arsenal
Show which external bug-bounty tools are installed on this machine and print install hints…
Black-box audit of a DEPLOYED AI agent (not the MCP server) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR, excessive agency, privilege compromise. Usage: /llm-app-audit <agent-url-or-product>
$ npx -y skills add awarexone/agentic-bug-hunter --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
/llm-app-auditContext preview
What this command does when you run it.
Black-box audit of a DEPLOYED AI agent (not the MCP server) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR, excessive agency, privilege compromise. Usage: /llm-app-audit <agent-url-or-product>
description: Black-box audit of a DEPLOYED AI agent (not the MCP server) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR, excessive agency, privilege compromise. Usage: /llm-app-audit <agent-url-or-product>
Audit a live AI agent product as a black box: you are trying to make it *act* with its privileges on someone else's behalf, not just say something. Loads the `skills/agentic-app-audit` playbook.
| Attack | ASI | Deterministic oracle | |---|---|---| | Tool-call hijacking | ASI02 | OOB callback — the tool reaches your collaborator host (`tools/oob_listener.py`) | | Cross-session memory poisoning | ASI06 | plant canary as identity A, re-read as identity B | | Confused-deputy via tools | ASI02/03 | privileged record returned that the user's role can't access | | Agent-to-agent IDOR | ASI07 | agent A returns agent B's context | | Excessive agency | ASI08 | destructive action completes without the required confirmation | | Privilege compromise | ASI03 | invoke a tool outside the user's role |
tools/llm_redteam.py --url <endpoint> --category excessive-agency --json # tool-abuse probes tools/oob_listener.py --listen # confirm tool reach-out tools/verifiers/ (xss) # confirm insecure-output XSS at the sink
ASI alone is **Informational**. Chain to impact: injection → memory poisoning → affects every user; tool misuse → SSRF/IMDS with returned data; insecure output → stored XSS → session theft. Use TWO identities for anything cross-tenant and record the full turn sequence so triage can replay it verbatim.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Repo: shuvonsec/claude-bug-bounty
Show which external bug-bounty tools are installed on this machine and print install hints…
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate →…
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count,…
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding,…
Build an exploit chain — given bug A, finds B and C to combine for higher severity and…
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum,…