/arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/arsenal
Context preview
What this command does when you run it.
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Command definition
arsenal.mddescription: Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
/arsenal
Inspect the external tool inventory used by this plugin.
Usage
/arsenal # full status table (installed vs missing)
/arsenal nuclei # show install hint for a single tool
What it covers
`tools/external_arsenal.sh` knows about ~50 tools across:
- **Recon** — subfinder, amass, assetfinder, bbot, theHarvester, dnsrecon, massdns, puredns, shuffledns, knockpy
- **Probing** — httpx, dnsx, naabu, smap, aquatone, eyewitness
- **Crawling** — katana, gau, waybackurls, waymore, hakrawler, gospider, cariddi
- **Fuzzing** — ffuf, feroxbuster, gobuster, arjun, x8
- **Scanning** — nuclei, dalfox, xsstrike, ghauri, sqlmap, fuxploider, log4j-scan, linkfinder
- **Secrets** — trufflehog, noseyparker, gitleaks, shhgit, git-hound
- **Cloud** — s3scanner, cloud_enum, cloudfail, scoutsuite
- **Takeover** — dnsreaper, subjack
- **Bypass** — byp4xx, whatwaf, unwaf
- **JWT/auth** — jwt_tool
- **Scope** — bbscope
- **Mobile** — mobsf, apkleaks, objection, jadx
- **OSINT** — maigret, pywhat, sublert
- **Misc** — gf, qsreplace, anew, interactsh-client
Sourcing the helper
Other scripts source `external_arsenal.sh` to gate optional code paths:
. "$(dirname "$0")/external_arsenal.sh"
if _have nuclei; then nuclei -l hosts.txt -severity high; fi
Use `_have <tool>` rather than `command -v` so the install-hint table stays the single source of truth for what is and isn't wired in.
Read more
description: Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
/arsenal
Inspect the external tool inventory used by this plugin.
Usage
/arsenal # full status table (installed vs missing) /arsenal nuclei # show install hint for a single tool
What it covers
`tools/external_arsenal.sh` knows about ~50 tools across:
- **Recon** — subfinder, amass, assetfinder, bbot, theHarvester, dnsrecon, massdns, puredns, shuffledns, knockpy
- **Probing** — httpx, dnsx, naabu, smap, aquatone, eyewitness
- **Crawling** — katana, gau, waybackurls, waymore, hakrawler, gospider, cariddi
- **Fuzzing** — ffuf, feroxbuster, gobuster, arjun, x8
- **Scanning** — nuclei, dalfox, xsstrike, ghauri, sqlmap, fuxploider, log4j-scan, linkfinder
- **Secrets** — trufflehog, noseyparker, gitleaks, shhgit, git-hound
- **Cloud** — s3scanner, cloud_enum, cloudfail, scoutsuite
- **Takeover** — dnsreaper, subjack
- **Bypass** — byp4xx, whatwaf, unwaf
- **JWT/auth** — jwt_tool
- **Scope** — bbscope
- **Mobile** — mobsf, apkleaks, objection, jadx
- **OSINT** — maigret, pywhat, sublert
- **Misc** — gf, qsreplace, anew, interactsh-client
Sourcing the helper
Other scripts source `external_arsenal.sh` to gate optional code paths:
. "$(dirname "$0")/external_arsenal.sh" if _have nuclei; then nuclei -l hosts.txt -severity high; fi
Use `_have <tool>` rather than `command -v` so the install-hint table stays the single source of truth for what is and isn't wired in.
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command - /cors
Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposure, suffix/prefix regex bypass, scheme downgrade. Usage: /cors <url> [--cookie "session=..."] | /cors -l urls.txt
Open command

