~ / rigs / H-mmer / pentest-agents

H-mmer/pentest-agents

Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

↗ GitHub ★ 984 no license updated 4mo ago project Claude CodeCodexCursorGemini CLICopilot
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~73.0k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add bounty-platforms -- uv run --with mcp mcp-bounty-server/server.py
$ claude mcp add writeup-search -- uv run --with mcp mcp-writeup-server/server.py
$ npx degit H-mmer/pentest-agents/.claude ./rig-pentest-agents  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add bounty-platforms -- uv run --with mcp mcp-bounty-server/server.py
$ claude mcp add writeup-search -- uv run --with mcp mcp-writeup-server/server.py
$ npx degit H-mmer/pentest-agents/.claude/skills/analyze .claude/skills/analyze
$ npx degit H-mmer/pentest-agents/.claude/skills/autopilot .claude/skills/autopilot
$ npx degit H-mmer/pentest-agents/.claude/skills/brain .claude/skills/brain
$ npx degit H-mmer/pentest-agents/.claude/skills/chain .claude/skills/chain
$ npx degit H-mmer/pentest-agents/.claude/skills/correlate .claude/skills/correlate
$ npx degit H-mmer/pentest-agents/.claude/skills/cost .claude/skills/cost
$ npx degit H-mmer/pentest-agents/.claude/skills/dupcheck .claude/skills/dupcheck
$ npx degit H-mmer/pentest-agents/.claude/skills/fullscan .claude/skills/fullscan
$ npx degit H-mmer/pentest-agents/.claude/skills/hunt .claude/skills/hunt
$ npx degit H-mmer/pentest-agents/.claude/skills/learn .claude/skills/learn
$ npx degit H-mmer/pentest-agents/.claude/skills/mindmap .claude/skills/mindmap
$ npx degit H-mmer/pentest-agents/.claude/skills/monitor .claude/skills/monitor
$ npx degit H-mmer/pentest-agents/.claude/skills/new .claude/skills/new
$ npx degit H-mmer/pentest-agents/.claude/skills/pipeline .claude/skills/pipeline
$ npx degit H-mmer/pentest-agents/.claude/skills/quality .claude/skills/quality
$ npx degit H-mmer/pentest-agents/.claude/skills/quickscan .claude/skills/quickscan
$ npx degit H-mmer/pentest-agents/.claude/skills/remember .claude/skills/remember
$ npx degit H-mmer/pentest-agents/.claude/skills/report .claude/skills/report
$ npx degit H-mmer/pentest-agents/.claude/skills/resume .claude/skills/resume
$ npx degit H-mmer/pentest-agents/.claude/skills/sast .claude/skills/sast
$ npx degit H-mmer/pentest-agents/.claude/skills/status .claude/skills/status
$ npx degit H-mmer/pentest-agents/.claude/skills/submit .claude/skills/submit
$ npx degit H-mmer/pentest-agents/.claude/skills/surface .claude/skills/surface
$ npx degit H-mmer/pentest-agents/.claude/skills/sync .claude/skills/sync
$ npx degit H-mmer/pentest-agents/.claude/skills/triage .claude/skills/triage
$ npx degit H-mmer/pentest-agents/.claude/skills/validate .claude/skills/validate
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-auth-tester .claude/skills/agent-auth-tester
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-brain .claude/skills/agent-brain
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-browser-agent .claude/skills/agent-browser-agent
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-browser-stealth-agent .claude/skills/agent-browser-stealth-agent
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-browser-verifier .claude/skills/agent-browser-verifier
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-business-logic .claude/skills/agent-business-logic
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-chain-builder .claude/skills/agent-chain-builder
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-cloud-recon .claude/skills/agent-cloud-recon
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-config-auditor .claude/skills/agent-config-auditor
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-correlator .claude/skills/agent-correlator
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-cors-hunter .claude/skills/agent-cors-hunter
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-csrf-hunter .claude/skills/agent-csrf-hunter
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-dast-devils-advocate .claude/skills/agent-dast-devils-advocate
$ npx degit H-mmer/pentest-agents/providers/cursor/.cursor/skills/agent-file-upload .claude/skills/agent-file-upload
$ curl -fsSL --create-dirs -o .claude/agents/auth-tester.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/auth-tester.md
$ curl -fsSL --create-dirs -o .claude/agents/brain.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/brain.md
$ curl -fsSL --create-dirs -o .claude/agents/browser-agent.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/browser-agent.md
$ curl -fsSL --create-dirs -o .claude/agents/browser-stealth-agent.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/browser-stealth-agent.md
$ curl -fsSL --create-dirs -o .claude/agents/browser-verifier.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/browser-verifier.md
$ curl -fsSL --create-dirs -o .claude/agents/business-logic.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/business-logic.md
$ curl -fsSL --create-dirs -o .claude/agents/chain-builder.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/chain-builder.md
