AI-powered bug bounty hunting toolkit that works with or without subscription.
$ npx -y skills add awarexone/agentic-bug-hunter --agent claude-code
Repo: awarexone/agentic-bug-hunter
What's inside

uv tool install agentic-bug-hunter # install the CLI (or: pipx install agentic-bug-hunter)
bughunter setup # connect a free AI provider
Then hunt — straight from your terminal:
bughunter hunt target.com # recon → find → validate → report
…or drive it from inside Claude Code:
/hunt target.com
The CLI and AI hunting work on their own. Full recon also uses external tools (subfinder · httpx · nuclei · katana · ffuf · nmap) — install them with install_tools.sh from the repo. Output lands in ~/.bughunter/.
Agentic Bug Hunter finds real, reportable bugs, not theoretical ones. Point it at a target and it runs recon, tests for vulnerabilities, validates findings against a strict gate, and writes a submission-ready report for HackerOne, Bugcrowd, Intigriti, or Immunefi.
It remembers everything: patterns found on one target inform the next, and sessions pick up where they left off.
Works as a Claude Code plugin, or as a fully standalone CLI (bughunter) with no subscription required.
You no longer need Claude Code, Claude Pro, or any paid AI subscription.
Install once, use the bughunter command from any terminal on your machine:
git clone https://github.com/Awarexone/Agentic-Bug-Hunter.git
cd Agentic-Bug-Hunter
./install.sh --agent standalone
Rerun the same command after pulling updates. The installer detects and
refreshes the active managed bughunter command, including older installations
under /usr/local/bin or ~/.local/bin, while preserving your saved provider
configuration in ~/.bughunter/config.json.
To uninstall the standalone command while keeping its configuration:
./uninstall.sh --agent standalone
Use --purge-config to also delete ~/.bughunter/config.json. The uninstaller
also supports claude, opencode, pi, codex, agents, and all targets.
bughunter help # show every command
bughunter setup # choose your AI provider (Ollama is free + offline)
bughunter recon target.com # map the attack surface
bughunter hunt target.com # hunt for vulnerabilities
bughunter validate "finding" # 7-Question Gate on your finding
bughunter report # write a submission-ready report
bughunter chat # interactive AI hunting shell
bughunter providers # list all available AI providers
bughunter models # list models and show the selected one
bughunter status # check which provider is active
bughunter h target.com # short alias for hunt
bughunter r target.com # short alias for recon
bughunter v "finding" # short alias for validate
| Provider | Cost | Privacy | Speed | Get Started |
|---|---|---|---|---|
| Ollama | 100% free · runs locally | Full - stays on your machine | Fast | ollama pull qwen2.5:14b |
| Groq | Free tier available | Cloud | Very fast | console.groq.com → get API key |
| DeepSeek | Very cheap (v4-flash / v4-pro) | Cloud | Fast | platform.deepseek.com |
| Claude API | Paid | Cloud | Fast | console.anthropic.com |
| OpenAI | Paid | Cloud | Fast | platform.openai.com |
| Grok (xAI) | Paid | Cloud | Fast | console.x.ai → grok-4.5 |
| OpenRouter | Subscription / pay-as-you-go | Cloud | Fast | openrouter.ai/keys → get API key |
FAQ
agentic-bug-hunter is a Claude Code plugin with 19 hand-picked skills for security work, indexed on Flowy. Install it with the command on its page. It includes agentic-app-audit, argus, bb-methodology. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.
Is this plugin yours?
Claim it with GitHubSubmit a pluginPromote it