bug-bounty

Automate bug bounty workflows from reconnaissance to report writing.

4.2k|751|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/shuvonsec/claude-bug-bounty --skill bug-bounty
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/shuvonsec/claude-bug-bounty/tree/main
Command: npx skills add https://github.com/shuvonsec/claude-bug-bounty --skill bug-bounty

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires subfinder, httpx, nuclei, ffuf, nmap, amass, gau, dalfox, subjack, arjun, paramspider, kiterunner, cloud_enum, trufflehog, gitleaks, xsstrike, secretfinder, sqlmap, semgrep, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill automates the entire bug bounty hunting process, from initial reconnaissance to report writing, making bug hunting faster and more efficient.

Core Features & Use Cases

  • End-to-End Automation: Covers recon, vulnerability scanning, validation, and report generation.
  • AI-Assisted Hunting: Leverages Claude AI for intelligent analysis and task execution.
  • Use Case: Quickly map the attack surface of any target, identify high-value vulnerabilities like IDOR and SSRF, validate findings using a 4-gate checklist, and generate submission-ready reports for HackerOne or Bugcrowd.

Quick Start

Use the bug-bounty skill to run recon on target.com and identify potential vulnerabilities.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate penetration testing and reconnaissance for bug bounty hunting?

You can automate penetration testing and bug bounty reconnaissance by orchestrating tools like subfinder, nuclei, and ffuf to continuously map attack surfaces and identify vulnerabilities without manual execution. This Skill coordinates that end-to-end workflow automatically.

What is the best way to generate bug bounty reports for HackerOne or Bugcrowd?

Generating bug bounty reports for HackerOne or Bugcrowd involves compiling scanned vulnerabilities, validating findings through a 4-gate checklist, and formatting the output. This Skill automates that report generation to produce submission-ready documents.

Can I use Claude AI to identify high-value vulnerabilities like IDOR and SSRF?

Yes, you can use Claude AI to identify high-value vulnerabilities like IDOR and SSRF by leveraging intelligent analysis during the scanning and validation phases. The AI assists in evaluating task execution across various vulnerability classes.

Does this vulnerability scanning workflow require installing separate tools like nmap and sqlmap?

Yes, vulnerability scanning requires installing separate dependencies like nmap, sqlmap, nuclei, and semgrep. This Skill integrates these external tools to perform the actual scanning, validation, and reconnaissance operations.

How do I validate vulnerability scanning findings before submitting a bug bounty report?

Validating vulnerability scanning findings requires applying a 4-gate checklist to filter out false positives before report generation. This Skill automates that validation process to ensure only confirmed vulnerabilities are submitted.