Автономный поиск уязвимостей и баг-баунти
★ 8.2 · security
Agentic-Bug-Hunter is a Claude Code skill that covers the complete bug bounty pipeline — recon, pre-hunt research, vulnerability hunting, validation, and report writing — within a single workflow. It includes A→B→C bug-chaining tables (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO), bypass references for SSRF IP, open redirect, and file upload, plus language-specific grep patterns for JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, and Rust unwrap. A dedicated LLM/AI security module covers prompt injection, indirect injection, ASCII smuggling, and the ASI01–ASI10 vulnerability classes. The built-in 7-Question Gate and four validation checkpoints eliminate theoretical findings before submission. Designed for security researchers running structured hunts on HackerOne or Bugcrowd who need to move systematically from subdomain enumeration through PoC generation and CVSS 3.1 scoring.
- #bug-bounty
- #vulnerability-hunting
- #penetration-testing
- #recon
- #code-audit
- #llm-security