shaniidevshaniidevCommunityยท1 Agent Skills Included

bug-reaper

Evidence-based web vulnerability hunting and bounty report writing

Finds and validates real web vulnerabilities across 18 classes including IDOR, SQLi, SSRF, XSS, and auth bypass. Eliminates false positives by requiring working proof-of-concept evidence before any finding is reported. Generates platform-ready reports for HackerOne, Bugcrowd, Intigriti, and YesWeHack with correct severity scoring. Chains low-severity bugs into critical findings to maximize bounty payouts.
npx skills add shaniidev/bug-reaper --all -g -y

All Skills in This Repository (1)

Pure Emerald Level Indicators

Frequently Asked Questions

FAQPage Schema
How to install BugReaper?โ–ผ

Run `npx skills add shaniidev/bug-reaper --all -g -y` in your terminal to install the skill globally for all compatible agents.

What does BugReaper do?โ–ผ

It guides your agent through a four-phase bug bounty workflow: recon, auditing 18 vulnerability classes, evidence-based validation, and platform-specific report writing. Every finding requires a working proof of concept before it is reported.

Which bug bounty platforms does BugReaper support?โ–ผ

It generates reports matching the triage criteria of HackerOne, Bugcrowd, Intigriti, and YesWeHack, with correct severity scoring for each platform.

Does BugReaper work with Claude Code and Cursor?โ–ผ

Yes. It follows the open Agent Skills standard and runs natively in Claude Code, Cursor, OpenClaw, Windsurf, and Antigravity without modification.

Can BugReaper audit source code?โ–ผ

Yes. It includes a white-box mode that reviews locally downloaded repositories, tracing dangerous sinks, secrets, and dependency issues across six programming languages.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’