/submit
Draft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review.
$ npx -y skills add H-mmer/pentest-agents --skill submit --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/submit
Context preview
The summary Claude sees to decide when to auto-load this skill.
Draft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review.
SKILL.md
submit.SKILL.mdname: submit
description: "Draft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review."
disable-model-invocation: false
Prepare and submit a report for finding: $ARGUMENTS
Workflow: 0. Read `rules/identities.md` to learn which env vars hold the researcher handle, email alias, and API token for the platform identified in step 1. NEVER hardcode a username or email; always reference the env-var symbol. If a required var is unset, abort with `error: <VAR> is not set; refusing to guess` and surface it to the user. 1. Read `scope.yaml` to determine the platform and program handle. 2. Read the finding details from brain/findings/poc directory matching "$ARGUMENTS". 3. Use MCP tool `draft_report` to create a platform-formatted draft:
- Format title as: `[Vuln Type] in [Component] allows [Impact] via [Vector]`
- Include CVSS vector string (CVSS 3.1 for HackerOne, CVSS 4.0 for all others)
- Map vulnerability type to platform-specific taxonomy (H1 weakness IDs, Bugcrowd VRT)
- Include all reproduction steps, impact, and remediation
4. Show the draft to the user and ASK FOR CONFIRMATION before submitting. 5. ONLY after explicit user approval, use MCP tool `submit_report` to submit. 6. After submission, update the brain: `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> confirmed <technique> "Submitted as report #<id> on <platform>"` 7. Update findings.json status to "reported".
IMPORTANT: NEVER submit without showing the draft and getting explicit user confirmation.
Top-Tier Submission Discipline
Submission is a controlled release.
Before asking for approval, verify:
- `/validate` PASS or explicit accepted equivalent exists
- `/quality` score is acceptable and blocking issues are fixed
- `/dupcheck` result is included or intentionally skipped with reason
- all evidence paths exist on disk
- platform taxonomy, severity, and CVSS version match the platform
- no secrets, customer data, or prohibited artifacts are over-shared
- remediation is actionable and scoped to the root cause
Show the user the final title, severity, platform, target asset, evidence list, and any residual risk. If anything changed after draft generation, re-run quality before submission.
Read more
name: submit description: "Draft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review." disable-model-invocation: false
Prepare and submit a report for finding: $ARGUMENTS
Workflow: 0. Read `rules/identities.md` to learn which env vars hold the researcher handle, email alias, and API token for the platform identified in step 1. NEVER hardcode a username or email; always reference the env-var symbol. If a required var is unset, abort with `error: <VAR> is not set; refusing to guess` and surface it to the user. 1. Read `scope.yaml` to determine the platform and program handle. 2. Read the finding details from brain/findings/poc directory matching "$ARGUMENTS". 3. Use MCP tool `draft_report` to create a platform-formatted draft:
- Format title as: `[Vuln Type] in [Component] allows [Impact] via [Vector]`
- Include CVSS vector string (CVSS 3.1 for HackerOne, CVSS 4.0 for all others)
- Map vulnerability type to platform-specific taxonomy (H1 weakness IDs, Bugcrowd VRT)
- Include all reproduction steps, impact, and remediation
4. Show the draft to the user and ASK FOR CONFIRMATION before submitting. 5. ONLY after explicit user approval, use MCP tool `submit_report` to submit. 6. After submission, update the brain: `uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> confirmed <technique> "Submitted as report #<id> on <platform>"` 7. Update findings.json status to "reported".
IMPORTANT: NEVER submit without showing the draft and getting explicit user confirmation.
Top-Tier Submission Discipline
Submission is a controlled release.
Before asking for approval, verify:
- `/validate` PASS or explicit accepted equivalent exists
- `/quality` score is acceptable and blocking issues are fixed
- `/dupcheck` result is included or intentionally skipped with reason
- all evidence paths exist on disk
- platform taxonomy, severity, and CVSS version match the platform
- no secrets, customer data, or prohibited artifacts are over-shared
- remediation is actionable and scoped to the root cause
Show the user the final title, severity, platform, target asset, evidence list, and any residual risk. If anything changed after draft generation, re-run quality before submission.
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Repo: H-mmer/pentest-agents
Other skills on pentest-agents.
- /analyze
Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>
Open skill - /autopilot
Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying
Open skill - /brain
Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.
Open skill - /chain
Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)
Open skill - /correlate
Run the finding correlation engine to discover attack chains from individual findings.
Open skill - /cost
Show cost tracking and ROI for this engagement.
Open skill