$ curl -fsSL --create-dirs -o .claude/agents/cloud-recon.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/cloud-recon.md
$ curl -fsSL --create-dirs -o .claude/agents/config-auditor.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/config-auditor.md
$ curl -fsSL --create-dirs -o .claude/agents/correlator.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/correlator.md
$ curl -fsSL --create-dirs -o .claude/agents/cors-hunter.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/cors-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/csrf-hunter.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/csrf-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/dast-devils-advocate.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/dast-devils-advocate.md
$ curl -fsSL --create-dirs -o .claude/agents/file-upload.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/file-upload.md
$ curl -fsSL --create-dirs -o .claude/agents/graphql-audit.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/graphql-audit.md
$ curl -fsSL --create-dirs -o .claude/agents/idor-hunter.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/idor-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/info-disclosure.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/info-disclosure.md
$ curl -fsSL --create-dirs -o .claude/agents/js-analyzer.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/js-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/llm-ai-hunter.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/llm-ai-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/monitor.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/monitor.md
$ curl -fsSL --create-dirs -o .claude/agents/nuclei-writer.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/nuclei-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/oauth-hunter.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/oauth-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/open-redirect.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/open-redirect.md
$ curl -fsSL --create-dirs -o .claude/agents/poc-builder.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/poc-builder.md
$ curl -fsSL --create-dirs -o .claude/agents/privilege-escalation.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/privilege-escalation.md
$ curl -fsSL --create-dirs -o .claude/agents/quality-check.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/quality-check.md
$ curl -fsSL --create-dirs -o .claude/agents/race-condition.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/race-condition.md
$ curl -fsSL --create-dirs -o .claude/agents/rce-hunter.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/rce-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/recon-ranker.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/recon-ranker.md
$ curl -fsSL --create-dirs -o .claude/agents/recon.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/recon.md
$ curl -fsSL --create-dirs -o .claude/agents/report-writer.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/report-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/sast-danger-mapper.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/sast-danger-mapper.md
$ curl -fsSL --create-dirs -o .claude/agents/sast-devils-advocate.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/sast-devils-advocate.md
$ curl -fsSL --create-dirs -o .claude/agents/sast-entry-mapper.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/sast-entry-mapper.md
$ curl -fsSL --create-dirs -o .claude/agents/sast-exploit-builder.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/sast-exploit-builder.md
$ curl -fsSL --create-dirs -o .claude/agents/sast-file-ranker.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/sast-file-ranker.md
$ curl -fsSL --create-dirs -o .claude/agents/sast-flow-tracer.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/sast-flow-tracer.md
$ curl -fsSL --create-dirs -o .claude/agents/sast-gap-analyzer.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/sast-gap-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/sast-hunter.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/sast-hunter.md
$ curl -fsSL --create-dirs -o .claude/agents/scope-check.md https://raw.githubusercontent.com/H-mmer/pentest-agents/main/.claude/agents/scope-check.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf /)",
      "Bash(rm -rf ~)",
      "Bash(> /dev/sd*)",
      "Bash(dd if=*of=/dev/*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "uv run python3 $CLAUDE_PROJECT_DIR/tools/scope_hook.py"
          }
        ]
      },
      {
        "matcher": "Write|Edit",
        "hooks": [
          {
            "type": "command",
            "command": "uv run python3 $CLAUDE_PROJECT_DIR/tools/file_path_guard.py"
          },
          {
            "type": "command",
            "command": "uv run python3 $CLAUDE_PROJECT_DIR/tools/cvss_version_guard.py"
          },
          {
            "type": "command",
            "command": "uv run python3 $CLAUDE_PROJECT_DIR/tools/validity_guard.py"
          }
        ]
      }
    ]
  }
}

