{"id":47383344,"url":"https://github.com/shuvonsec/claude-bug-bounty","last_synced_at":"2026-08-15T22:43:04.171Z","repository":{"id":342952292,"uuid":"1175748759","full_name":"shuvonsec/claude-bug-bounty","owner":"shuvonsec","description":"AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes,   autonomous hunting, and report generation. All inside Claude Code.","archived":false,"fork":false,"pushed_at":"2026-07-21T01:29:57.000Z","size":2419,"stargazers_count":3995,"open_issues_count":12,"forks_count":712,"subscribers_count":33,"default_branch":"main","last_synced_at":"2026-07-21T03:24:15.066Z","etag":null,"topics":["ai-security","bug-bounty","bugcrowd","claude-ai","claude-code","ethical-hacking","hackerone","penetration-testing","recon","vulnerability-scanner"],"latest_commit_sha":null,"homepage":"https://shuvonsec.me/","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/shuvonsec.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":".github/CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":".github/CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":".github/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null}},"created_at":"2026-03-08T05:34:18.000Z","updated_at":"2026-07-21T01:30:01.000Z","dependencies_parsed_at":null,"dependency_job_id":"e9245863-34a6-461f-aeb3-e763254fe9e7","html_url":"https://github.com/shuvonsec/claude-bug-bounty","commit_stats":null,"previous_names":["shuvonsec/claude-bug-bounty"],"tags_count":4,"template":false,"template_full_name":null,"purl":"pkg:github/shuvonsec/claude-bug-bounty","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shuvonsec%2Fclaude-bug-bounty","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shuvonsec%2Fclaude-bug-bounty/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shuvonsec%2Fclaude-bug-bounty/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shuvonsec%2Fclaude-bug-bounty/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/shuvonsec","download_url":"https://codeload.github.com/shuvonsec/claude-bug-bounty/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/shuvonsec%2Fclaude-bug-bounty/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36698915,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-15T02:00:05.847Z","response_time":94,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ai-security","bug-bounty","bugcrowd","claude-ai","claude-code","ethical-hacking","hackerone","penetration-testing","recon","vulnerability-scanner"],"created_at":"2026-03-19T16:00:38.421Z","updated_at":"2026-08-15T22:43:04.153Z","avatar_url":"https://github.com/shuvonsec.png","language":"Python","funding_links":["https://www.buymeacoffee.com/shuvonsec"],"categories":["Python","bugbounty","CTF / Exploit / Bug-Bounty Agents \u0026 Benchmarks","Agentic AI Security Skills"],"sub_categories":["Specialty Security LLMs","Data \u0026 Supply Chain Security"],"readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"logo.png\" alt=\"BugHunter\" width=\"160\"/\u003e\n\u003c/p\u003e\n\n\u003ch1 align=\"center\"\u003eBugHunter\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cb\u003eAI-powered bug bounty hunting — recon to report, in your terminal.\u003c/b\u003e\n  \n  \u003cbr\u003e \n  \u003ca href=\"#standalone-mode--no-subscription-required\"\u003eFree Setup\u003c/a\u003e\n  ·\n  \u003ca href=\"#quick-start\"\u003eQuick Start\u003c/a\u003e\n  ·\n  \u003ca href=\"#commands\"\u003eCommands\u003c/a\u003e\n  ·\n  \u003ca href=\"#what-it-finds\"\u003eWhat It Finds\u003c/a\u003e\n  ·\n  \u003ca href=\"#installation\"\u003eInstall\u003c/a\u003e\n  ·\n  \u003ca href=\"FAQ.md\"\u003eFAQ\u003c/a\u003e\n  \u003c/br\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/shuvonsec/claude-bug-bounty/blob/main/LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/badge/License-MIT-yellow.svg?style=flat-square\" alt=\"MIT