~ / rigs / awarexone / Agentic-Bug-Hunter

awarexone/Agentic-Bug-Hunter

AI-powered bug bounty hunting toolkit that works with or without subscription.

↗ GitHub ★ 5,261 mit updated 6d ago project Claude CodeCodex Claude plugin
share on X
ARCHETYPE
Skill Collector
Ten-plus skills loaded on demand. A procedural-knowledge library.
CONTEXT TAX · EVERY TURN
~5.5k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
1/5
No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit awarexone/Agentic-Bug-Hunter/.claude ./rig-agentic-bug-hunter  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit awarexone/Agentic-Bug-Hunter/skills/agentic-app-audit .claude/skills/agentic-app-audit
$ npx degit awarexone/Agentic-Bug-Hunter/skills/argus .claude/skills/argus
$ npx degit awarexone/Agentic-Bug-Hunter/skills/bb-methodology .claude/skills/bb-methodology
$ npx degit awarexone/Agentic-Bug-Hunter/skills/bug-bounty .claude/skills/bug-bounty
$ npx degit awarexone/Agentic-Bug-Hunter/skills/cicd-security .claude/skills/cicd-security
$ npx degit awarexone/Agentic-Bug-Hunter/skills/client-reverse .claude/skills/client-reverse
$ npx degit awarexone/Agentic-Bug-Hunter/skills/cloud-pentest .claude/skills/cloud-pentest
$ npx degit awarexone/Agentic-Bug-Hunter/skills/credential-attack .claude/skills/credential-attack
$ npx degit awarexone/Agentic-Bug-Hunter/skills/graphql-audit .claude/skills/graphql-audit
$ npx degit awarexone/Agentic-Bug-Hunter/skills/llm-redteam .claude/skills/llm-redteam
$ npx degit awarexone/Agentic-Bug-Hunter/skills/mcp-server-audit .claude/skills/mcp-server-audit
$ npx degit awarexone/Agentic-Bug-Hunter/skills/meme-coin-audit .claude/skills/meme-coin-audit
$ npx degit awarexone/Agentic-Bug-Hunter/skills/mobile-pentest .claude/skills/mobile-pentest
$ npx degit awarexone/Agentic-Bug-Hunter/skills/report-writing .claude/skills/report-writing
$ npx degit awarexone/Agentic-Bug-Hunter/skills/security-arsenal .claude/skills/security-arsenal
$ npx degit awarexone/Agentic-Bug-Hunter/skills/triage-validation .claude/skills/triage-validation
$ npx degit awarexone/Agentic-Bug-Hunter/skills/web2-recon .claude/skills/web2-recon
$ npx degit awarexone/Agentic-Bug-Hunter/skills/web2-vuln-classes .claude/skills/web2-vuln-classes
$ npx degit awarexone/Agentic-Bug-Hunter/skills/web3-audit .claude/skills/web3-audit

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (19)

Hooks (1)

eventmatcherruns
Stop*[ -f tools/memory_gc.py ] && python3 -m tools.memory_gc --rotate >/dev/null 2>&1 || true

Slash commands (41)

/arsenal/autopilot/breach-check/bypass-403/chain/cloud-recon/cors/crlf/dashboard/domxss/hunt/intel/jwt-scan/llm-app-audit/llm-redteam/memory-gc/nosqli/oob/osint-employees/param-discover/pickup/poc/portscan/recon/remember/report/sast/scan-cves/scope-aggregate/scope/screenshot/secrets-hunt/spray/surface/takeover/token-scan/triage/validate/verify/web3-audit/wordlist-gen

Similar rigs

copied ✓