bugcrowd skills

33 tagged bugcrowd, measured the same way as everything else here.

Browse within: bug-bounty 32ai-security 21application-security 11bugbounty 11hackerone 11claude-ai 10cti 10

argus

01

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

Argus — the all-seeing scanner suite. Six automated scanners for high-value web + LLM bug classes — CORS misconfiguration (origin reflection / null / credentialed read), CRLF & host-header injection, NoSQL injection (operator auth-bypass / $where blind), JWT attacks (alg:none / RS256→HS256 confusion / secret crack)…

4.7k +30 today A 166 tokens original MIT

credential-attack

02

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

Password spray methodology for bug bounty — when to do it vs web-vuln hunting, the wordlist-gen + breach-check + osint-employees + spray pipeline, mode selection (http-form / oauth / o365 / okta), rate-limit + lockout tactics, BBP legal guardrails, success detection, and the spray → authenticated /hunt chain pattern.…

4.7k +30 today A 102 tokens original MIT

graphql-audit

03

Awarexone/Agentic-Bug-Hunter

Skill Claude CodeCodex

GraphQL security hunting — introspection abuse, field suggestion enumeration (clairvoyance), batching DoS, IDOR via aliasing, auth bypass, injection via arguments, subscription abuse, depth/complexity bombs, and WAF bypass. Covers graphw00f fingerprinting, gqlmap, graphql-cop, and inql. Use when a target exposes a…

4.7k +30 today A 92 tokens original MIT

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external…

3.9k 2d ago A 145 tokens original MIT

bugcrowd-reporting

05

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints…

3.9k 2d ago A 171 tokens original MIT

hunt-aspnet

06

elementalsouls/Claude-BugHunter

Skill Claude CodeCodex

Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors mode=Off…

3.9k 2d ago A 98 tokens original MIT

analyze

07

H-mmer/pentest-agents

Skill Claude CodeCodex

Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze.

813 2mo ago A 25 tokens

chain

08

H-mmer/pentest-agents

Skill Claude CodeCodex

Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A).

813 2mo ago A 33 tokens

fullscan

09

H-mmer/pentest-agents

Skill Claude CodeCodex

Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.

813 2mo ago A 25 tokens