License\"\u003e\u003c/a\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Python-3.9+-3776AB.svg?style=flat-square\u0026logo=python\u0026logoColor=white\" alt=\"Python 3.9+\"\u003e\n  \u003cimg src=\"https://img.shields.io/badge/Standalone-Free-brightgreen.svg?style=flat-square\" alt=\"Free Standalone Mode\"\u003e\n  \u003ca href=\"https://claude.ai/claude-code\"\u003e\u003cimg src=\"https://img.shields.io/badge/Claude_Code-Plugin-D97706.svg?style=flat-square\" alt=\"Claude Code Plugin\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/shuvonsec/claude-bug-bounty/stargazers\"\u003e\u003cimg src=\"https://img.shields.io/github/stars/shuvonsec/claude-bug-bounty?style=flat-square\u0026color=yellow\" alt=\"GitHub Stars\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n    \u003ca href=\"https://trendshift.io/repositories/23808?utm_source=repository-badge\u0026amp;utm_medium=badge\u0026amp;utm_campaign=badge-repository-23808\" target=\"_blank\" rel=\"noopener noreferrer\"\u003e\u003cimg src=\"https://trendshift.io/api/badge/repositories/23808\" alt=\"shuvonsec%2Fclaude-bug-bounty | Trendshift\" width=\"250\" height=\"55\"/\u003e\u003c/a\u003e\n  \u003cimg src=\"assets/cli-banner.png\" alt=\"BUGHUNTER — Bug Bounty Automation Pipeline\" width=\"900\"/\u003e\n\u003c/p\u003e\n\n---\n\n## What Is This?\n\nA professional bug bounty hunting toolkit that works **with or without a Claude subscription**. Give it a target — it handles recon, tests for vulnerabilities, validates findings through a strict gate, and writes submission-ready reports for HackerOne, Bugcrowd, Intigriti, and Immunefi.\n\n**It remembers everything.** Patterns found on one target inform the next. Sessions pick up where they left off.\n\nWorks as a [Claude Code](https://claude.ai/claude-code) plugin **or** as a fully standalone CLI (`bughunter`) powered by free AI providers.\n\n---\n\n## Standalone Mode — No Subscription Required\n\n**You no longer need Claude Code, Claude Pro, or any paid AI subscription.**\n\nInstall once, use the `bughunter` command from any terminal on your machine:\n\n```bash\ngit clone https://github.com/shuvonsec/claude-bug-bounty.git\ncd claude-bug-bounty\n./install.sh --agent standalone\n```\n\nRerun the same command after pulling updates. The installer detects and\nrefreshes the active managed `bughunter` command, including older installations\nunder `/usr/local/bin` or `~/.local/bin`, while preserving your saved provider\nconfiguration in `~/.bughunter/config.json`.\n\nTo uninstall the standalone command while keeping its configuration:\n\n```bash\n./uninstall.sh --agent standalone\n```\n\nUse `--purge-config` to also delete `~/.bughunter/config.json`. The uninstaller\nalso supports `claude`, `opencode`, `pi`, `codex`, `agents`, and `all` targets.\n\n```\nbughunter help               # show every command\nbughunter setup              # choose your AI provider (Ollama is free + offline)\nbughunter recon target.com   # map the attack surface\nbughunter hunt  target.com   # hunt for vulnerabilities\nbughunter validate \"finding\" # 7-Question Gate on your finding\nbughunter report             # write a submission-ready report\nbughunter chat               # interactive AI hunting shell\nbughunter providers          # list all available AI providers\nbughunter models             # list models and show the selected one\nbughunter status             # check which provider is active\nbughunter h target.com       # short alias for hunt\nbughunter r target.com       # short alias for recon\nbughunter v \"finding\"        # short alias for validate\n```\n\n### Free AI Providers (auto-detected, free-first priority)\n\n| Provider | Cost | Privacy | Speed | Get Started |\n|:---|:---|:---|:---|:---|\n| **Ollama** | 