, tricking victims into performing unintended actions (e.g., transferring funds, deleting accounts, or granting permissions) via hidden layers.

not rated 22 2mo ago A 55 tokens original MIT

clickjacking

84

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.

not rated 22 2mo ago A 47 tokens copy · 100% MIT

cloud-security

85

ShulkwiSEC/bb-huge

Skill Claude Code

Cloud security posture assessment for AWS, Azure, and GCP. Tests IAM privilege escalation paths, public storage exposure, serverless attack surface, database exposure, logging gaps, container registry security, and cloud-specific attacks. Both authenticated (with cloud credentials) and unauthenticated (external)…

not rated 22 2mo ago C 139 tokens original MIT

cmd-injection

86

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

OS command injection occurs when user input is passed unsanitized to a system shell via dangerous APIs: Java Runtime.exec(), Python os.system/subprocess, PHP system/shellexec/exec/procopen, C system/exec. Detect via pipe |, semicolon ;, &&, ||, backtick, $() operators, and time-delay payloads (sleep 5). Tools: Commix…

not rated 22 2mo ago A 104 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Command injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks.

not rated 22 2mo ago B 36 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Operate Cobalt Strike for red team engagements including Beacon deployment, C2 communication, post-exploitation, lateral movement, and evasion. Use this skill when conducting authorized red team operations that require a commercial C2 framework. Covers malleable C2 profiles, staged/stageless payloads, sleep and jitter…

not rated 22 2mo ago A 94 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Create and implement Malleable C2 profiles in Cobalt Strike to evade network intrusion detection systems (NIDS/IPS) and endpoint detection architectures. This skill focuses on molding the Beacon's HTTP/HTTPS traffic to resemble legitimate network traffic like Amazon, Google, or jQuery.

not rated 22 2mo ago A 69 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Code obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-modifying code, control flow flattening, VM protection, or string encryption.

not rated 22 2mo ago A 51 tokens copy · 100% MIT

codebase

91

ShulkwiSEC/bb-huge

Skill Claude Code

White-box source code security review structured around OWASP ASVS 5.0 (427 verification requirements across 16 chapters). Reads and understands application source code to build a security-aware knowledge base that enriches all downstream skills. Covers: tech stack identification, route/endpoint mapping…

not rated 22 2mo ago A 208 tokens original MIT

colang-gen

92

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Generates NeMo Guardrails Colang (.co) files and YAML config blocks from a plain-language description of a chatbot's purpose, allowed behaviors, and constraints. Use this skill whenever a user wants to build guardrails for a chatbot, define allowed intents for an LLM, create an AI firewall with NeMo Guardrails…

not rated 22 2mo ago A 117 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Identify and exploit OS Command Injection vulnerabilities where web applications insecurely pass user input into system shell commands. Use this skill when applications feature ping utilities, file conversions, network diagnostics, or PDF generators to execute arbitrary system commands and achieve Remote Code…

not rated 22 2mo ago C 58 tokens original MIT

compliance

94

ShulkwiSEC/bb-huge

Skill Claude Code

Full ASVS 5.0 compliance assessment against a codebase and/or architecture diagrams. Reads all 346 controls from the companion CSV, performs targeted code analysis per control, and produces a complete matrix marked COMPLIANT / NONCOMPLIANT / NOTRELEVANT — with per-control reasoning and evidence (code snippets…

not rated 22 2mo ago A 90 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace tricks, or runtime vulnerabilities.

not rated 22 2mo ago C 52 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude Code

Container and Kubernetes security assessment. Tests container escape vectors, Docker/containerd socket exposure, K8s RBAC misconfigurations, pod security violations, exposed API servers, etcd access, service account token abuse, image layer secrets, private registry attacks, SSRF to metadata services, cross-namespace…

not rated 22 2mo ago D 137 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: