/spray
Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray <url> --mode <mode> --users <file>
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/spray
Context preview
What this command does when you run it.
Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray <url> --mode <mode> --users <file>
Command definition
spray.mddescription: Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray <url> --mode <mode> --users <file> --passes <file>
/spray
Live credential spray against an authentication endpoint. **The most dangerous tool in this plugin.** Read the guards section before using.
Modes
| Mode | Use case | Engine | |---|---|---| | `http-form` | Custom login page (POST username/password) | Built-in Python + urllib | | `oauth` | OAuth password grant (`grant_type=password`) | Built-in Python + urllib | | `o365` | Microsoft 365 / Azure AD | `trevorspray` | | `okta` | Okta SSO | `trevorspray` |
Usage
# HTTP form (simplest)
/spray https://target.com/login --mode http-form \
--users users.txt --passes ranked.txt
# HTTP form with CSRF token extraction
/spray https://target.com/login --mode http-form \
--users users.txt --passes ranked.txt \
--post-data "user={USER}&pass={PASS}&_token={CSRF}" \
--csrf-extract 'name="_token" value="([^"]+)"' \
--success-regex "Welcome" \
--fail-regex "Invalid credentials"
# OAuth password grant
/spray https://target.com/oauth/token --mode oauth \
--users users.txt --passes ranked.txt \
--oauth-client-id mobile-app \
--oauth-scope "openid profile"
# Microsoft 365 (TREVORspray)
/spray https://login.microsoftonline.com --mode o365 \
--users users.txt --passes ranked.txt
# Dry-run (pre-flight only, no real attempts)
/spray https://target.com/login --mode http-form \
--users users.txt --passes ranked.txt --dry-runHard guards (cannot be bypassed)
1. **Typed-hostname confirmation** — Pre-flight prints the target hostname and requires you to type it back. Prevents spraying the wrong target. 2. **Lockout warning** — Calculates per-user failed-attempt count from your `--passes` size and warns if it exceeds typical lockout thresholds. 3. **Audit log** — Every attempt is appended to `recon/<host>/spray/attempts-<timestamp>.jsonl`. Format: `{ts, round, user, pwd_sha256_prefix, status_code, looks_like_success, duration_ms}`. **Passwords are never logged in plaintext** — only their SHA-256 prefix. 4. **Spray order** — `pass[i] × all_users` per round (NOT brute-per-user). Each account sees at most 1 failed attempt per round.
Spray order example (3 users × 3 passwords)
Round 1: Password1! → alice, bob, charlie [delay]
Round 2: Welcome2025 → alice, bob, charlie [delay]
Round 3: Summer2024 → alice, bob, charlie
If `--continue-on-hit` is NOT set, spray stops at the first valid credentials.
Rate limiting
| Flag | Default | Effect | |---|---|---| | `--delay <sec>` | 1800 (30 min) | Sleep between rounds | | `--jitter <sec>` | 60 | Random ±jitter added to each delay | | `--aggressive` | off | Sets delay=60, jitter=10 (fast spray — use only when you have explicit permission and rate-limit allowance) |
For Microsoft 365 / Azure AD smart lockout: defaults are designed to stay well under the 10-min sliding window threshold. **Do not use `--aggressive` against O365** unless you've cleared it with the program.
Success detection (http-form mode)
The script checks these in order: 1. `--success-regex` matches response body → success 2. `--fail-regex` set + body does NOT match → success 3. HTTP redirect (3xx) to a path that is NOT the login page → success (heuristic) 4. None of the above → not success
If you get false positives, supply `--fail-regex` (e.g. `--fail-regex "Invalid|incorrect|wrong password"`) to anchor detection.
Success detection (oauth mode)
HTTP 200 response with `"access_token"` field in JSON body → success. HTTP 4xx (typically 400 invalid_grant / 401) → fail.