100% free · runs locally | Full — stays on your machine | Fast | `ollama pull qwen2.5:14b` |\n| **Groq** | Free tier available | Cloud | Very fast | [console.groq.com](https://console.groq.com) → get API key |\n| **DeepSeek** | Very cheap (v4-flash / v4-pro) | Cloud | Fast | [platform.deepseek.com](https://platform.deepseek.com) |\n| Claude API | Paid | Cloud | Fast | [console.anthropic.com](https://console.anthropic.com) |\n| OpenAI | Paid | Cloud | Fast | [platform.openai.com](https://platform.openai.com) |\n| **Grok (xAI)** | Paid | Cloud | Fast | [console.x.ai](https://console.x.ai) → `grok-4.5` |\n| **OpenRouter** | Subscription / pay-as-you-go | Cloud | Fast | [openrouter.ai/keys](https://openrouter.ai/keys) → get API key |\n\nBugHunter auto-detects providers in this order: **Ollama → Groq → DeepSeek → … → OpenRouter → Claude → OpenAI**\n\nSwitch providers or choose an installed Ollama model anytime: `bughunter setup`.\nThe setup can also be fully non-interactive:\n\n```bash\nbughunter setup --provider ollama --model qwen2.5:14b\n```\n\nFor a one-off override, put the option before the command:\n\n```bash\nbughunter --provider ollama --model qwen3:14b hunt target.com\n```\n\n### Zero-cost fully offline setup\n\n```bash\n# 1. Install Ollama (runs AI locally, no internet needed after download)\ncurl -fsSL https://ollama.ai/install.sh | sh\nollama pull qwen2.5:14b          # ~9 GB, one-time download\n\n# 2. Install BugHunter\ngit clone https://github.com/shuvonsec/claude-bug-bounty.git\ncd claude-bug-bounty\n./install.sh --agent standalone   # creates system-wide 'bughunter' command\n\n# 3. Hunt\nbughunter setup       # choose Ollama, then choose one of its installed models\nbughunter recon target.com\n```\n\n### Groq setup (free cloud, fastest option)\n\n```bash\nexport GROQ_API_KEY=\"your-key-here\"     # free at console.groq.com\n./install.sh --agent standalone\nbughunter setup       # choose Groq\nbughunter hunt target.com\n```\n\n---\n\n## Quick Start\n\n**Option A — standalone (no subscription, works for everyone)**\n\n```bash\ngit clone https://github.com/shuvonsec/claude-bug-bounty.git\ncd claude-bug-bounty\n./install.sh --agent standalone   # creates system-wide 'bughunter' command\nbughunter setup                   # pick a free AI provider\nbughunter recon target.com\nbughunter hunt  target.com\nbughunter validate \"my finding\"\nbughunter report\n```\n\n**Option B — Claude Code plugin** *(requires Claude Code)*\n\n```bash\ngit clone https://github.com/shuvonsec/claude-bug-bounty.git\ncd claude-bug-bounty\nchmod +x install_tools.sh \u0026\u0026 ./install_tools.sh   # subfinder · httpx · nuclei · katana · ffuf\nchmod +x install.sh      \u0026\u0026 ./install.sh          # skills + commands → ~/.claude/\n```\n\n```bash\nclaude\n/recon target.com        # map the attack surface\n/hunt target.com         # test for vulnerabilities\n/validate                # run the 7-Question Gate\n/report                  # write the submission\n```\n\n**Option C — let Claude install it** *(Claude Code only)*\n\nOpen your terminal, run `claude`, then paste:\n\n```text\nInstall the Claude Bug Bounty toolkit from https://github.com/shuvonsec/claude-bug-bounty\ninto ~/tools/. Clone the repo, run ./install_tools.sh then ./install.sh.\nVerify /recon /hunt /validate /report are available.