Sep 24, 2026

Claude-BugHunter Turns Claude Code Into a Scope-Safe Bug-Hunting Operator

A 5k-star bundle installs 83 security skills, 15 slash commands, and a validation gate that keeps authorized bug-bounty and red-team work inside its written scope.

#tutorial#security#agent-tools

A general-purpose agent forgets its discipline the moment a target gets interesting — it drafts findings before validating them and loses evidence hygiene at exactly the wrong time. Claude-BugHunter, a 5k-star skill bundle for Claude Code, encodes the operating habits of authorized bug-bounty and external red-team work: 83 skills — the 58 hunt-* webapp skills among them curated from 681 disclosed HackerOne reports — loaded automatically by topic, with validation gates that fire before anything gets submitted.

Why This Skill Matters

Four layers stack. Think — bb-methodology and redteam-mindset — carries the workflow and operator discipline. Hunt webapps puts 58 hunt-* skills behind per-class detection patterns, payloads, bypass tables, and chain templates across 24 core vulnerability classes. Hit the perimeter adds enterprise platform chains for M365/Entra, Okta, vCenter, SSL-VPN appliances, SharePoint, and cloud IAM. Ship it handles validation and reporting — the 7-Question Gate, VRT-aware severity, PII redaction.

Everything triggers from plain English. Describe what you are testing and the relevant skill loads; the README is explicit that no skill is invoked by name.

Installation

The fastest path is the plugin route, from inside Claude Code:

/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsouls

All 83 skills and 15 commands load namespaced under claude-bughunter:, and nothing is copied into ~/.claude/. The copy install is the alternative: clone the repo and run bash scripts/install.sh (macOS/Linux) or pwsh ./scripts/install.ps1 (Windows), which copies skills and commands into ~/.claude/ and wires the hunt engagement scaffolder.

Real Workflow: Recon a Bug-Bounty Target

  1. Open Claude Code and state the engagement in plain English — the target, and that it is an in-scope program. Recon and OSINT skills load on topic.
  2. Let the bundle map the surface. The README's illustrative transcript shows the shape: subdomain enumeration, live-host checks, a ranked list of where to start. Treat it as an illustration — your own run produces your own numbers.
  3. Hunt the ranked surface. The hunt-* skills load per vulnerability class as your probing touches them.
  4. Before anything is submitted, the 7-Question Gate fires — it asks whether the asset is in scope (Q3) and on the program's accepted-impact list (Q2). Findings that fail the gate do not leave the machine as reports.
  5. Report through the platform-specific skills: HackerOne, Bugcrowd with VRT-aware severity, Intigriti, or Immunefi.

Second Workflow: One Install, Five Harnesses

The skills are plain Agent Skills, and the copy installer ports them: bash scripts/install.sh --all --burp-mcp detects installed harnesses and writes to each one's path — Claude Code, OpenCode, OpenAI Codex CLI, Hermes Agent, and Google AntiGravity, with the --burp-mcp flag wiring the Burp MCP server into each. The README notes the knowledge layer ports to all five, while the slash commands and the /hunt engine stay Claude-Code-only by design.

Tips

  • Use the cbh terminal runner if you prefer orchestration outside the chat — pipx install git+https://github.com/elementalsouls/Claude-BugHunter installs it standalone.
  • Anthropic's runtime cyber safeguards block vulnerability-exploitation requests by default, even authorized ones. The README's guidance is to enroll in Anthropic's free Cyber Verification Program rather than reword an engagement to look defensive.
  • On Opus 5, some higher-risk cyber requests fall back to Opus 4.8 with a notice — the README calls this out because in a long agentic run the label is easy to scroll past.
  • Engagement context belongs in the session explicitly: /hunt states the authorized, scope-bounded, remediable-finding frame on its first turn for exactly this reason.

When Not to Use This

The bundle covers the external attack surface only, and says so plainly: internal Active Directory attacks, C2 frameworks, post-exploitation and persistence, and evasion tradecraft are all deliberate exclusions, not gaps — and the README holds out a future bundle only for the internal AD and post-exploit territory. And the authorization boundary is absolute — these skills are for assets you own or have written authorization to assess: in-scope bug-bounty targets, engagement letters, CTF challenges, your own infrastructure.


See the leaderboard for more skills.