ChatBotKit
Official@chatbotkit
The simplest way to build advanced AI chat bots.
Agent Skills by ChatBotKit
Showing 40 vetted skills indexed across 1 GitHub repositories.
hunt-api-misconfig
Identify API misconfigurations enabling privilege escalation and data leakage.
hunt-xss
Identify and catalog XSS vulnerabilities across target web applications.
meme-coin-audit
Assess meme-coin tokens for rug-pull risks and vulnerabilities on Ethereum and Solana.
hunt-csrf
Identifies CSRF vulnerabilities and maps chain-to-ATO attack patterns in web apps.
hunt-dispatch
Fingerprint the target and load the matching platform attack skill set for /hunt.
hunt-ssti
Fingerprint SSTI vulnerabilities across template engines and test payloads for RCE paths.
report-writing
Convert vulnerability findings into standardized reports for bug bounty platforms.
hunt-idor
Identify and exploit IDOR vulnerabilities in multi-tenant apps and APIs.
bug-bounty
Automate end-to-end bug bounty workflows from reconnaissance to reporting.
hunt-saml
Test SAML endpoints for XSW, NameID manipulation, signature stripping, and XXE vulnerabilities.
hunt-race-condition
Identifies and exploits web race conditions using parallel requests.
mid-engagement-ir-detection
Correlate baseline measurements with post-change observations to log mid-engagement security-state deltas.
hunt-xxe
Identify and validate XXE vulnerabilities in XML parsers with inline ENTITY and OOB tests.
bugcrowd-reporting
Map Bugcrowd submissions to VRT categories, severity requests, and OOS rebuttals.
hunt-subdomain
Identify vulnerable subdomain takeovers and generate verification-ready reports with proof of ownership.
redteam-report-template
Generate client-facing red-team reports with a six-section finding structure.
supply-chain-attack-recon
Identifies and maps external supply-chain risks from public GitHub orgs and registries.
security-arsenal
Catalog offensive security payloads for XSS, SSRF, SQLi, and related vulnerabilities.
hunt-http-smuggling
Detect HTTP request smuggling variants using Burp extension and time-delay techniques.
hunt-business-logic
Identify and analyze business-logic flaws in web applications for bug-bounty reports.
hunt-aspnet
Detect ASP.NET ViewState deserialization, machineKey misconfigurations, and trace/elmah exposure.
hunt-rce
Identify, validate, and chain remote code execution vulnerabilities across targets.
hunt-sqli
Identify SQLi and NoSQLi vulnerabilities in web applications and ORM-backed services.
bb-methodology
Orchestrate a five-phase bug-bounty workflow across recon, mapping, discovery, proving, and reporting.
Frequently Asked Questions About ChatBotKit
FAQPage SchemaWhat specific security tasks can I perform using these capabilities?βΌ
You can perform comprehensive web application security testing, including identifying XSS, SQLi, XXE, and IDOR vulnerabilities. The framework also supports cloud IAM credential analysis, Android APK decompilation, smart contract auditing, and the generation of standardized, client-ready vulnerability reports for bug bounty platforms.
Who is the target persona for these security modules?βΌ
These modules are designed for professional bug bounty hunters, penetration testers, and red-team operators. They are intended for security researchers who require structured methodologies for reconnaissance, vulnerability chaining, and evidence documentation to maximize the impact and acceptance rate of their security findings.
What are the prerequisites for deploying these security modules?βΌ
Users require a functional environment capable of executing security research tasks, including network access for reconnaissance and standard web testing utilities. Familiarity with common vulnerability classes and bug bounty platform submission requirements is necessary to effectively utilize the provided reporting and validation logic.