codexstar69/bug-hunter
Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds security vulnerabilities, logic errors, and runtime bugs — then
ARCHETYPE
Skill Collector
Ten-plus skills loaded on demand. A procedural-knowledge library.
Copy this rig
# review before running: this installs third-party code
$ npx degit codexstar69/bug-hunter/skills ./rig-bug-hunter/skills MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit codexstar69/bug-hunter/skills/commit-security-scan .claude/skills/commit-security-scan $ npx degit codexstar69/bug-hunter/skills/doc-lookup .claude/skills/doc-lookup $ npx degit codexstar69/bug-hunter/skills/fixer .claude/skills/fixer $ npx degit codexstar69/bug-hunter/skills/hunter .claude/skills/hunter $ npx degit codexstar69/bug-hunter/skills/recon .claude/skills/recon $ npx degit codexstar69/bug-hunter/skills/referee .claude/skills/referee $ npx degit codexstar69/bug-hunter/skills/security-review .claude/skills/security-review $ npx degit codexstar69/bug-hunter/skills/skeptic .claude/skills/skeptic $ npx degit codexstar69/bug-hunter/skills/threat-model-generation .claude/skills/threat-model-generation $ npx degit codexstar69/bug-hunter/skills/vulnerability-validation .claude/skills/vulnerability-validation
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (10)
Similar rigs
gavraz/recon
tmux-native dashboard for managing Claude Code agents
Minimalist 797 tok ·
lamngockhuong/termote
Self-hosted PWA to control Claude Code, Codex, GitHub Copilot or any terminal from your phone or desktop. Single Go binary streaming tmux/psmux/Herdr sessions to xterm.js, native or in a container.
Pragmatist 20.9k tok ·
crewship-ai/crewship
Self-hosted runtime for AI coding agents. Real Linux containers, your hardware, your keys, your data.
Pragmatist 3.1k tok ·
thewaltero/mythos-router
The leaked Anthropic reasoning protocol. Running locally. Zero-drift coding with Strict Write Discipline and adaptive Claude Opus 5 thinking. Mythos
Minimalist 2.2k tok ·