Pre-flight output (what you see before any HTTP)
=============================================
SPRAY PRE-FLIGHT — target.com
=============================================
Target URL: https://target.com/login
Mode: http-form
Users file: users.txt (50 entries)
Passes file: ranked.txt (10 entries)
Total attempts: 500
Rounds: 10
Delay/round: 1800s + 60s jitter
Est. duration: ~5h
=============================================
[!] LEGAL / SCOPE REMINDER
[!] Credential spray requires EXPLICIT program permission...
Type the target hostname (target.com) to confirm: _
[!] LOCKOUT WARNING
[!] Per-user failed attempts (this run): 10
[!] Estimated accounts likely to be locked: ~80% of 50 = 40
Type 'yes' to proceed (anything else aborts): _
Skipping confirmations
`--i-understand` skips both prompts. **Only use after a clean dry-run and explicit program sign-off.** The flag's name is a deliberate friction point — you should be able to truthfully say "yes I understand the risks of spraying this target right now" before adding it.
Audit log format
{"ts":"2026-05-27T22:00:01Z","round":1,"user":"alice","pwd_sha256_prefix":"a3f2b8e1c0d4","status_code":401,"looks_like_success":false,"duration_ms":320}
{"ts":"2026-05-27T22:00:02Z","round":1,"user":"bob","pwd_sha256_prefix":"a3f2b8e1c0d4","status_code":302,"redirect_to":"/dashboard","looks_like_success":true,"duration_ms":410}Pipeline position
/wordlist-gen <target> -> ranked.txt
/breach-check ranked.txt -> ranked-ranked.txt (HIBP-validated)
/osint-employees <target> -> usernames.txt
/spray <login> --users usernames.txt --passes ranked-ranked.txt
Dependencies
- Built-in modes (http-form, oauth): pure Python 3.9+ stdlib
- TREVOR modes (o365, okta): `trevorspray` from `./install_tools.sh --with-credential-attack`
- `tools/scope_checker.py` for typed-confirmation logic (Python 3.9 compat)
Underlying tool
`tools/spray_orchestrator.sh <url> --mode ... --users ... --passes ...`
Read more
description: Password spray with hard guards — typed-hostname confirmation, lockout warning, audit log. Modes: http-form (custom login page), oauth (password grant), o365 + okta (via TREVORspray). Default delay 30min/round + 60s jitter. Usage /spray <url> --mode <mode> --users <file> --passes <file>
/spray
Live credential spray against an authentication endpoint. **The most dangerous tool in this plugin.** Read the guards section before using.
Modes
| Mode | Use case | Engine | |---|---|---| | `http-form` | Custom login page (POST username/password) | Built-in Python + urllib | | `oauth` | OAuth password grant (`grant_type=password`) | Built-in Python + urllib | | `o365` | Microsoft 365 / Azure AD | `trevorspray` | | `okta` | Okta SSO | `trevorspray` |
Usage
# HTTP form (simplest)
/spray https://target.com/login --mode http-form \
--users users.txt --passes ranked.txt
# HTTP form with CSRF token extraction
/spray https://target.com/login --mode http-form \
--users users.txt --passes ranked.txt \
--post-data "user={USER}&pass={PASS}&_token={CSRF}" \
--csrf-extract 'name="_token" value="([^"]+)"' \
--success-regex "Welcome" \
--fail-regex "Invalid credentials"
# OAuth password grant
/spray https://target.com/oauth/token --mode oauth \
--users users.txt --passes ranked.txt \
--oauth-client-id mobile-app \
--oauth-scope "openid profile"
# Microsoft 365 (TREVORspray)
/spray https://login.microsoftonline.com --mode o365 \
--users users.txt --passes ranked.txt
# Dry-run (pre-flight only, no real attempts)
/spray https://target.com/login --mode http-form \
--users users.txt --passes ranked.txt --dry-runHard guards (cannot be bypassed)
1. **Typed-hostname confirmation** — Pre-flight prints the target hostname and requires you to type it back. Prevents spraying the wrong target. 2. **Lockout warning** — Calculates per-user failed-attempt count from your `--passes` size and warns if it exceeds typical lockout thresholds. 3. **Audit log** — Every attempt is appended to `recon/<host>/spray/attempts-<timestamp>.jsonl`. Format: `{ts, round, user, pwd_sha256_prefix, status_code, looks_like_success, duration_ms}`. **Passwords are never logged in plaintext** — only their SHA-256 prefix. 4. **Spray order** — `pass[i] × all_users` per round (NOT brute-per-user). Each account sees at most 1 failed attempt per round.
