arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to…
Write a submission-ready bug bounty report. Generates H1/Bugcrowd/Intigriti/Immunefi format with CVSS 3.1 score, proof of concept, impact statement, and remediation. Run /validate first. Usage: /report
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
/reportContext preview
What this command does when you run it.
Write a submission-ready bug bounty report. Generates H1/Bugcrowd/Intigriti/Immunefi format with CVSS 3.1 score, proof of concept, impact statement, and remediation. Run /validate first. Usage: /report
description: Write a submission-ready bug bounty report. Generates H1/Bugcrowd/Intigriti/Immunefi format with CVSS 3.1 score, proof of concept, impact statement, and remediation. Run /validate first. Usage: /report
Generate a submission-ready bug bounty report.
Run `/validate` first. All 4 gates must pass before running this command.
Never write a report before validating. N/A submissions hurt your validity ratio.
/report
Provide when prompted:
1. Title following the formula: `[Bug Class] in [Endpoint] allows [actor] to [impact]` 2. Summary paragraph (impact-first, no "could potentially") 3. Vulnerability details with CVSS 3.1 score and vector string 4. Steps to Reproduce with copy-paste HTTP requests 5. Impact statement with quantification 6. Recommended fix (1-2 sentences, specific) 7. Supporting materials section
Always save the full report and the final triage guidance into the finding's folder. Do not leave the pre-submit checklist, references, escalation notes, or "one note before submitting" guidance only in terminal output.
Expected files:
findings/<target-or-program>-<bug-class>/ ├── hackerone-report.md # or bugcrowd-report.md / intigriti-report.md / immunefi-report.md ├── submission-notes.md # checklist, references, final caveats, submission note └── evidence/ # screenshots, curl output, response bodies when available
If `/validate` generated `submission-notes.md`, update that file instead of creating a second notes file.
If `validation.json` includes `scanner_summary`, keep that context attached to the finding folder so you can trace how the result graduated from a scanner hit to a validated finding.
1. **Never use:** "could potentially", "may allow", "might be possible" 2. **Always prove:** show actual data/action, not just "200 OK" 3. **Impact first:** sentence 1 = what attacker gets, not what the bug is 4. **Quantify:** how many users affected, what data type, $ amount 5. **Short:** triagers skim. < 600 words. 6. **Human:** write to a person, not a system
Common patterns:
IDOR read PII (any user, auth needed): → AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N = 6.5 Medium Auth bypass → admin (no auth): → AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H = 9.8 Critical SSRF → cloud metadata: → AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N = 9.1 Critical Stored XSS (any user, scope changed): → AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N = 8.2 High
Use when payout is being downgraded:
"This requires only a free account — no special privileges." "The exposed data includes [PII type], subject to GDPR/CCPA requirements." "An attacker can automate this — all [N] records in [X] minutes with a simple loop." "This is exploitable externally without any internal network access." "The impact is equivalent to a full data breach of [feature/data type]."
[ ] Title follows formula [ ] First sentence states exact impact [ ] HTTP request is copy-pasteable [ ] Response showing impact included [ ] Two accounts used (not self-testing) [ ] CVSS calculated and included [ ] Fix: 1-2 sentences [ ] No typos in endpoint/param names [ ] Under 600 words [ ] Severity matches impact (no overclaiming) [ ] NEVER used "could potentially"
AI-powered bug bounty hunting toolkit that works with or without subscription.
Repo: shuvonsec/claude-bug-bounty
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to…
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot…
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent.…
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when…
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata,…
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in…