claude-bughunter

A skill and command bundle for authorized bug bounty and external red-team work in Claude Code: methodology, chain templates and reports

Plugin

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Includes offensive techniques and vulnerability exploitation chains
  • Runs recon tools and network commands against targets
  • Intended only for authorized testing, with responsibility on the user
All reasons and checks

elementalsouls/claude-bughunter

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add plugins/claude-bughunter

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run one by one in the Claude Code chat

/plugin marketplace add elementalsouls/claude-bughunter
/plugin install claude-bughunter@elementalsouls

Checked against the repository on Sep 24, 2026, commit e9fea3d.

Text for your agent

Install the plugin: /plugin marketplace add elementalsouls/Claude-BugHunter, then /plugin install claude-bughunter@elementalsouls. Or clone the repository and run bash scripts/install.sh.

Other ways from the author
/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsouls

Skills and commands load under the claude-bughunter prefix and update with the plugin version.

This is third-party code. Review the repository files before installing.

What it does

The bundle turns Claude Code into an assistant for vulnerability hunting and external red-team work. It is built from several layers: a five-phase non-linear methodology and operator discipline, dozens of hunt-* skills by web vulnerability class with detection patterns, payloads, filter-bypass tables and chain templates, plus enterprise perimeter attack chains (M365 and Entra, Okta, vCenter, SSL-VPN, SharePoint, cloud IAM) with current CVE chains. A separate layer handles triage, reporting and evidence hygiene: a seven-question gate before submission, VRT-aware severity, out-of-scope rebuttals and PII redaction. Skills load automatically from a plain-English description of what you are testing. There is Burp integration over MCP, a standalone cbh CLI and an engagement-folder scaffolder. Offensive domains require the target to be in scope and the work to be authorized.

Who it is for. For security professionals: bug hunters, pentesters and red-teamers working within an authorized scope.

Good fit when

  • An authorized bug bounty is underway and you need recon and surface prioritization
  • You need detection patterns and chains for a specific vulnerability class
  • You need to prepare triage and a report with severity assessment

Not a fit when

  • You have no written authorization and defined scope
  • The target is not yours and not part of a testing program

Example request

I am testing an in-scope HackerOne target, run recon and rank the attack surface

Limitations

The bundle is intended only for authorized testing, research and education; keeping to scope and staying legal is the user's responsibility. Some features need separate setup: the cbh CLI installs via pipx, the engagement-folder scaffolder ships only with a repo clone, and Burp integration over MCP is wired separately. The slash commands and the hunt engine work only in Claude Code, while the knowledge layer ports to other environments. MIT licensed.

How to disable. Remove the plugin: /plugin uninstall claude-bughunter@elementalsouls. If you installed by copying, remove the skill and command folders from ~/.claude/.

Security check

  • Includes offensive techniques and vulnerability exploitation chains
  • Runs recon tools and network commands against targets
  • Intended only for authorized testing, with responsibility on the user

README in short

The README describes a bundle of dozens of skills and fifteen slash commands that turn Claude Code into a bug-hunting and external red-team assistant. The material is split into layers: methodology and operator mindset, hunt-* skills by vulnerability class based on disclosed HackerOne reports, attack chains against enterprise platforms, and a layer for triage, reporting and evidence hygiene. Installation is as a plugin via the repository marketplace or by copying with install.sh or install.ps1. The SKILL.md format ports across several environments, including Claude Code, OpenCode and Codex CLI. There is Burp integration over MCP, a cbh CLI and an engagement-folder scaffolder. MIT licensed.

FAQ

Is this legal?

The bundle targets authorized testing within a defined scope. It includes scope checks, out-of-scope assessment and evidence hygiene, but authorization for the target must be yours.

Do I have to install every skill?

The plugin installs all skills and commands under the claude-bughunter prefix. With a copy install you can move only the skill folders you need.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIclaude-bughunter

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.