Source

elementalsouls/claude-bughunter

83 skills · 11.7K combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
bb-methodology Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do nex…
elementalsouls/claude-bughunter
192
2
report-writing Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first …
elementalsouls/claude-bughunter
181
3
hunt-auth-bypass Hunting skill for auth bypass vulnerabilities. Built from 12 public bug bounty reports across SAML XSW / parser-diffe…
elementalsouls/claude-bughunter
175
4
offensive-osint Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks…
elementalsouls/claude-bughunter
169
5
web2-recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), U…
elementalsouls/claude-bughunter
167
6
hunt-rce Hunting skill for rce vulnerabilities. Built from 67 public bug bounty reports. Use when hunting rce on any target.
elementalsouls/claude-bughunter
166
7
bug-bounty Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source…
elementalsouls/claude-bughunter
165
8
hunt-xss Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target. …
elementalsouls/claude-bughunter
165
9
bugcrowd-reporting Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no e…
elementalsouls/claude-bughunter
164
10
hunt-oauth Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any targe…
elementalsouls/claude-bughunter
164
11
hunt-sqli Hunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports including modern NoSQL injection (Roc…
elementalsouls/claude-bughunter
164
12
hunt-ssrf Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOn…
elementalsouls/claude-bughunter
163
13
bb-local-toolkit Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for…
elementalsouls/claude-bughunter
161
14
evidence-hygiene Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to …
elementalsouls/claude-bughunter
161
15
hunt-ato Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1) password reset flaws (host-header i…
elementalsouls/claude-bughunter
161
16
hunt-cache-poison Hunting skill for cache poison vulnerabilities. Built from 10 public bug bounty reports including X-Forwarded-Host po…
elementalsouls/claude-bughunter
161
17
hunt-ssti Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rail…
elementalsouls/claude-bughunter
161
18
hunt-subdomain Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps …
elementalsouls/claude-bughunter
161
19
hunt-idor Hunting skill for idor vulnerabilities. Built from 26 public bug bounty reports. Use when hunting idor on any target.
elementalsouls/claude-bughunter
160
20
web3-audit Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, …
elementalsouls/claude-bughunter
160
21
hunt-mfa-bypass Hunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive endpoints (password change, email chan…
elementalsouls/claude-bughunter
159
22
hunt-business-logic Hunting skill for business logic vulnerabilities. Built from 12 public bug bounty reports. Covers coupon-race-stackin…
elementalsouls/claude-bughunter
158
23
hunt-csrf Hunting skill for csrf vulnerabilities. Built from 15 public bug bounty reports including modern variants — SameSite=…
elementalsouls/claude-bughunter
158
24
hunt-dispatch Skill-set loader for /hunt orchestrator. Fingerprints the target, picks the right platform attack skills, and loads t…
elementalsouls/claude-bughunter
158
25
hunt-graphql Hunting skill for graphql vulnerabilities. Built from 12 public bug bounty reports across IDOR via node() / GID, muta…
elementalsouls/claude-bughunter
158
26
hunt-race-condition Hunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 sin…
elementalsouls/claude-bughunter
158
27
osint-methodology Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers th…
elementalsouls/claude-bughunter
158
28
redteam-report-template Client-facing red-team deliverable format — codifies the Subject / Observations / Description / Impact / Recommendati…
elementalsouls/claude-bughunter
158
29
triage-validation Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-reje…
elementalsouls/claude-bughunter
158
30
hunt-api-misconfig Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. Mass assignment: send…
elementalsouls/claude-bughunter
157
31
hunt-file-upload Hunt file upload bugs — RCE via webshell, XSS via SVG/HTML, SSRF via XXE in DOCX, path traversal via filename. Bypass…
elementalsouls/claude-bughunter
157
32
hunt-http-smuggling Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). Cause: front-end proxy and back-end server disagree on wher…
elementalsouls/claude-bughunter
157
33
hunt-xxe Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (…
elementalsouls/claude-bughunter
157
34
redteam-mindset Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built fro…
elementalsouls/claude-bughunter
157
35
hunt-llm-ai Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling,…
elementalsouls/claude-bughunter
156
36
hunt-saml Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by r…
elementalsouls/claude-bughunter
156
37
vmware-vcenter-attack VMware vSphere / vCenter Server external attack matrix — version fingerprinting, the high-impact CVE chain (CVE-2021-…
elementalsouls/claude-bughunter
156
38
enterprise-vpn-attack External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix N…
elementalsouls/claude-bughunter
155
39
hunt-cloud-misconfig Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket pol…
elementalsouls/claude-bughunter
155
40
hunt-sharepoint Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration…
elementalsouls/claude-bughunter
155
41
meme-coin-audit Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), So…
elementalsouls/claude-bughunter
155
42
apk-redteam-pipeline End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jad…
elementalsouls/claude-bughunter
154
43
cloud-iam-deep Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-d…
elementalsouls/claude-bughunter
154
44
hunt-aspnet Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parse…
elementalsouls/claude-bughunter
154
45
hunt-misc Hunting skill for misc vulnerabilities. Built from 225 public bug bounty reports. Use when hunting misc on any target.
elementalsouls/claude-bughunter
154
46
m365-entra-attack Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vector…
elementalsouls/claude-bughunter
154
47
security-arsenal Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with…
elementalsouls/claude-bughunter
154
48
okta-attack Okta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analys…
elementalsouls/claude-bughunter
152
49
supply-chain-attack-recon External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusio…
elementalsouls/claude-bughunter
152
50
mid-engagement-ir-detection Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-t…
elementalsouls/claude-bughunter
150
Page 1 · 83 total Next