\n```\n\n---\n\n## Commands\n\n### Core Workflow\n\n| Command | What It Does |\n|:---|:---|\n| `/recon target.com` | Subdomain enum · live host probing · URL crawl · nuclei sweep |\n| `/hunt target.com` | Tests IDOR · auth bypass · SSRF · XSS · SQLi · logic flaws and more |\n| `/validate` | 7-Question Gate — kills weak findings before you waste time reporting |\n| `/report` | Generates an H1 · Bugcrowd · Intigriti · Immunefi submission in 60s |\n| `/autopilot target.com` | Full loop, autonomous — scope → recon → hunt → validate → report |\n\n### Recon \u0026 Enumeration\n\n| Command | What It Does |\n|:---|:---|\n| `/surface target.com` | Ranked attack surface from recon data + memory |\n| `/scope-aggregate \u003cprogram\u003e` | All in-scope assets across H1 · Bugcrowd · Intigriti · YWH · Immunefi |\n| `/cloud-recon --keyword \u003cname\u003e` | Public S3 · Azure · GCP buckets + CloudFlare-bypass origin IPs |\n| `/param-discover \u003curl\u003e` | Hidden HTTP parameters via Arjun · x8 |\n| `/secrets-hunt --js-bundle \u003cdir\u003e` | Leaked credentials in source, JS bundles, or a GitHub org |\n| `/takeover --recon \u003cdir\u003e` | Subdomain takeover candidates via dnsReaper · subjack |\n| `/scan-cves \u003chost\u003e` | Focused nuclei high/critical sweep + optional log4j-scan |\n| `/bypass-403 \u003curl\u003e` | Header · method · encoding tricks against 403/401 |\n\n\n### Scanners (Web + LLM)\n\n| Command | What It Does |\n|:---|:---|\n| `/cors \u003curl\u003e` | CORS misconfig — origin reflection · null · credentialed |\n| `/crlf \u003curl\u003e` | CRLF / response-splitting + host-header injection |\n| `/nosqli \u003curl\u003e` | NoSQL injection (operator bypass · `$where` timing) |\n| `/jwt-scan \u003ctoken\u003e` | Offline JWT toolkit — alg:none · RS256→HS256 · secret crack |\n| `/oob \u003ctarget\u003e` | Out-of-band listener (interactsh) for blind SSRF/XXE/SQLi |\n| `/llm-redteam \u003cendpoint\u003e` | LLM red-team corpus — prompt injection · jailbreak · exfil |\n\n### Smart Contract (Web3)\n\n| Command | What It Does |\n|:---|:---|\n| `/web3-audit \u003ccontract.sol\u003e` | 10-class smart contract audit with Foundry PoC template |\n| `/token-scan \u003ccontract\u003e` | Rug pull scanner — mint authority · LP lock · honeypot · bonding curve |\n\n### Session \u0026 Utility\n\n| Command | What It Does |\n|:---|:---|\n| `/pickup target.com` | Resume from last session — untested endpoints first |\n| `/intel target.com` | CVEs + disclosed reports relevant to this target |\n| `/chain` | Bug A found → finds bugs B and C that chain with it |\n| `/scope \u003casset\u003e` | Checks if a domain or URL is in scope before you test it |\n| `/triage` | Quick 2-minute go/no-go check |\n| `/remember` | Logs the current finding or technique to hunt memory |\n| `/memory-gc` | Inspect or rotate hunt-memory JSONL files (10 MB cap, 3 backups) |\n| `/arsenal [tool]` | Lists installed external tools or prints an install hint |\n\n---\n\n## What It Finds\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e26 Web2 Vulnerability Classes\u003c/b\u003e\u003c/summary\u003e\n\u003cbr\u003e\n\n| Vulnerability | Typical Payout |\n|:---|:---|\n| IDOR / BOLA | $500 – $5K |\n| Auth Bypass | $1K – $10K |\n| XSS (Stored / Reflected / DOM) | $500 – $5K |\n| SSRF | $1K – $15K |\n| Business Logic | $500 – $10K |\n| Race Conditions | $500 – $5K |\n| SQL Injection | $1K – $15K |\n| OAuth / OIDC | $500 – $5K |\n| File Upload → RCE | $500 – $10K |\n| GraphQL Auth Bypass | $1K – $10K |\n| LLM / Prompt Injection | $500 – $10K |\n| API Misconfiguration (mass assignment · JWT · CORS) | $500 – $5K |\n| Account Takeover | $1K – $20K |\n| SSTI | $2K – $10K |\n| Subdomain Takeover | $200 – $5K |\n| Cloud / Infra Exposure | $500 – $20K |\n| HTTP Request Smuggling | $5K – $30K |\n| Cache Poisoning | $1K – $10K |\n| MFA / 2FA Bypass | $1K – $10K |\n| SAML / SSO Attack | $2K – $20K |\n| Error Disclosure / Debug Endpoints | $200 – $5K |\n| CSS Injection | $500 – $5K |\n| LFI → RCE | $1K – $15K |\n| Insecure Deserialization | $5K – $30K |\n| Dependency Confusion / Supply Chain | $1K – $20K |\n| Padding Oracle / Crypto Misuse | $2K – $20K |\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003e10 