MCP servers (2)

serversourceest. tokens
mcp · "bounty-platforms" pypi 2.5k
mcp · "writeup-search" pypi 2.5k

Skills (115)

Subagents (50)

auth-tester
model: inherit
Authentication and session management testing agent. Use for login bypass, session fixation, password reset flow abuse, MFA bypass, OAuth flaws, and privilege escalation testing. Provide the applicati
brain
model: inherit
Central knowledge coordinator. Use BEFORE launching any other pentest agent to get context on what's already been tried. Also use AFTER any agent completes to record findings, exhausted vectors, and l
browser-agent
model: inherit
Browser automation agent for interactive web testing. Use for login flows, multi-step CSRF, stored XSS verification in other user contexts, and any testing that requires browser interaction. Requires
browser-stealth-agent
model: inherit
Stealth browser automation agent for targets behind Cloudflare, Akamai, Google, DataDome, or PerimeterX bot detection. Drives the local camofox-browser REST server (Camoufox, C++-patched Firefox) for
browser-verifier
model: inherit
Mandatory browser verification for client-side findings (XSS, DOM, postMessage, prototype pollution). Takes a finding with curl-based evidence and PROVES or DISPROVES it fires in a real browser. No fi
business-logic
model: inherit
Business Logic vulnerability specialist (H1 #28, CWE-840/841/639/362). Use for testing workflow bypasses, price manipulation, coupon abuse, MFA/2FA bypass, password-reset bypass, free-trial abuse, rac
chain-builder
model: inherit
Deep exploit chain builder. Given bug A, recursively walks the chain graph — each confirmed link becomes the new A. No depth limit. Supports 2-link to 10+ link chains. Use when you have any finding th
cloud-recon
model: inherit
Cloud misconfiguration scanner. Use for S3 bucket enumeration, Azure blob discovery, GCP storage checks, exposed cloud services, and cloud metadata analysis. Provide target domain or known cloud ident
config-auditor
model: haiku
Security header and server configuration auditor. Use for HTTP security header analysis, CSP evaluation, CORS policy review, TLS configuration assessment, cookie security, and server hardening checks.
correlator
model: inherit
Finding correlation engine. Use AFTER multiple agents have reported findings to discover attack chains. Combines individual findings into higher-impact chains (e.g., open redirect + CORS + SSRF = toke
cors-hunter
model: inherit
CORS Misconfiguration specialist (H1 #58). Use for testing cross-origin resource sharing policies, origin reflection, null origin bypass, and credential-bearing cross-origin requests.
csrf-hunter
model: inherit
CSRF specialist (H1 #57). Use for testing state-changing actions without proper token validation, SameSite cookie bypass, and CSRF in JSON/API endpoints.
dast-devils-advocate
model: inherit
Adversarial validator for DAST findings. Attempts to DISPROVE each finding and DOWNGRADE severity. Catches inflated reports, unverified assumptions, and theoretical-only bugs. Dispatch after /validate
file-upload
model: inherit
File Upload vulnerability specialist (H1 #39). Use for testing upload restrictions, content-type bypass, extension filtering, path traversal in filenames, and web shell upload scenarios.
graphql-audit
model: inherit
GraphQL API security specialist. Use for introspection analysis, query complexity attacks, injection testing, authorization bypass, and batching abuse on GraphQL endpoints.
idor-hunter
model: inherit
IDOR / BOLA specialist (H1 #55, OWASP API1:2023). Use for testing insecure direct object references and broken object level authorization across web apps, APIs, GraphQL endpoints, multi-tenant SaaS, m
info-disclosure
model: haiku
Information Disclosure specialist (H1 #18, CWE-200/209/215/538/668/798). Use for finding exposed sensitive data: stack traces, debug endpoints, config files, environment variables, API keys, .git/.env
js-analyzer
model: inherit
JavaScript static analysis agent for client-side security review. Use for analyzing JS bundles, finding hardcoded secrets, tracing DOM XSS source-sink flows, identifying postMessage handlers, extracti
llm-ai-hunter
model: inherit
LLM and Agentic AI vulnerability specialist. Covers OWASP LLM Top 10 v2025 (LLM01-LLM10) and OWASP Agentic AI Top 10 (AA-01..AA-10). Dispatcher passes subtype — 'prompt-injection', 'indirect-injection
monitor
model: haiku
Continuous monitoring agent for authorized bug bounty programs. Modes: 'baseline' captures initial state, 'check' detects changes, 'scope' re-syncs platform scope. Runs in background.
