Gabson0x/bountyforge
all round pentest skill
ARCHETYPE
Skill Collector
Ten-plus skills loaded on demand. A procedural-knowledge library.
Copy this rig
# review before running: this installs third-party code
$ npx degit Gabson0x/bountyforge/skills ./rig-bountyforge/skills MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit Gabson0x/bountyforge/skills/bb-methodology .claude/skills/bb-methodology $ npx degit Gabson0x/bountyforge/skills/bug-bounty .claude/skills/bug-bounty $ npx degit Gabson0x/bountyforge/skills/code-sleuth .claude/skills/code-sleuth $ npx degit Gabson0x/bountyforge/skills/fizz .claude/skills/fizz $ npx degit Gabson0x/bountyforge/skills/fizz/skills/fizz-convert .claude/skills/fizz-convert $ npx degit Gabson0x/bountyforge/skills/fizz/skills/fizz-sync .claude/skills/fizz-sync $ npx degit Gabson0x/bountyforge/skills/godmod .claude/skills/godmod $ npx degit Gabson0x/bountyforge/skills/hackenproof-triage-marketplace .claude/skills/hackenproof-triage-marketplace $ npx degit Gabson0x/bountyforge/skills/meme-coin-audit .claude/skills/meme-coin-audit $ npx degit Gabson0x/bountyforge/skills/report-writing .claude/skills/report-writing $ npx degit Gabson0x/bountyforge/skills/security-arsenal .claude/skills/security-arsenal $ npx degit Gabson0x/bountyforge/skills/smart-contract-audit .claude/skills/smart-contract-audit $ npx degit Gabson0x/bountyforge/skills/triage-validation .claude/skills/triage-validation $ npx degit Gabson0x/bountyforge/skills/web2-recon .claude/skills/web2-recon $ npx degit Gabson0x/bountyforge/skills/web2-vuln-classes .claude/skills/web2-vuln-classes $ npx degit Gabson0x/bountyforge/skills/web3-audit .claude/skills/web3-audit
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,974 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(~/.aws/**)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(.env)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/.env.*)",
"Read(**/*.key)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(npm publish:*)",
"Bash(wget *)",
"Bash(git rebase *)",
"Bash(gh pr merge *)",
"Bash(git commit *)"
]
}
} Skills (16)
Similar rigs
awarexone/Agentic-Bug-Hunter
AI-powered bug bounty hunting toolkit that works with or without subscription.
Skill Collector 5.5k tok ·
pashov/skills
Pashov Audit Group Skills
Minimalist 300 tok ·
elementalsouls/Claude-BugHunter
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
Skill Collector 6.7k tok ·
AhmedAl-Ashwal/claude-code-global-config
Global Claude Code configuration: one CLAUDE.md with unified phases for every project, a /report session-summary command, and the design-md skill. English and Arabic README.
Pragmatist 1.8k tok ·