awarexone/Agentic-Bug-Hunter
AI-powered bug bounty hunting toolkit that works with or without subscription.
ARCHETYPE
Skill Collector
Ten-plus skills loaded on demand. A procedural-knowledge library.
Copy this rig
# review before running: this installs third-party code
$ npx degit awarexone/Agentic-Bug-Hunter/.claude ./rig-agentic-bug-hunter # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit awarexone/Agentic-Bug-Hunter/skills/agentic-app-audit .claude/skills/agentic-app-audit $ npx degit awarexone/Agentic-Bug-Hunter/skills/argus .claude/skills/argus $ npx degit awarexone/Agentic-Bug-Hunter/skills/bb-methodology .claude/skills/bb-methodology $ npx degit awarexone/Agentic-Bug-Hunter/skills/bug-bounty .claude/skills/bug-bounty $ npx degit awarexone/Agentic-Bug-Hunter/skills/cicd-security .claude/skills/cicd-security $ npx degit awarexone/Agentic-Bug-Hunter/skills/client-reverse .claude/skills/client-reverse $ npx degit awarexone/Agentic-Bug-Hunter/skills/cloud-pentest .claude/skills/cloud-pentest $ npx degit awarexone/Agentic-Bug-Hunter/skills/credential-attack .claude/skills/credential-attack $ npx degit awarexone/Agentic-Bug-Hunter/skills/graphql-audit .claude/skills/graphql-audit $ npx degit awarexone/Agentic-Bug-Hunter/skills/llm-redteam .claude/skills/llm-redteam $ npx degit awarexone/Agentic-Bug-Hunter/skills/mcp-server-audit .claude/skills/mcp-server-audit $ npx degit awarexone/Agentic-Bug-Hunter/skills/meme-coin-audit .claude/skills/meme-coin-audit $ npx degit awarexone/Agentic-Bug-Hunter/skills/mobile-pentest .claude/skills/mobile-pentest $ npx degit awarexone/Agentic-Bug-Hunter/skills/report-writing .claude/skills/report-writing $ npx degit awarexone/Agentic-Bug-Hunter/skills/security-arsenal .claude/skills/security-arsenal $ npx degit awarexone/Agentic-Bug-Hunter/skills/triage-validation .claude/skills/triage-validation $ npx degit awarexone/Agentic-Bug-Hunter/skills/web2-recon .claude/skills/web2-recon $ npx degit awarexone/Agentic-Bug-Hunter/skills/web2-vuln-classes .claude/skills/web2-vuln-classes $ npx degit awarexone/Agentic-Bug-Hunter/skills/web3-audit .claude/skills/web3-audit
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (19)
agentic-app-auditargusbb-methodologybug-bountycicd-securityclient-reversecloud-pentestcredential-attackgraphql-auditllm-redteammcp-server-auditmeme-coin-auditmobile-pentestreport-writingsecurity-arsenaltriage-validationweb2-reconweb2-vuln-classesweb3-audit
Hooks (1)
| event | matcher | runs |
|---|---|---|
| Stop | * | [ -f tools/memory_gc.py ] && python3 -m tools.memory_gc --rotate >/dev/null 2>&1 || true |
Slash commands (41)
/arsenal/autopilot/breach-check/bypass-403/chain/cloud-recon/cors/crlf/dashboard/domxss/hunt/intel/jwt-scan/llm-app-audit/llm-redteam/memory-gc/nosqli/oob/osint-employees/param-discover/pickup/poc/portscan/recon/remember/report/sast/scan-cves/scope-aggregate/scope/screenshot/secrets-hunt/spray/surface/takeover/token-scan/triage/validate/verify/web3-audit/wordlist-gen
Similar rigs
Gabson0x/bountyforge
all round pentest skill
Skill Collector 1.3k tok ·
elementalsouls/Claude-BugHunter
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
Skill Collector 6.7k tok ·
andreaderuvo/argus
Self-hosted workspace for existing AI coding agents: tmux sessions, files, reports and hand-offs together on desktop or phone.
Pragmatist 17.9k tok ·
AhmedAl-Ashwal/claude-code-global-config
Global Claude Code configuration: one CLAUDE.md with unified phases for every project, a /report session-summary command, and the design-md skill. English and Arabic README.
Pragmatist 1.8k tok ·