Web3 / Smart Contract Bug Classes\u003c/b\u003e\u003c/summary\u003e\n\u003cbr\u003e\n\n| Vulnerability | Typical Payout |\n|:---|:---|\n| Accounting Desync | $50K – $2M |\n| Access Control | $50K – $2M |\n| Incomplete Code Path | $50K – $2M |\n| Off-By-One | $10K – $100K |\n| Oracle Manipulation | $100K – $2M |\n| ERC4626 Share Inflation | $50K – $500K |\n| Reentrancy | $10K – $500K |\n| Flash Loan Attack | $100K – $2M |\n| Signature Replay | $10K – $200K |\n| Proxy / Upgrade | $50K – $2M |\n\n\u003c/details\u003e\n\n---\n\n## AI Agents\n\nNine specialists, each built for one job:\n\n| Agent | Role |\n|:---|:---|\n| `recon-agent` | Subdomain enum · live host discovery · URL crawl |\n| `report-writer` | Impact-first reports that get paid, not N/A'd |\n| `validator` | Runs the 7-Question Gate — kills weak findings |\n| `web3-auditor` | Smart contract audit across 10 bug classes |\n| `chain-builder` | Bug A → finds bugs B and C that chain with it |\n| `autopilot` | Full hunt loop with safety checkpoints |\n| `recon-ranker` | Ranks attack surface by highest-value targets first |\n| `token-auditor` | Meme coin / token rug pull and security scan |\n| `credential-hunter` | Wordlist gen → OSINT → breach-check → spray (hard-stop before spray) |\n\n---\n\n## How It Works\n\n\u003cdiv align=\"center\"\u003e\n\n```\n   You ─▶ /recon ─▶ /hunt ─▶ /validate ─▶ /report\n              │                  │\n              ▼                  ▼\n        Hunt Memory       7-Question Gate\n   (persists across    (kills weak findings\n       sessions)         before you submit)\n```\n\n\u003c/div\u003e\n\nEvery tool in the pipeline is gated on whether it's installed — missing tools are skipped, not errors. Auth headers set once carry through httpx · katana · ffuf · nuclei · dalfox automatically.\n\n---\n\n## Project Structure\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eClick to expand the full tree\u003c/b\u003e\u003c/summary\u003e\n\u003cbr\u003e\n\n```\nclaude-bug-bounty/\n│\n├── skills/                    # AI knowledge bases — loaded as /skill-name\n│   ├── bug-bounty/            # Master workflow — all vuln classes, LLM testing, chains\n│   ├── bb-methodology/        # Hunting mindset · 5-phase workflow · session discipline\n│   ├── web2-recon/            # Subdomain enum · live host discovery · URL crawl\n│   ├── web2-vuln-classes/     # 26 bug classes with bypass tables\n│   ├── security-arsenal/      # Payloads · bypass tables · gf patterns\n│   ├── triage-validation/     # 7-Question Gate · 4 gates · never-submit list\n│   ├── report-writing/        # Templates for H1 · Bugcrowd · Intigriti · Immunefi\n│   ├── web3-audit/            # Smart contract bugs · Foundry PoC · 10 bug classes\n│   ├── meme-coin-audit/       # Rug pull detection · LP attacks · bonding curve\n│   ├── credential-attack/     # Password spray methodology · legal guardrails\n│   └── client-reverse/        # Request-signing / anti-bot token reversal\n│\n├── commands/                  # 26 slash commands (/recon /hunt /validate /report …)\n├── agents/                    # 9 specialized AI agents (recon, validator, reporter …)\n│\n├── tools/                     # Python + shell scanner pipeline (~35 tools)\n│   ├── hunt.py                # Master orchestrator\n│   ├── recon_engine.sh        # Subdomain + URL discovery\n│   ├── vuln_scanner.sh        # XSS · SQLi · SSRF · SSTI probe pipeline\n│   ├── validate.py            # 4-gate finding validator with identity checks\n│   └── …                      # 30+ more scanners — see tools/README.md\n│\n├── memory/                    # Cross-session hunt memory (pattern DB · audit log)\n├── rules/                     # Always-active hunting + reporting rules\n├── tests/                     # Regression test suite (pytest)\n├── web3/                      # 13-chapter smart contract audit guide\n├── mcp/                       # MCP integrations — Burp Suite · Caido · HackerOne API\n├── wordlists/                 # Curated wordlists + SecLists / PayloadsAllTheThings refs\n├── scripts/                   # Dork runner · full hunt pipeline\n├── hooks/                     # Claude Code hook configuration\n├── site/                      # bughunter.fun landing page\n├── demo/                      # Local vulnerable target for tutorial recordings\n│\n├── docs/                      # Extended documentation\n│   ├── advanced-techniques.md # Exploitation techniques + chaining strategies\n│   ├── auth-sessions.md       # Auth header management guide\n│   ├── payloads.md            # Payload reference for common vuln classes\n│   ├── smart-contract-audit.md# Smart contract audit deep-dive\n│   ├── TUTORIAL.md            # A→Z video tutorial walkthrough\n│   └── TODOS.md               # Open improvement items\n│\n├── .github/                   # GitHub community health files\n│   ├── CONTRIBUTING.md        # How to contribute\n│   ├── CODE_OF_CONDUCT.md     # Community standards\n│   ├── SECURITY.md            # Vulnerability reporting policy\n│   ├── PULL_REQUEST_TEMPLATE.md\n│   └── ISSUE_TEMPLATE/        # Bug report · Feature request · False positive\n│\n├── engine.py                  # Standalone CLI — 'bughunter' command, no subscription needed\n├── brain.py                   # Multi-provider LLM layer (Ollama · Groq · DeepSeek · Claude · OpenAI)\n├── agent.py                   # LangGraph-style ReAct hunting agent\n├── install.sh                 # Install skills + commands → ~/.claude/ (or standalone mode)\n├── install_tools.sh           # Install subfinder · httpx · nuclei · katana · ffuf …\n├── uninstall.sh               # Remove skills + commands from ~/.claude/\n├── uninstall_tools.sh         # Remove external scanning tools\n├── serve.py                   # Launch local demo target (python3 serve.py)\n├── config.example.json        # Auth session config template\n├── requirements.txt           # Python dependencies\n├── CLAUDE.md                  # Claude Code plugin manifest (auto-loaded)\n├── AGENTS.md                  # Multi-harness plugin guide (OpenCode · Codex · Pi)\n├── SKILL.md                   # Master skill shortcut (auto-loaded by agent harnesses)\n├── OPENCODE.md                # OpenCode-specific installation guide\n├── CHANGELOG.md               # Version history\n├── FAQ.md                     # Frequently asked questions\n└── TERMS.md                   # Terms of use + authorized testing only\n```\n\n\u003c/details\u003e\n\n---\n\n## Installation\n\n**Prerequisites:**\n\n```bash\n# macOS\nbrew install go python3 jq\n\n# Linux (Ubuntu/Debian)\nsudo apt install golang python3 jq\n```\n\n**Scanning tools** (installs subfinder · httpx · nuclei · katana · ffuf · gau · dnsx · nmap · dalfox and more):\n\n```bash\nchmod +x install_tools.sh \u0026\u0026 ./install_tools.sh\n```\n\n**Standalone `bughunter` command** (no subscription, works without Claude Code):\n\n```bash\n./install.sh --agent standalone\nbughunter setup    # choose Ollama (free) · Groq (free tier) · DeepSeek (cheap) · Claude · OpenAI\n```\n\n**AI skills + commands** into Claude Code:\n\n```bash\nchmod +x install.sh \u0026\u0026 ./install.sh\n```\n\n**Other agent harnesses:**\n\n```bash\n./install.sh --agent opencode    # OpenCode\n./install.sh --agent pi          # Pi Agent\n./install.sh --agent codex       # Codex\n./install.sh --agent all         # every supported target\n```\n\n**Optional: Chaos API key** (better subdomain coverage)\n\n```bash\nexport CHAOS_API_KEY=\"your-key\"\necho 'export CHAOS_API_KEY=\"your-key\"' \u003e\u003e ~/.zshrc\n```\n\n---\n\n## Rules\n\nSeven rules run every session, no exceptions:\n\n| # | Rule | Why |\n|:-:|:---|:---|\n| 1 | **Read full scope first** | Only test what the program authorizes |\n| 2 | **Real bugs only** | \"Can an attacker do this RIGHT NOW?