nuclei-writer
model: inherit
Custom nuclei template builder. Use when you've found a pattern that should be checked across multiple targets or when existing templates miss a specific vulnerability. Provide the vulnerability detai
oauth-hunter
model: inherit
OAuth 2.0 / 2.1, OpenID Connect (OIDC), SAML SSO, and JWT specialist. Dispatcher passes subtype — 'oauth', 'oidc', 'saml', or 'jwt' — in the task; falls back to inference. Use for redirect_uri / retur
open-redirect
model: inherit
Open Redirect specialist (H1 #38). Use for testing URL redirect parameters, login/logout flows, OAuth callbacks, and any endpoint that redirects based on user input.
poc-builder
model: inherit
Bug bounty PoC and report builder. Use after confirming a vulnerability to create minimal reproduction steps, self-contained HTML demonstration pages, curl-based reproduction scripts, and platform-rea
privilege-escalation
model: inherit
Privilege Escalation specialist (H1 #26). Use for testing vertical and horizontal privilege escalation, role manipulation, admin endpoint access, and permission boundary violations.
quality-check
model: inherit
Report quality scorer. Use BEFORE submitting any report to validate completeness, clarity, title strength, CVSS accuracy, PoC quality, and overall report grade. Provide the draft report path or conten
race-condition
model: inherit
Race Condition specialist (H1 #29). Use for testing TOCTOU flaws, double-spend, parallel request abuse on balance operations, coupon redemption, and any non-idempotent state changes.
rce-hunter
model: inherit
Remote Code Execution specialist (H1 #70). Use for testing command injection, template injection (SSTI), deserialization, expression language injection, and any vector that achieves server-side code e
recon-ranker
model: inherit
Attack surface ranker. Takes recon output + brain data, produces P1/P2/Kill prioritized attack plan with concrete curl commands for each P1 target. Use after recon to decide what to test first.
recon
model: inherit
Reconnaissance agent for target enumeration. Use for subdomain discovery, port scanning, service fingerprinting, tech stack identification, and OSINT gathering. Specify scope and depth: 'passive' for
report-writer
model: inherit
Security report generation agent. Use for compiling findings into formal penetration test reports, executive summaries, technical write-ups, and bug bounty submissions. Provide the findings directory
sast-danger-mapper
model: inherit
Maps dangerous operations in a source file: memory ops, type casts, arithmetic near trust boundaries, free/dealloc patterns. Pattern matching task — list what you see, don't speculate. Use via /sast c
sast-devils-advocate
model: inherit
Adversarial validator for SAST findings. Your ONLY job is to DISPROVE the candidate. Find every reason it's not exploitable. If you can't disprove it, it survives. Use via /sast command.
sast-entry-mapper
model: inherit
Maps entry points where untrusted data enters a source file. Lists every function that receives external input with data type, size constraints, and initial validation. Use via /sast command.
sast-exploit-builder
model: inherit
Builds working exploits from confirmed SAST findings. Takes a confirmed crash, develops it into a full exploit. Tier 1 (DoS) → Tier 5 (code execution). Use via /sast command after PoC confirmation.
sast-file-ranker
model: inherit
Source file attack surface ranker. Reads a repository, scores every source file 1-5 by exploitability. Outputs ranked JSON for per-file hunting. Use via /sast command.
sast-flow-tracer
model: claude-opus-4-6
Traces data flow from entry points to dangerous operations. Cross-file reasoning to determine which entries can reach which dangers, and what validation exists in between. MUST run on Opus for reasoni
sast-gap-analyzer
model: claude-opus-4-6
Analyzes validation gaps in data flows. Takes traced flows and identifies where checks are missing, insufficient, or bypassable. The 'interaction reasoning' step — finds bugs that exist in the gaps be
sast-hunter
model: inherit
Focused PoC builder for SAST candidates. Receives a SPECIFIC candidate vulnerability that survived adversarial validation. Writes a PoC, compiles, runs with ASan, confirms or rejects. Use via /sast co
scope-check
model: inherit
Target scope validation agent. Use BEFORE any active testing to verify targets are in scope. Provide the target and the program name or scope file. Checks against .scope.txt, scope.yaml, and fetches l