Spray order example (3 users × 3 passwords)
Round 1: Password1! → alice, bob, charlie [delay] Round 2: Welcome2025 → alice, bob, charlie [delay] Round 3: Summer2024 → alice, bob, charlie
If `--continue-on-hit` is NOT set, spray stops at the first valid credentials.
Rate limiting
| Flag | Default | Effect | |---|---|---| | `--delay <sec>` | 1800 (30 min) | Sleep between rounds | | `--jitter <sec>` | 60 | Random ±jitter added to each delay | | `--aggressive` | off | Sets delay=60, jitter=10 (fast spray — use only when you have explicit permission and rate-limit allowance) |
For Microsoft 365 / Azure AD smart lockout: defaults are designed to stay well under the 10-min sliding window threshold. **Do not use `--aggressive` against O365** unless you've cleared it with the program.
Success detection (http-form mode)
The script checks these in order: 1. `--success-regex` matches response body → success 2. `--fail-regex` set + body does NOT match → success 3. HTTP redirect (3xx) to a path that is NOT the login page → success (heuristic) 4. None of the above → not success
If you get false positives, supply `--fail-regex` (e.g. `--fail-regex "Invalid|incorrect|wrong password"`) to anchor detection.
Success detection (oauth mode)
HTTP 200 response with `"access_token"` field in JSON body → success. HTTP 4xx (typically 400 invalid_grant / 401) → fail.
Pre-flight output (what you see before any HTTP)
============================================= SPRAY PRE-FLIGHT — target.com ============================================= Target URL: https://target.com/login Mode: http-form Users file: users.txt (50 entries) Passes file: ranked.txt (10 entries) Total attempts: 500 Rounds: 10 Delay/round: 1800s + 60s jitter Est. duration: ~5h ============================================= [!] LEGAL / SCOPE REMINDER [!] Credential spray requires EXPLICIT program permission... Type the target hostname (target.com) to confirm: _ [!] LOCKOUT WARNING [!] Per-user failed attempts (this run): 10 [!] Estimated accounts likely to be locked: ~80% of 50 = 40 Type 'yes' to proceed (anything else aborts): _
Skipping confirmations
`--i-understand` skips both prompts. **Only use after a clean dry-run and explicit program sign-off.** The flag's name is a deliberate friction point — you should be able to truthfully say "yes I understand the risks of spraying this target right now" before adding it.
Audit log format
{"ts":"2026-05-27T22:00:01Z","round":1,"user":"alice","pwd_sha256_prefix":"a3f2b8e1c0d4","status_code":401,"looks_like_success":false,"duration_ms":320}
{"ts":"2026-05-27T22:00:02Z","round":1,"user":"bob","pwd_sha256_prefix":"a3f2b8e1c0d4","status_code":302,"redirect_to":"/dashboard","looks_like_success":true,"duration_ms":410}Pipeline position
/wordlist-gen <target> -> ranked.txt /breach-check ranked.txt -> ranked-ranked.txt (HIBP-validated) /osint-employees <target> -> usernames.txt /spray <login> --users usernames.txt --passes ranked-ranked.txt
Dependencies
- Built-in modes (http-form, oauth): pure Python 3.9+ stdlib
- TREVOR modes (o365, okta): `trevorspray` from `./install_tools.sh --with-credential-attack`
- `tools/scope_checker.py` for typed-confirmation logic (Python 3.9 compat)
Underlying tool
`tools/spray_orchestrator.sh <url> --mode ... --users ... --passes ...`
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Open command - /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command