\" — if no, stop |\n| 3 | **Kill weak findings** | A 30-second check saves hours of wasted reporting |\n| 4 | **Never go out of scope** | One wrong request can get you banned |\n| 5 | **5-minute rule** | No progress after 5 minutes? Move on |\n| 6 | **Validate before report** | `/validate` before spending 30 minutes writing |\n| 7 | **Impact first** | Test the bugs with the worst consequences first |\n\n---\n\n## Contributing\n\nPRs welcome. Most valuable:\n- New scanner modules or detection techniques\n- Payload additions to `skills/security-arsenal/SKILL.md`\n- Methodology improvements backed by paid reports\n- Platform support (YesWeHack · Synack · HackenProof)\n\n```bash\ngit checkout -b feature/your-contribution\ngit commit -m \"feat: short description\"\ngit push origin feature/your-contribution\n```\n\n---\n\n## Star History\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://www.star-history.com/?repos=shuvonsec%2Fclaude-bug-bounty\u0026type=date\u0026legend=top-left\"\u003e\n    \u003cpicture\u003e\n      \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://api.star-history.com/chart?repos=shuvonsec/claude-bug-bounty\u0026type=date\u0026theme=dark\u0026legend=top-left\" /\u003e\n      \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://api.star-history.com/chart?repos=shuvonsec/claude-bug-bounty\u0026type=date\u0026legend=top-left\" /\u003e\n      \u003cimg alt=\"Star History Chart\" src=\"https://api.star-history.com/chart?repos=shuvonsec/claude-bug-bounty\u0026type=date\u0026legend=top-left\" width=\"560\" /\u003e\n    \u003c/picture\u003e\n  \u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n## Support\n\nIf BugHunter helps your hunts, you can fuel more of them:\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://www.buymeacoffee.com/shuvonsec\"\u003e\n    \u003cimg src=\"https://cdn.buymeacoffee.com/buttons/v2/default-yellow.png\" alt=\"Buy Me A Coffee\" height=\"50\"/\u003e\n  \u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n## Thanks\n\nThanks to everyone who has contributed to BugHunter. Click any avatar to open their GitHub profile.\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/shuvonsec\"\u003e\u003cimg src=\"https://github.com/shuvonsec.png?size=96\" width=\"48\" height=\"48\" alt=\"shuvonsec\" title=\"shuvonsec\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/shuv0n\"\u003e\u003cimg src=\"https://github.com/shuv0n.png?size=96\" width=\"48\" height=\"48\" alt=\"shuv0n\" title=\"shuv0n\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/letztek\"\u003e\u003cimg src=\"https://github.com/letztek.png?size=96\" width=\"48\" height=\"48\" alt=\"letztek\" title=\"letztek\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/bertolikimberly\"\u003e\u003cimg src=\"https://github.com/bertolikimberly.png?size=96\" width=\"48\" height=\"48\" alt=\"bertolikimberly\" title=\"bertolikimberly\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/venkatas\"\u003e\u003cimg src=\"https://github.com/venkatas.png?size=96\" width=\"48\" height=\"48\" alt=\"venkatas\" title=\"venkatas\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/adityaax\"\u003e\u003cimg src=\"https://github.com/adityaax.png?size=96\" width=\"48\" height=\"48\" alt=\"adityaax\" title=\"adityaax\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/BeargleIndustries\"\u003e\u003cimg src=\"https://github.com/BeargleIndustries.png?size=96\" width=\"48\" height=\"48\" alt=\"BeargleIndustries\" title=\"BeargleIndustries\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/ultra-supara\"\u003e\u003cimg src=\"https://github.com/ultra-supara.png?size=96\" width=\"48\" height=\"48\" alt=\"ultra-supara\" title=\"ultra-supara\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/AurisDSP\"\u003e\u003cimg src=\"https://github.com/AurisDSP.png?size=96\" width=\"48\" height=\"48\" alt=\"AurisDSP\" title=\"AurisDSP\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/Edneam\"\u003e\u003cimg src=\"https://github.com/Edneam.png?size=96\" width=\"48\" height=\"48\" alt=\"Edneam\" title=\"Edneam\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/depapp\"\u003e\u003cimg src=\"https://github.com/depapp.png?size=96\" width=\"48\" height=\"48\" alt=\"depapp\" title=\"depapp\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/Realgagenichols\"\u003e\u003cimg src=\"https://github.com/Realgagenichols.png?size=96\" width=\"48\" height=\"48\" alt=\"Realgagenichols\" title=\"Realgagenichols\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/thuvh\"\u003e\u003cimg src=\"https://github.com/thuvh.png?size=96\" width=\"48\" height=\"48\" alt=\"thuvh\" title=\"thuvh\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/onlybugs05\"\u003e\u003cimg src=\"https://github.com/onlybugs05.png?size=96\" width=\"48\" height=\"48\" alt=\"onlybugs05\" title=\"onlybugs05\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/savioruz\"\u003e\u003cimg src=\"https://github.com/savioruz.png?size=96\" width=\"48\" height=\"48\" alt=\"savioruz\" title=\"savioruz\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/Paebak\"\u003e\u003cimg src=\"https://github.com/Paebak.png?size=96\" width=\"48\" height=\"48\" alt=\"Paebak\" title=\"Paebak\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/nurazhardotcom\"\u003e\u003cimg src=\"https://github.com/nurazhardotcom.png?size=96\" width=\"48\" height=\"48\" alt=\"nurazhardotcom\" title=\"nurazhardotcom\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/SeekAndExploit\"\u003e\u003cimg src=\"https://github.com/SeekAndExploit.png?size=96\" width=\"48\" height=\"48\" alt=\"SeekAndExploit\" title=\"SeekAndExploit\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/Shawanga\"\u003e\u003cimg src=\"https://github.com/Shawanga.png?size=96\" width=\"48\" height=\"48\" alt=\"Shawanga\" title=\"Shawanga\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/zeze-zeze\"\u003e\u003cimg src=\"https://github.com/zeze-zeze.png?size=96\" width=\"48\" height=\"48\" alt=\"zeze-zeze\" title=\"zeze-zeze\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/grave0x\"\u003e\u003cimg src=\"https://github.com/grave0x.png?size=96\" width=\"48\" height=\"48\" alt=\"grave0x\" title=\"grave0x\"/\u003e\u003c/a\u003e\u0026nbsp;\n  \u003ca href=\"https://github.com/kevinaimonster\"\u003e\u003cimg src=\"https://github.com/kevinaimonster.png?size=96\" width=\"48\" height=\"48\" alt=\"kevinaimonster\" title=\"kevinaimonster\"/\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n---\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"logo.png\" alt=\"BugHunter\" width=\"48\"/\u003e\u003cbr\u003e\n  \u003ca href=\"https://github.com/shuvonsec\"\u003eGitHub\u003c/a\u003e\n  ·\n  \u003ca href=\"https://x.com/shuvonsec\"\u003eTwitter\u003c/a\u003e\n  ·\n  \u003ca href=\"mailto:shuvonsec@gmail.com\"\u003eshuvonsec@gmail.com\u003c/a\u003e\u003cbr\u003e\n  \u003cb\u003eBuilt by bug hunters, for bug hunters.\u003c/b\u003e\u003cbr\u003e\n  \u003csub\u003eMIT License · For authorized security testing only. Always test within an approved bug bounty program scope.\u003c/sub\u003e\n\u003c/p\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fshuvonsec%2Fclaude-bug-bounty","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fshuvonsec%2Fclaude-bug-bounty","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fshuvonsec%2Fclaude-bug-bounty/lists"}