Hooks (9)

eventmatcherruns
SubagentStop*uv run python3 $CLAUDE_PROJECT_DIR/tools/cost_hook.py
SubagentStop*uv run python3 $CLAUDE_PROJECT_DIR/tools/chain_pressure_hook.py
Stop*uv run python3 $CLAUDE_PROJECT_DIR/tools/cost_hook.py
SessionStart*echo '{"hookSpecificOutput":{"hookEventName":"SessionStart","additionalContext":"Bug bounty workspace active. Commands: /status /hunt /surface /resume /triage /chain /autopilot. Check scope FIRST."}}'
PreToolUseBashuv run python3 $CLAUDE_PROJECT_DIR/tools/scope_hook.py
PreToolUseWrite|Edituv run python3 $CLAUDE_PROJECT_DIR/tools/file_path_guard.py
PreToolUseWrite|Edituv run python3 $CLAUDE_PROJECT_DIR/tools/cvss_version_guard.py
PreToolUseWrite|Edituv run python3 $CLAUDE_PROJECT_DIR/tools/validity_guard.py
PostToolUseBashjq -r '.tool_input.command // empty' | { read -r cmd; if echo "$cmd" | grep -qE '^(curl|httpx|nuclei|ffuf|nmap|sqlmap|subfinder|katana|feroxbuster|amass|masscan|nikto) '; then uv run python3 "$CLAUDE_PROJECT_DIR/tools/cost_hook.py" 2>/dev/n

Cursor rules (9)

pentest-agents-chain-tablepentest-agents-hunting · alwayspentest-agents-identitiespentest-agents-mistakespentest-agents-never-submit · alwayspentest-agents-payloadspentest-agents-techniquespentest-agents-vendor-statuspentest-agents-waf-bypass-protocol

Permissions

deny (4)
Bash(rm -rf /)
Bash(rm -rf ~)
Bash(> /dev/sd*)
Bash(dd if=*of=/dev/*)
ask (0)
—
allow (66)
Bash(nmap:*)
Bash(httpx:*)
Bash(subfinder:*)
Bash(nuclei:*)
Bash(ffuf:*)
Bash(katana:*)
Bash(curl:*)
Bash(uv run python3:*)
Bash(python3 $CLAUDE_PROJECT_DIR/tools/*)
Bash(python3 tools/*)
Bash(dig:*)
Bash(whois:*)
Bash(host:*)
Bash(wafw00f:*)
Bash(testssl*)
Bash(nikto:*)
Bash(wpscan:*)
Bash(arjun:*)
Bash(gau:*)
Bash(waybackurls:*)
Bash(subjack:*)
Bash(feroxbuster:*)
Bash(amass:*)
Bash(masscan:*)
Bash(rustscan:*)
Bash(gowitness:*)
Bash(jwt_tool:*)
Bash(php:*)
Bash(psalm:*)
Bash(phpstan:*)
Bash(composer:*)
Bash(phpggc:*)
Bash(semgrep:*)
Bash(cppcheck:*)
Bash(jq:*)
Bash(grep:*)
Bash(sort:*)
Bash(uniq:*)
Bash(wc:*)
Bash(cat:*)
Bash(head:*)
Bash(tail:*)
Bash(mkdir:*)
Bash(ls:*)
Bash(git:*)
Bash(gh:*)
Read(*)
Write(recon/*)
Write(scans/*)
Write(js-analysis/*)
Write(poc/*)
Write(reports/*)
Write(findings.json)
Write(.scope.txt)
Write(scope.yaml)
Write(policy.md)
Write(hacktivity.md)
Write(ATTACK_SURFACE_RANKING.md)
Write(TRIAGE_REPORT.md)
Write(BRAIN.md)

Similar rigs

copied ✓