Ross ROSS = Recommend OSS · open-source software intelligence for agents

elementalsouls/Claude-BugHunter

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices. observed · 2026-08-28

github.com/elementalsouls/Claude-BugHunter · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

77/100

  • Activity 99
  • Release rhythm 87
  • Longevity 8

Flags: young

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 10
  • age_days: 120
  • days_rel: 89
  • days_push: 7
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

3801 stars · 588 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

A Claude Code skill bundle that turns Claude into a bug-hunting and red-team assistant, with 83 skills, 15 slash commands, and 681 disclosed-report patterns across 24 vulnerability classes. It includes enterprise attack matrices, triage validation gates, VRT severity mapping, and Burp MCP integration for authorized security engagements.

Use cases

  • run recon on an in-scope bug bounty target and rank attack surface
  • hunt web vulnerabilities like XSS, SSRF, or IDOR using curated payload and bypass patterns
  • assess enterprise platforms such as M365/Entra, Okta, or vCenter for known CVE chains
  • validate and triage findings before submitting a HackerOne report
  • generate client-facing red-team reports with proper evidence hygiene and PII redaction
  • practice on training platforms like DVWA, OWASP Juice Shop, or Hacker101

When to choose

  • you use Claude Code for authorized bug bounty or red-team work and want curated methodology and payloads
  • you need auditable, cited vulnerability patterns from disclosed HackerOne reports
  • you want scope-aware validation gates and VRT-aligned severity mapping built into your workflow

When to avoid

  • you lack authorization for the targets you plan to test
  • you need a standalone scanner rather than an AI-assisted skill bundle inside Claude Code
  • you don't use Claude Code or an Anthropic-compatible agent runtime

Facets

plugin · maturity active

penetration-testing security mcp prompt-engineering developer-tools security penetration-testing developer-tools cli cross-platform windows claude-code claude-skills bug-bounty red-team offensive-security vulnerability-assessment hackerone burp-suite skill-bundle ethical-hacking automation macos linux

2 sources

Member repositories

RepositoryRoleHealth v2
elementalsouls/Claude-BugHuntermain77

For agents

markdown · JSON · MCP: product_card(name="elementalsouls/Claude-BugHunter")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem