bb-local-toolkit

Orchestrate bug bounty and red-team operations within Claude Code.

Updated Jul 1, 2026
One-click install
npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill bb-local-toolkit-bpnrockstar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-local-toolkit
Source: https://github.com/bpnrockstar/UnifiedBugHunter/tree/main/skills/bb-local-toolkit
Command: npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill bb-local-toolkit-bpnrockstar

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires Claude Code, subfinder, httpx, nuclei, katana, waybackurls, gau, dalfox, ffuf, assetfinder, gf, interactsh-client, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill Unit streamlines bug bounty and red-team operations within Claude Code, providing a comprehensive workflow for reconnaissance, learning, hunting, validation, and reporting.

Core Features & Use Cases

  • Reconnaissance: Enumerate subdomains, discover assets, fingerprint services, and audit source code.
  • Learning: Analyze disclosed reports and research tech stacks for informed hunting.
  • Hunting: Identify and exploit vulnerabilities such as IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, SSTI, subdomain takeover, cloud misconfig, ATO chains, AI.
  • Validation: Ensure findings are real and impactful before reporting.
  • Reporting: Document findings with a 7-Question Gate, CVSS 3.1 scoring, PoC generation, and a never-submit list.

Quick Start

Use the bb-local-toolkit skill to begin reconnaissance on the target domain 'example.com'.

Frequently Asked Questions about bb-local-toolkit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty reconnaissance and vulnerability hunting in Claude Code?

You can orchestrate bug bounty and red-team operations in Claude Code by using this skill to automate subdomain enumeration, service fingerprinting, and vulnerability hunting. It coordinates external tools to identify and exploit vulnerabilities across various environments.

What is the best way to validate and report bug bounty findings?

Validating and reporting bug bounty findings requires ensuring impact before submission. This skill provides a 7-Question Gate, CVSS 3.1 scoring, PoC generation, and a never-submit list to document findings accurately and prevent false positives.

Do I need external tools like subfinder and nuclei to run red-team operations with this skill?

Yes, you need Claude Code and a suite of external tools including subfinder, httpx, nuclei, katana, and dalfox. These dependencies are required for scope checking, data exfiltration, and comprehensive vulnerability testing.

How does reconnaissance work for subdomain takeover and cloud misconfigurations?

Reconnaissance works by enumerating subdomains and discovering assets using tools like assetfinder and waybackurls. It fingerprints services and audits source code to identify subdomain takeovers, cloud misconfigurations, and other vulnerabilities.

Can I use this skill to hunt for specific vulnerabilities like SSRF and XSS?

Yes, you can hunt for specific vulnerabilities like SSRF, XSS, IDOR, SQLi, and GraphQL flaws. The skill integrates tools like dalfox and ffuf to identify and exploit these vulnerabilities across various application types.

What are the limitations of using Claude Code for red-team operations?

Limitations include dependency on external tools like interactsh-client and gau, requiring local installation and configuration. The skill cannot operate without Claude Code and relies heavily on these tools for scope checking and vulnerability validation.