ShulkwiSEC/bb-huge

bb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents

This repository also configures its own agents. See what bb-huge tells them →

22Stars on the repository
200Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

cookie-attacks

97

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Audit and attack session cookies via missing Secure/HttpOnly/SameSite attributes, overly broad Domain/Path scope, non-expiring persistent cookies, absent Host- and Secure- prefixes, browser cache leakage (Cache-Control: no-store missing), session token predictability via Burp Sequencer analysis, server-side session…

not rated 22 2mo ago A 109 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

CORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed browser reads, origin reflection, preflight policy bugs, and browser-based access to authenticated APIs.

not rated 22 2mo ago A 43 tokens copy · 100% MIT

cors-misconfig

99

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

CORS misconfiguration allows attacker-controlled origins to read sensitive cross-origin responses when servers echo the Origin header in Access-Control-Allow-Origin or set it to with Access-Control-Allow-Credentials: true. Detect via Origin: https://attacker.com reflection in Access-Control-Allow-Origin response…

not rated 22 2mo ago A 108 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Identify and exploit Cross-Origin Resource Sharing (CORS) misconfigurations. Use this skill when auditing APIs or web applications that share sensitive data across domains, forcing victims' browsers to inadvertently leak private information (e.g., API keys, PII, CSRF tokens) to an attacker-controlled website.

not rated 22 2mo ago C 67 tokens original MIT

credential-audit

102

ShulkwiSEC/bb-huge

Skill Claude Code

Authentication and credential security assessment. Tests password brute-force, credential stuffing, password spraying, default credential testing, credential harvesting, lockout analysis, MFA bypass, OAuth/OIDC abuse, session token entropy, Kerberos attacks, and intelligent wordlist generation. Uses hydra, john…

not rated 22 2mo ago A 103 tokens original MIT

crlf-injection

103

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed characters can split or inject content.

not rated 22 2mo ago A 44 tokens copy · 100% MIT

csp-bypass-advanced

104

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.

not rated 22 2mo ago A 52 tokens copy · 100% MIT

cspt

105

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Use when hunting Client-Side Path Traversal (CSPT) vulnerabilities where attacker- controlled input is unsafely concatenated into the path component of a JavaScript fetch() or XHR request. Trigger on: "CSPT", "client-side path traversal", "fetch path traversal", "XHR path injection", "fetch concatenation", "../ in…

not rated 22 2mo ago A 114 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

CSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.

not rated 22 2mo ago D 44 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Identify and exploit Cross-Site Request Forgery (CSRF) vulnerabilities by bypassing weak or flawed anti-CSRF token implementations, SameSite cookie attributes, and Origin/Referer headers. Use this skill when testing state-changing web application endpoints for session riding attacks. Covers token removal, token…

not rated 22 2mo ago A 79 tokens original MIT

csrf

108

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Cross-Site Request Forgery (CSRF) tricks authenticated users into submitting forged requests to a target application by exploiting browser automatic cookie attachment. Detect via missing or predictable CSRF tokens in state-changing requests (POST/PUT/DELETE), absent SameSite cookie attributes, and JSON endpoints…

not rated 22 2mo ago C 103 tokens original MIT

csv-formula-injection

109

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT). Use when exports, imports, or user fields feed spreadsheets or reporting tools.

not rated 22 2mo ago A 41 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Exploit CVE-2023-36884, a critical Remote Code Execution vulnerability in Windows and Office associated with the Storm-0978 APT. This skill covers the weaponization of malicious Word documents to achieve code execution upon opening, bypassing Mark-of-the-Web (MotW) defenses.

not rated 22 2mo ago A 74 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, sanitizer strips event handlers, WAF blocks script tags) — exfiltrate CSRF tokens, session data, and page content by injecting unclosed HTML tags that capture subsequent page content.

not rated 22 2mo ago A 67 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Test organizational egress controls by executing various data exfiltration techniques during a red team engagement. Use this skill to simulate an adversary attempting to steal sensitive data without triggering DLP (Data Loss Prevention) or network monitoring alerts. Covers exfiltration over DNS, ICMP, HTTP/S…

not rated 22 2mo ago A 80 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Execute sophisticated Data Extraction and Privacy Leakage attacks explicitly against Large Language Models (LLMs) to natively force the neural network entirely into organically regurgitating exact, verbatim strings of Highly Confidential Personally Identifiable Information (PII), proprietary source code, or…

not rated 22 2mo ago A 74 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Simulate supply chain and adversarial machine learning attacks by injecting poisoned data or targeted backdoors into training and fine-tuning datasets. Use this skill when assessing the integrity controls of MLOps pipelines or evaluating the resilience of AI models against highly targeted, stealthy manipulation…

not rated 22 2mo ago A 71 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

Analyze and detect synthetic media, including deepfake videos, AI-generated images, and cloned voice audio. Use this skill when investigating potential disinformation campaigns, verifying the authenticity of digital evidence, or assessing social engineering attacks leveraging synthetic media (e.g., vishing with voice…

not rated 22 2mo ago A 86 tokens original MIT

default-credentials

116

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Identify and exploit default or weak credentials on web application login forms, admin panels, CMS backends (WordPress wp-admin, Joomla, Drupal), and embedded device management interfaces. Signals include framework fingerprinting (WhatWeb, Wappalyzer, Nikto), exposed admin paths from robots.txt/dirbusting, and weak…

not rated 22 2mo ago A 99 tokens original MIT

defi-attack-patterns

117

ShulkwiSEC/bb-huge

Skill Claude CodeCodex needs its repo

DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attacks, governance exploits, bridge vulnerabilities, and token standard edge cases in decentralized finance protocols.

not rated 22 2mo ago A 46 tokens copy · 100% MIT

dependency-confusion

118

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Supply-chain testing via package-manager dependency confusion: when internal package names resolve to attacker-controlled public registries, leading to malicious install and script execution. Use for npm/pip/gem/Maven/Composer/Docker manifest review and authorized red-team supply-chain exercises.

not rated 22 2mo ago A 56 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar mechanisms that may lead to RCE, file access, or privilege escalation.

not rated 22 2mo ago A 52 tokens copy · 100% MIT

distill-skill

120

ShulkwiSEC/bb-huge

Skill Claude Code

Use when the user wants to extract reusable offensive security knowledge from any source and generate a SKILL.md file. Trigger on: "distill this", "extract skill from", "turn this into a skill", "generate skill from", "convert this report/blog/book/walkthrough into a skill", or when the user pastes raw security…

not rated 22 2mo ago A 105 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: