/intel
On-demand intelligence fetch for a target — CVEs, disclosed reports, new features. Wraps learn.py + hunt memory context. Usage: /intel target.com
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/intel
Context preview
What this command does when you run it.
On-demand intelligence fetch for a target — CVEs, disclosed reports, new features. Wraps learn.py + hunt memory context. Usage: /intel target.com
Command definition
intel.mddescription: On-demand intelligence fetch for a target — CVEs, disclosed reports, new features. Wraps learn.py + hunt memory context. Usage: /intel target.com
/intel
Fetch actionable intelligence for a target.
What This Does
1. Runs `learn.py` for CVEs and advisories matching the target's tech stack 2. Fetches HackerOne Hacktivity for the target (via HackerOne MCP if available) 3. Cross-references with hunt memory — flags untested CVEs and new endpoints 4. Outputs prioritized intel with hunt recommendations
Usage
/intel target.com
Output
INTEL: target.com
═══════════════════════════════════════
ALERTS:
[CRITICAL] CVE-2026-XXXX — Next.js middleware bypass (CVSS 9.1)
target.com runs Next.js 14.2.3 (vulnerable). Patch: 14.2.4.
→ You haven't tested this endpoint yet. Hunt candidate.
[HIGH] New feature detected: /api/v3/billing/invoices
Not in your tested_endpoints list. 3 new paths.
→ New = unreviewed. Priority hunt target.
[INFO] 2 new disclosed reports on HackerOne for target.com
→ Read for methodology insights before hunting.
MEMORY CONTEXT:
Last hunted: 2026-03-24 (2 days ago)
Tech stack: Next.js 14.2.3, GraphQL, PostgreSQL
Untested CVEs: 1 critical, 0 high
Data Sources
| Source | What | Auth required? | |---|---|---| | `learn.py` — NVD | CVEs matching tech stack | No | | `learn.py` — GitHub Advisory | Security advisories | No | | `learn.py` — HackerOne Hacktivity | Disclosed reports | No | | HackerOne MCP (if connected) | Program stats, policy | No (public) | | Hunt memory | Previously tested endpoints | Local files |
Read more
description: On-demand intelligence fetch for a target — CVEs, disclosed reports, new features. Wraps learn.py + hunt memory context. Usage: /intel target.com
/intel
Fetch actionable intelligence for a target.
What This Does
1. Runs `learn.py` for CVEs and advisories matching the target's tech stack 2. Fetches HackerOne Hacktivity for the target (via HackerOne MCP if available) 3. Cross-references with hunt memory — flags untested CVEs and new endpoints 4. Outputs prioritized intel with hunt recommendations
Usage
/intel target.com
Output
INTEL: target.com ═══════════════════════════════════════ ALERTS: [CRITICAL] CVE-2026-XXXX — Next.js middleware bypass (CVSS 9.1) target.com runs Next.js 14.2.3 (vulnerable). Patch: 14.2.4. → You haven't tested this endpoint yet. Hunt candidate. [HIGH] New feature detected: /api/v3/billing/invoices Not in your tested_endpoints list. 3 new paths. → New = unreviewed. Priority hunt target. [INFO] 2 new disclosed reports on HackerOne for target.com → Read for methodology insights before hunting. MEMORY CONTEXT: Last hunted: 2026-03-24 (2 days ago) Tech stack: Next.js 14.2.3, GraphQL, PostgreSQL Untested CVEs: 1 critical, 0 high
Data Sources
| Source | What | Auth required? | |---|---|---| | `learn.py` — NVD | CVEs matching tech stack | No | | `learn.py` — GitHub Advisory | Security advisories | No | | `learn.py` — HackerOne Hacktivity | Disclosed reports | No | | HackerOne MCP (if connected) | Program stats, policy | No (public) | | Hunt memory | Previously tested endpoints | Local files |
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Open command - /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command

