claude-bughunter
A skill and command bundle for authorized bug bounty and external red-team work in Claude Code: methodology, chain templates and reports
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Includes offensive techniques and vulnerability exploitation chains
- Runs recon tools and network commands against targets
- Intended only for authorized testing, with responsibility on the user
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add plugins/claude-bughunterDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run one by one in the Claude Code chat
/plugin marketplace add elementalsouls/claude-bughunter
/plugin install claude-bughunter@elementalsoulsInstall the plugin: /plugin marketplace add elementalsouls/Claude-BugHunter, then /plugin install claude-bughunter@elementalsouls. Or clone the repository and run bash scripts/install.sh.
Other ways from the author
/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsoulsSkills and commands load under the claude-bughunter prefix and update with the plugin version.
This is third-party code. Review the repository files before installing.
What it does
The bundle turns Claude Code into an assistant for vulnerability hunting and external red-team work. It is built from several layers: a five-phase non-linear methodology and operator discipline, dozens of hunt-* skills by web vulnerability class with detection patterns, payloads, filter-bypass tables and chain templates, plus enterprise perimeter attack chains (M365 and Entra, Okta, vCenter, SSL-VPN, SharePoint, cloud IAM) with current CVE chains. A separate layer handles triage, reporting and evidence hygiene: a seven-question gate before submission, VRT-aware severity, out-of-scope rebuttals and PII redaction. Skills load automatically from a plain-English description of what you are testing. There is Burp integration over MCP, a standalone cbh CLI and an engagement-folder scaffolder. Offensive domains require the target to be in scope and the work to be authorized.
Who it is for. For security professionals: bug hunters, pentesters and red-teamers working within an authorized scope.
Good fit when
- An authorized bug bounty is underway and you need recon and surface prioritization
- You need detection patterns and chains for a specific vulnerability class
- You need to prepare triage and a report with severity assessment
Not a fit when
- You have no written authorization and defined scope
- The target is not yours and not part of a testing program
Example request
I am testing an in-scope HackerOne target, run recon and rank the attack surfaceLimitations
The bundle is intended only for authorized testing, research and education; keeping to scope and staying legal is the user's responsibility. Some features need separate setup: the cbh CLI installs via pipx, the engagement-folder scaffolder ships only with a repo clone, and Burp integration over MCP is wired separately. The slash commands and the hunt engine work only in Claude Code, while the knowledge layer ports to other environments. MIT licensed.
How to disable. Remove the plugin: /plugin uninstall claude-bughunter@elementalsouls. If you installed by copying, remove the skill and command folders from ~/.claude/.
Security check
- Includes offensive techniques and vulnerability exploitation chains
- Runs recon tools and network commands against targets
- Intended only for authorized testing, with responsibility on the user
README in short
The README describes a bundle of dozens of skills and fifteen slash commands that turn Claude Code into a bug-hunting and external red-team assistant. The material is split into layers: methodology and operator mindset, hunt-* skills by vulnerability class based on disclosed HackerOne reports, attack chains against enterprise platforms, and a layer for triage, reporting and evidence hygiene. Installation is as a plugin via the repository marketplace or by copying with install.sh or install.ps1. The SKILL.md format ports across several environments, including Claude Code, OpenCode and Codex CLI. There is Burp integration over MCP, a cbh CLI and an engagement-folder scaffolder. MIT licensed.
FAQ
Is this legal?
The bundle targets authorized testing within a defined scope. It includes scope checks, out-of-scope assessment and evidence hygiene, but authorization for the target must be yours.
Do I have to install every skill?
The plugin installs all skills and commands under the claude-bughunter prefix. With a copy install you can move only the skill folders you need.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents