Полный конвейер bug bounty для Claude Code
★ 8.1 · general
claude-bug-bounty is a Claude Code skill that covers the full bug bounty pipeline — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope review, source code audit), vulnerability hunting, validation, and report writing. It addresses dozens of vulnerability classes: IDOR, SSRF, XSS, SQLi, XXE, race conditions, OAuth/OIDC chains, HTTP smuggling, cache poisoning, subdomain takeover, cloud misconfigurations, and LLM-specific attacks including prompt injection, ASCII smuggling, and ASI01–ASI10 categories. The skill includes bypass tables for SSRF, open redirect, and file upload; language-specific grep patterns for JS, Python, PHP, Go, Ruby, and Rust; A→B→C bug chaining methodology; and four validation gates with a submission checklist, CVSS 3.1 scoring, and PoC generation templates. Suited for hunters at any stage — starting a new target, auditing AI features, or finalizing a report.