/cors
Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposure, suffix/prefix regex bypass, scheme downgrade. Usage: /cors <url> [--cookie "session=..."] | /cors -l urls.txt
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/cors
Context preview
What this command does when you run it.
Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposure, suffix/prefix regex bypass, scheme downgrade. Usage: /cors <url> [--cookie "session=..."] | /cors -l urls.txt
Command definition
cors.mddescription: Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposure, suffix/prefix regex bypass, scheme downgrade. Usage: /cors <url> [--cookie "session=..."] | /cors -l urls.txt
/cors
Find CORS misconfigurations that let an attacker page read authenticated responses cross-origin. Sends a battery of crafted `Origin` headers and inspects the `Access-Control-Allow-Origin` / `Access-Control-Allow-Credentials` reply.
Usage
/cors https://api.target.com/me
/cors https://api.target.com/me --cookie "session=abcd1234"
/cors -l recon/target.com/urls/api-endpoints.txt --json
Run directly:
tools/cors_scanner.py https://api.target.com/me --cookie "session=..."
What it tests
| Origin sent | Detects | |---|---| | `https://evil.example` | arbitrary-origin reflection | | `null` | sandboxed-iframe / data: URI trust | | `https://api.target.com.evil.example` | weak `endsWith` (suffix) regex | | `https://notapi.target.com` | weak `startsWith` (prefix) regex | | `https://attacker.api.target.com` | blanket subdomain trust (chains w/ takeover) | | `http://api.target.com` | https→http scheme downgrade |
Severity
- **CRITICAL** — reflects attacker origin **with** `ACAC: true` (cookie-auth cross-origin read).
- **HIGH** — `null` origin trusted with credentials.
- **MEDIUM** — reflects attacker origin without credentials (exploitable when auth is a non-cookie token), or trusts http downgrade.
- **INFO** — `ACAO: *` with no credentials (usually intended public CORS).
Why a credentialed reflection is the win
`ACAO: <attacker>` + `ACAC: true` means `fetch(url, {credentials:'include'})` from an attacker page returns the victim's authenticated response body — full account-data exfil. Pass `--cookie` with a live session to confirm the credentialed path.
Chain
CORS data-read → harvest CSRF token / PII / API keys from the response → escalate to ATO. A subdomain-trust CORS bug + a [subdomain takeover](takeover.md) on that subdomain = a clean credentialed-read exploit.
Read more
description: Scan an endpoint for CORS misconfiguration — arbitrary-origin reflection, null-origin trust, credential exposure, suffix/prefix regex bypass, scheme downgrade. Usage: /cors <url> [--cookie "session=..."] | /cors -l urls.txt
/cors
Find CORS misconfigurations that let an attacker page read authenticated responses cross-origin. Sends a battery of crafted `Origin` headers and inspects the `Access-Control-Allow-Origin` / `Access-Control-Allow-Credentials` reply.
Usage
/cors https://api.target.com/me /cors https://api.target.com/me --cookie "session=abcd1234" /cors -l recon/target.com/urls/api-endpoints.txt --json
Run directly:
tools/cors_scanner.py https://api.target.com/me --cookie "session=..."
What it tests
| Origin sent | Detects | |---|---| | `https://evil.example` | arbitrary-origin reflection | | `null` | sandboxed-iframe / data: URI trust | | `https://api.target.com.evil.example` | weak `endsWith` (suffix) regex | | `https://notapi.target.com` | weak `startsWith` (prefix) regex | | `https://attacker.api.target.com` | blanket subdomain trust (chains w/ takeover) | | `http://api.target.com` | https→http scheme downgrade |
Severity
- **CRITICAL** — reflects attacker origin **with** `ACAC: true` (cookie-auth cross-origin read).
- **HIGH** — `null` origin trusted with credentials.
- **MEDIUM** — reflects attacker origin without credentials (exploitable when auth is a non-cookie token), or trusts http downgrade.
- **INFO** — `ACAO: *` with no credentials (usually intended public CORS).
Why a credentialed reflection is the win
`ACAO: <attacker>` + `ACAC: true` means `fetch(url, {credentials:'include'})` from an attacker page returns the victim's authenticated response body — full account-data exfil. Pass `--cookie` with a live session to confirm the credentialed path.
Chain
CORS data-read → harvest CSRF token / PII / API keys from the response → escalate to ATO. A subdomain-trust CORS bug + a [subdomain takeover](takeover.md) on that subdomain = a clean credentialed-read exploit.
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Open command - /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command

