Source

xiaolai/claude-bughunter

50 skills · 68 combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
hunt-subdomain Hunting skill for subdomain vulnerabilities. Built from 11 public bug bounty reports. Use when hunting subdomain on a…
xiaolai/claude-bughunter
3
2
bug-bounty Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source…
xiaolai/claude-bughunter
2
3
hunt-api-misconfig Hunt API security misconfiguration — mass assignment, JWT attacks, prototype pollution, CORS, HTTP verb tampering. Ma…
xiaolai/claude-bughunter
2
4
hunt-llm-ai Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use, ASCII smuggling, agentic …
xiaolai/claude-bughunter
2
5
hunt-oauth Hunting skill for oauth vulnerabilities. Built from 10 public bug bounty reports. Use when hunting oauth on any targe…
xiaolai/claude-bughunter
2
6
hunt-race-condition Hunting skill for race condition vulnerabilities. Built from 3 public bug bounty reports. Use when hunting race condi…
xiaolai/claude-bughunter
2
7
hunt-rce Hunting skill for rce vulnerabilities. Built from 67 public bug bounty reports. Use when hunting rce on any target.
xiaolai/claude-bughunter
2
8
hunt-saml Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW1-XSW8) — modify Assertion while keeping Signature vali…
xiaolai/claude-bughunter
2
9
hunt-sharepoint Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration…
xiaolai/claude-bughunter
2
10
hunt-sqli Hunting skill for sqli vulnerabilities. Built from 8 public bug bounty reports. Use when hunting sqli on any target.
xiaolai/claude-bughunter
2
11
hunt-ssti Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rail…
xiaolai/claude-bughunter
2
12
hunt-xxe Hunting skill for xxe vulnerabilities. Built from 4 public bug bounty reports. Use when hunting xxe on any target.
xiaolai/claude-bughunter
2
13
offensive-osint Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks…
xiaolai/claude-bughunter
2
14
osint-methodology Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers th…
xiaolai/claude-bughunter
2
15
redteam-mindset Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT.
xiaolai/claude-bughunter
2
16
redteam-report-template Client-facing red-team deliverable format — codifies the Subject / Observations / Description / Impact / Recommendati…
xiaolai/claude-bughunter
2
17
security-arsenal Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with…
xiaolai/claude-bughunter
2
18
apk-redteam-pipeline End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jad…
xiaolai/claude-bughunter
1
19
bb-local-toolkit Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source…
xiaolai/claude-bughunter
1
20
bb-methodology Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do nex…
xiaolai/claude-bughunter
1
21
bugcrowd-reporting Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no e…
xiaolai/claude-bughunter
1
22
cloud-iam-deep Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-d…
xiaolai/claude-bughunter
1
23
enterprise-vpn-attack External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix N…
xiaolai/claude-bughunter
1
24
evidence-hygiene Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to …
xiaolai/claude-bughunter
1
25
hunt-aspnet Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parse…
xiaolai/claude-bughunter
1
26
hunt-ato Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1) password reset flaws (host header i…
xiaolai/claude-bughunter
1
27
hunt-auth-bypass Hunting skill for auth bypass vulnerabilities. Built from 4 public bug bounty reports. Use when hunting auth bypass o…
xiaolai/claude-bughunter
1
28
hunt-business-logic Hunting skill for business logic vulnerabilities. Built from 7 public bug bounty reports. Use when hunting business l…
xiaolai/claude-bughunter
1
29
hunt-cache-poison Hunting skill for cache poison vulnerabilities. Built from 4 public bug bounty reports. Use when hunting cache poison…
xiaolai/claude-bughunter
1
30
hunt-cloud-misconfig Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket pol…
xiaolai/claude-bughunter
1
31
hunt-csrf Hunting skill for csrf vulnerabilities. Built from 10 public bug bounty reports. Use when hunting csrf on any target.
xiaolai/claude-bughunter
1
32
hunt-dispatch Skill-set loader for /hunt orchestrator.
xiaolai/claude-bughunter
1
33
hunt-file-upload Hunt file upload bugs — RCE via webshell, XSS via SVG/HTML, SSRF via XXE in DOCX, path traversal via filename. Bypass…
xiaolai/claude-bughunter
1
34
hunt-graphql Hunting skill for graphql vulnerabilities. Built from 3 public bug bounty reports. Use when hunting graphql on any ta…
xiaolai/claude-bughunter
1
35
hunt-http-smuggling Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). Cause: front-end proxy and back-end server disagree on wher…
xiaolai/claude-bughunter
1
36
hunt-idor Hunting skill for idor vulnerabilities. Built from 26 public bug bounty reports. Use when hunting idor on any target.
xiaolai/claude-bughunter
1
37
hunt-mfa-bypass Hunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive endpoints (password change, email chan…
xiaolai/claude-bughunter
1
38
hunt-misc Hunting skill for misc vulnerabilities. Built from 225 public bug bounty reports. Use when hunting misc on any target.
xiaolai/claude-bughunter
1
39
hunt-ssrf Hunting skill for ssrf vulnerabilities. Built from 9 public bug bounty reports. Use when hunting ssrf on any target.
xiaolai/claude-bughunter
1
40
hunt-xss Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target.
xiaolai/claude-bughunter
1
41
m365-entra-attack Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vector…
xiaolai/claude-bughunter
1
42
meme-coin-audit Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), So…
xiaolai/claude-bughunter
1
43
mid-engagement-ir-detection Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-t…
xiaolai/claude-bughunter
1
44
okta-attack Okta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analys…
xiaolai/claude-bughunter
1
45
report-writing Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first …
xiaolai/claude-bughunter
1
46
supply-chain-attack-recon External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusio…
xiaolai/claude-bughunter
1
47
triage-validation Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-reje…
xiaolai/claude-bughunter
1
48
vmware-vcenter-attack VMware vSphere / vCenter Server external attack matrix — version fingerprinting, the high-impact CVE chain (CVE-2021-…
xiaolai/claude-bughunter
1
49
web2-recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), U…
xiaolai/claude-bughunter
1
50
web3-audit Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, …
xiaolai/claude-bughunter
1