arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to…
Quick 7-Question Gate triage on a finding before writing a report. Kills N/A submissions before they happen. Faster than /validate — for quick go/no-go decisions. Usage: /triage
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
/triageContext preview
What this command does when you run it.
Quick 7-Question Gate triage on a finding before writing a report. Kills N/A submissions before they happen. Faster than /validate — for quick go/no-go decisions. Usage: /triage
description: Quick 7-Question Gate triage on a finding before writing a report. Kills N/A submissions before they happen. Faster than /validate — for quick go/no-go decisions. Usage: /triage
Quick triage to decide: submit or kill?
Use this before spending time writing a full report. If triage passes, run `/validate` for the full 4-gate check, then `/report`.
/triage
Describe the finding in one sentence. Example:
Answer YES or NO to each. First NO = kill it immediately.
Q1: Can I demonstrate this with a real HTTP request RIGHT NOW?
YES: I have the request/response already
NO: I need to look at more code first → KILL
Q2: Is this impact type accepted by the program?
YES: Bug class is on their accepted list
NO: They explicitly exclude this type → KILL
Q3: Is the vulnerable asset owned by and in scope for the program?
YES: Domain confirmed in-scope, not third-party
NO: Third-party service or excluded domain → KILL
Q4: Does this work without admin/privileged access?
YES: Regular user account is enough
NO: Requires admin → KILL (99% of programs)
Q5: Is this NOT already known/disclosed/documented behavior?
YES: Not in changelogs, not in disclosed reports
NO: It's documented as intended → KILL
Q6: Can I prove impact beyond "technically possible"?
YES: I have actual data in the response / action completed
NO: I only have a 200 status or error message → DOWNGRADE
Q7: Is this NOT on the never-submit list?
YES: It's a real bug class
NO: Missing headers, self-XSS, open redirect alone, etc. → KILL or CHAINIf the bug class involves IDOR, BOLA, auth bypass, ATO, or privilege escalation, you must prove it across identities:
Blank answers fail this check. If you cannot prove cross-account impact, kill it.
Typical scanner hits that still need a real PoC:
Kill immediately if ANY of these are true:
[ ] "Admin can do X" = not a bug [ ] "Could theoretically lead to..." = no PoC = not a bug [ ] Bug requires 3+ preconditions simultaneously [ ] Finding is a missing header, missing flag, missing DMARC [ ] SSRF with DNS callback only, no data returned [ ] Open redirect with no OAuth chain or ATO path [ ] Self-XSS (only affects your own account) [ ] Introspection only (no IDOR, no auth bypass shown) [ ] Rate limit on login/contact/search (Cloudflare covers it)
If it's on the never-submit list BUT you can chain it:
Open redirect → OAuth code theft → ATO = report the chain SSRF DNS → internal service access = data = report the chain CORS → credentialed data exfil PoC = report the chain Prompt injection → IDOR via chatbot = report the chain
If you can't build the chain today → KILL IT.
**GO:** "All 7 pass. Run /validate for full check, then /report."
**KILL [reason]:**
**DOWNGRADE:**
AI-powered bug bounty hunting toolkit that works with or without subscription.
Repo: shuvonsec/claude-bug-bounty
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to…
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot…
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent.…
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when…
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata,…
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in…