arsenal
Show which external bug-bounty tools are installed on this machine and print install hints…
Launch the local Hunt Dashboard — one live view of leads, recon surface, findings, reports, screenshot galleries, and the memory flywheel. Usage: /dashboard [--port 8777] | /dashboard --export dashboard.html
$ npx -y skills add awarexone/agentic-bug-hunter --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
/dashboardContext preview
What this command does when you run it.
Launch the local Hunt Dashboard — one live view of leads, recon surface, findings, reports, screenshot galleries, and the memory flywheel. Usage: /dashboard [--port 8777] | /dashboard --export dashboard.html
description: Launch the local Hunt Dashboard — one live view of leads, recon surface, findings, reports, screenshot galleries, and the memory flywheel. Usage: /dashboard [--port 8777] | /dashboard --export dashboard.html
Spin up a single live view of the current hunt. A hunt's state is normally scattered across `memory/leads/<target>.jsonl`, `recon/<target>/`, `findings/`, `reports/`, screenshot `gallery.html` files, and `hunt-memory/*.jsonl` — the dashboard reads all of it and shows it in one place, so stale high-priority leads (Critical Rule 6) and the memory flywheel stop being invisible.
Pure stdlib, zero dependencies. Binds to `127.0.0.1` only.
/dashboard # serve at http://127.0.0.1:8777 /dashboard --port 9000 # custom port /dashboard --export report.html # write a shareable self-contained snapshot
Run directly:
tools/hunt_dashboard.py serve --port 8777 tools/hunt_dashboard.py export -o dashboard.html
> Not to be confused with `tools/dashboard.py`, the in-terminal ANSI progress > bar shown *while* a recon/hunt runs. This is the persistent **web view** of > everything a hunt has accumulated.
red **stale HIGH leads** alert (HIGH-priority `new` leads untouched ≥2 days).
→ parked → killed), untouched-first, with priority chips and per-lead age.
newest first, clickable (served safely from within the repo root).
| Path | Returns | |---|---| | `/` | the dashboard (auto-refreshes every 30s) | | `/api/state` | the same data as JSON — for scripting or other tools | | `/file?path=<rel>` | a finding/report, restricted to the repo root |
**Host-header allow-list** (loopback + the bind host + any `--allow-host`) blocks **DNS-rebinding** — a malicious page pointing its domain at your loopback still sends a foreign `Host` and gets a `403`.
only viewable extensions are served.
nosniff`), never as active HTML — a recon/PoC-captured response can't run JS in the dashboard's origin and exfil `/api/state`.
dashboard itself, so a malicious captured value cannot execute.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Repo: shuvonsec/claude-bug-bounty
Show which external bug-bounty tools are installed on this machine and print install hints…
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate →…
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count,…
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding,…
Build an exploit chain — given bug A, finds B and C to combine for higher severity and…
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum,…