/remember
Log current finding or successful pattern to hunt memory. Auto-fills from /validate output if available. Usage: /remember
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/remember
Context preview
What this command does when you run it.
Log current finding or successful pattern to hunt memory. Auto-fills from /validate output if available. Usage: /remember
Command definition
remember.mddescription: Log current finding or successful pattern to hunt memory. Auto-fills from /validate output if available. Usage: /remember
/remember
Save a finding or successful pattern to persistent hunt memory.
What This Does
1. Auto-populates fields from session context (target, endpoint, vuln_class, technique) 2. If `/validate` was run in this session, pre-fills from validation output 3. Prompts you to confirm or edit before saving 4. Writes to `journal.jsonl` (always) + `patterns.jsonl` (if confirmed + payout > 0) 5. Updates the target profile's `tested_endpoints` and `findings`
Usage
/remember # after finding something
/remember --from-validate # explicitly pull from last /validate
Interactive Flow
REMEMBER — Log finding to hunt memory
Target: target.com (auto-detected)
Endpoint: /api/v2/users/{id}/orders (from session)
Vuln Class: idor (from session)
Technique: numeric_id_swap_with_put_method
Result: [confirmed / rejected / partial / informational]?
Severity: [critical / high / medium / low]?
Payout: $___?
Notes: ___?
Tags: [comma-separated]?
Save to hunt memory? [y/n]Minimum Required Fields
- target
- vuln_class
- endpoint
- result
What Gets Written
| Field | journal.jsonl | patterns.jsonl | target profile | |---|---|---|---| | Finding details | Always | If confirmed + payout > 0 | findings[] updated | | Tested endpoint | — | — | tested_endpoints[] updated | | Tech stack | — | From target profile | — |
Why This Matters
- Next time you hunt a target with similar tech stack, your successful patterns are suggested first
- `/pickup target.com` shows which endpoints you've tested and which remain
- Cross-target learning: patterns from target A inform hunting on target B
Read more
description: Log current finding or successful pattern to hunt memory. Auto-fills from /validate output if available. Usage: /remember
/remember
Save a finding or successful pattern to persistent hunt memory.
What This Does
1. Auto-populates fields from session context (target, endpoint, vuln_class, technique) 2. If `/validate` was run in this session, pre-fills from validation output 3. Prompts you to confirm or edit before saving 4. Writes to `journal.jsonl` (always) + `patterns.jsonl` (if confirmed + payout > 0) 5. Updates the target profile's `tested_endpoints` and `findings`
Usage
/remember # after finding something /remember --from-validate # explicitly pull from last /validate
Interactive Flow
REMEMBER — Log finding to hunt memory
Target: target.com (auto-detected)
Endpoint: /api/v2/users/{id}/orders (from session)
Vuln Class: idor (from session)
Technique: numeric_id_swap_with_put_method
Result: [confirmed / rejected / partial / informational]?
Severity: [critical / high / medium / low]?
Payout: $___?
Notes: ___?
Tags: [comma-separated]?
Save to hunt memory? [y/n]Minimum Required Fields
- target
- vuln_class
- endpoint
- result
What Gets Written
| Field | journal.jsonl | patterns.jsonl | target profile | |---|---|---|---| | Finding details | Always | If confirmed + payout > 0 | findings[] updated | | Tested endpoint | — | — | tested_endpoints[] updated | | Tech stack | — | From target profile | — |
Why This Matters
- Next time you hunt a target with similar tech stack, your successful patterns are suggested first
- `/pickup target.com` shows which endpoints you've tested and which remain
- Cross-target learning: patterns from target A inform hunting on target B
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Open command - /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command

