/scope-aggregate
Pull every in-scope asset for a bug bounty program across HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi in one shot. Uses bbscope when authenticated, otherwise the public bounty-targets-data dump. Output is one host per line, ready to feed into /recon. Usage:
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/scope-aggregate
Context preview
What this command does when you run it.
Pull every in-scope asset for a bug bounty program across HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi in one shot. Uses bbscope when authenticated, otherwise the public bounty-targets-data dump. Output is one host per line, ready to feed into /recon. Usage:
Command definition
scope-aggregate.mddescription: Pull every in-scope asset for a bug bounty program across HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi in one shot. Uses bbscope when authenticated, otherwise the public bounty-targets-data dump. Output is one host per line, ready to feed into /recon. Usage: /scope-aggregate <program-handle> [--platform h1|bc|it|ywh|imf|all]
/scope-aggregate
Aggregate the full in-scope asset list for a public program without copy-pasting from the program page.
Usage
/scope-aggregate shopify
/scope-aggregate yelp --platform h1
/scope-aggregate --list-programs --platform h1
What it does
`tools/scope_aggregator.sh` runs in two strategies:
1. **bbscope** (`sw33tLie/bbscope`) — authenticated multi-platform pull. Best freshness, but needs platform tokens in env (`H1_USERNAME`, `H1_API_KEY`, `BUGCROWD_EMAIL`, etc.). Tries it first when installed. 2. **bounty-targets-data dump** (`arkadiyt/bounty-targets-data`) — hourly public dump of every public program. No auth needed; fallback if bbscope returns nothing.
Output: `~/.cache/bbhunt/scope/<program>.scope.txt` (one host per line, with wildcards stripped to bare domains).
Next steps
/scope ~/.cache/bbhunt/scope/<program>.scope.txt # human verification
/recon ~/.cache/bbhunt/scope/<program>.scope.txt # feed into recon (domain-list mode)
`recon_engine.sh` already supports passing a file in place of a domain — it reads each line as a pre-resolved scope entry and skips subdomain enumeration (programs without wildcards benefit hugely).
When NOT to use
- Programs with `*.target.com`-style wildcards: aggregator gives you the
*seed*; still run `/recon target.com` to brute the wildcard.
- Private programs you cannot install bbscope creds for: bounty-targets-data
only covers public scope, so private invites won't appear.
Read more
description: Pull every in-scope asset for a bug bounty program across HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi in one shot. Uses bbscope when authenticated, otherwise the public bounty-targets-data dump. Output is one host per line, ready to feed into /recon. Usage: /scope-aggregate <program-handle> [--platform h1|bc|it|ywh|imf|all]
/scope-aggregate
Aggregate the full in-scope asset list for a public program without copy-pasting from the program page.
Usage
/scope-aggregate shopify /scope-aggregate yelp --platform h1 /scope-aggregate --list-programs --platform h1
What it does
`tools/scope_aggregator.sh` runs in two strategies:
1. **bbscope** (`sw33tLie/bbscope`) — authenticated multi-platform pull. Best freshness, but needs platform tokens in env (`H1_USERNAME`, `H1_API_KEY`, `BUGCROWD_EMAIL`, etc.). Tries it first when installed. 2. **bounty-targets-data dump** (`arkadiyt/bounty-targets-data`) — hourly public dump of every public program. No auth needed; fallback if bbscope returns nothing.
Output: `~/.cache/bbhunt/scope/<program>.scope.txt` (one host per line, with wildcards stripped to bare domains).
Next steps
/scope ~/.cache/bbhunt/scope/<program>.scope.txt # human verification /recon ~/.cache/bbhunt/scope/<program>.scope.txt # feed into recon (domain-list mode)
`recon_engine.sh` already supports passing a file in place of a domain — it reads each line as a pre-resolved scope entry and skips subdomain enumeration (programs without wildcards benefit hugely).
When NOT to use
- Programs with `*.target.com`-style wildcards: aggregator gives you the
*seed*; still run `/recon target.com` to brute the wildcard.
- Private programs you cannot install bbscope creds for: bounty-targets-data
only covers public scope, so private invites won't appear.
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Open command - /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command

