ArianHobson333/claude-bug-bounty-stack
Complete Claude Code setup for bug bounty hunting — 99 skills, 22 slash commands, 10 agents, hooks, and 4 vendored toolkits (shuvonsec, transilience, Decepticon, hexstrike-ai)
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code $ npx degit ArianHobson333/claude-bug-bounty-stack/commands ./rig-claude-bug-bounty-stack/commands $ npx degit ArianHobson333/claude-bug-bounty-stack/skills ./rig-claude-bug-bounty-stack/skills $ npx degit ArianHobson333/claude-bug-bounty-stack/hooks ./rig-claude-bug-bounty-stack/hooks
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit ArianHobson333/claude-bug-bounty-stack/skills/hunt-idor .claude/skills/hunt-idor $ npx degit ArianHobson333/claude-bug-bounty-stack/skills/hunt-sqli .claude/skills/hunt-sqli $ npx degit ArianHobson333/claude-bug-bounty-stack/skills/hunt-ssrf .claude/skills/hunt-ssrf $ npx degit ArianHobson333/claude-bug-bounty-stack/skills/hunt-xss .claude/skills/hunt-xss $ npx degit ArianHobson333/claude-bug-bounty-stack/skills/owasp-ref .claude/skills/owasp-ref $ npx degit ArianHobson333/claude-bug-bounty-stack/skills/report-gen .claude/skills/report-gen $ npx degit ArianHobson333/claude-bug-bounty-stack/skills/resource-index .claude/skills/resource-index
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (7)
Slash commands (5)
/hunt-simple/recon-simple/report-simple/resources/scope-check-simple
Similar rigs
elementalsouls/Claude-BugHunter
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
Skill Collector 6.7k tok ·
anomalyco/opencode
The open source coding agent.
Pragmatist 4.2k tok ·
DietrichGebert/ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
Pragmatist 1.6k tok ·
Shubhamsaboo/awesome-llm-apps
100+ AI Agents, Agent Skills and RAG Apps - Free and Open Source.
Pragmatist 4.2k tok ·