★ ★ ★LIVE51 SPECIALIZED SKILLS ACROSS 8 ATTACK DOMAINS · BUGGY AI·VIEW SKILLS →★ ★ ★
BUGGY
buggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leaked
★ NEWCLAUDE 3.7 AGENT · 51 SECURITY SKILLS

OFFENSIVE SECURITY
INTELLIGENCE VIA BUGGY

51 Production skills for bug hunting & red teaming. Built from 574+ HackerOne & Bugcrowd disclosures, audited via mandatory 7-Question Gate.

· · ·· · ·
A\
CLAUDE
Sonnet 3.7
BUGGY AGENT
51 Skills · Active
RECON ENGINE
Nuclei · ffuf
7-GATE TRIAGE
0% N/A · Cleared
[ REPO ]git clone https://github.com/bimoadis/Buggy.gitLIVE
22
WEB HUNTING SKILLS
CLAUDE CODE
100%
7-QUESTION GATE
REJECT SPECULATIVE
51
TOTAL PRODUCTION SKILLS
8 DOMAINS
[ TRIAGE QUALITY ]
VERIFIED EXPLOITS51/51
SPECULATIVE SUBMISSIONS0/51
[ ● SSR · ZERO FALSE POSITIVES ]
[ 51 SKILLS. ONE AGENT. ]
WEB HUNTINGAUTH & IDENTITYAPI & INFRAENTERPRISERED TEAMRECON & OSINTREPORTINGSPECIALIZED
[ ● SKILLS FOR AGENTS ]
ANALYSIS VERIFIED
[ ● 7-GATE PASS ]
[ CLAUDE SECURITY SKILLS ]

BUILT FOR OFFENSIVE
INTELLIGENCE

> EXPLORE (↕↓)

51 ready-to-use skills for Claude Code + Chat. Built from 574+ HackerOne disclosures. Copy and run directly in your Claude environment.

Web Hunting
Deep-dive skills for SQL injection, XSS, SSRF, RCE, business logic, and 15+ other web vulnerability classes — ...
LEARN MORE (22)
Auth & Identity
OAuth 2.0 flows, JWT attacks, ATO chains, SAML bypasses, and MFA bypass techniques drawn from 19–40 disclosed ...
LEARN MORE (5)
API & Infrastructure
Mass assignment, JWT/CORS flaws, GraphQL introspection, prototype pollution, cloud misconfiguration, and NTLM ...
LEARN MORE (4)
Enterprise Platforms
Attack chains for M365/Entra, Okta, VMware vCenter, SharePoint, IAM privilege escalation, and enterprise VPN l...
LEARN MORE (6)
Red Team
Full APK red-team pipeline, supply chain recon, IR detection evasion patterns, and red-team mindset for extern...
LEARN MORE (4)
Recon & OSINT
5-stage recon pipeline, asset-graph methodology, subdomain enumeration, identity-fabric mapping, and crypto tr...
LEARN MORE (3)
Reporting & Hygiene
7-Question Gate, report templates for H1/Bugcrowd/Intigriti/Immunefi, CVSS 3.1 scoring, evidence hygiene, and ...
LEARN MORE (5)
🔒
Specialized
Solidity/Rust smart contract audits for DeFi protocols and meme-coin rug-pull pattern detection for Web3 bug b...
LEARN MORE (2)
[ PRECISION TOOLS ]

51 SKILLS.
ONE AGENT.

Production-ready context bundles for SQLi, XSS, SSRF, OAuth, JWT, and cloud infrastructure audits. Copy and run directly in Claude Code.

VIEW SKILLS →READ DOCS
[ DOCUMENTATION ]
Architecture & Methodology
Full pipeline overview — skill auto-discovery, context injection, and 7-Gate triage.
7-Question Quality Gate
Pre-submission triage rules and automatic rejection criteria for theoretical bugs.
Claude Chat vs Claude Code
Environment scope comparison, tool execution rules, and system prompt setup.
Quick Start & Setup
Four-step setup from clone to active live target hunting in Claude Code CLI.
HackerOne / Bugcrowd Report Formats
Standardized CVSS 3.1 templates, evidence hygiene, and non-destructive PoC rules.
OPEN FULL DOCS →
[ SECURITY ANALYSIS ]
51 SKILLS · CLAUDE CODE · DAILY PATTERNS
> FILTER (↕↓)
#Skill & VulnerabilityCommandDomainEnvReports
01
SQLi Hunter
SQL and NoSQL injection across ORM raw fragments, GraphQL resolvers, OIDC-p...
/hunt-sqliweb-huntingboth12VIEW →
02
XSS Hunter
Cross-site scripting across DOM, reflected, stored, and mutation-based patt...
/hunt-xssweb-huntingboth174VIEW →
03
SSRF Hunter
Server-side request forgery including cloud metadata endpoint exfiltration,...
/hunt-ssrfweb-huntingbothVIEW →
04
RCE Hunter
Remote code execution via deserialization, template injection, command inje...
/hunt-rceweb-huntingbothVIEW →
05
IDOR Hunter
Insecure direct object references including BOLA in REST/GraphQL, ID enumer...
/hunt-idorweb-huntingboth26VIEW →
06
CSRF Hunter
Cross-site request forgery including SameSite bypass, token fixation, and J...
/hunt-csrfweb-huntingbothVIEW →
07
SSTI Hunter
Server-side template injection across Jinja2, Twig, Freemarker, Velocity, a...
/hunt-sstiweb-huntingbothVIEW →
08
XXE Hunter
XML external entity injection including blind OOB exfiltration, file read v...
/hunt-xxeweb-huntingbothVIEW →
09
File Upload Hunter
Unrestricted file upload bypasses — MIME type spoofing, extension trickery,...
/hunt-file-uploadweb-huntingbothVIEW →
10
Cache Poison Hunter
Web cache poisoning via unkeyed headers, parameter cloaking, fat GET exploi...
/hunt-cache-poisonweb-huntingbothVIEW →
11
HTTP Smuggling Hunter
HTTP request smuggling — CL.TE, TE.CL, TE.TE variants with bypass and respo...
/hunt-http-smugglingweb-huntingcodeVIEW →
12
Race Condition Hunter
Race condition exploitation on payment flows, coupon redemption, rate-limit...
/hunt-race-conditionweb-huntingcodeVIEW →
13
Business Logic Hunter
Business logic flaws — price manipulation, workflow bypass, state machine a...
/hunt-business-logicweb-huntingbothVIEW →
14
GraphQL Hunter
GraphQL introspection abuse, batching attacks, IDOR through aliases, nested...
/hunt-graphqlweb-huntingbothVIEW →
15
LLM/AI Hunter
LLM-integrated application vulnerabilities — prompt injection, insecure too...
/hunt-llm-aiweb-huntingbothVIEW →
16
Dispatch Hunter
Smart target triage and hunting path dispatch — routes to the right skill b...
/hunt-dispatchweb-huntingcodeVIEW →
17
Misc Vuln Hunter
Catch-all for open redirect, CRLF injection, clickjacking, host header inje...
/hunt-miscweb-huntingbothVIEW →
18
ASP.NET Hunter
ASP.NET-specific attack surface — ViewState deserialization, __EVENTTARGET ...
/hunt-aspnetweb-huntingbothVIEW →
19
Bug Bounty Planner
Structured methodology for scoping, prioritizing, and executing a bug bount...
/bug-bountyweb-huntingbothVIEW →
20
BB Methodology
End-to-end bug bounty methodology — recon, attack surface mapping, vulnerab...
/bb-methodologyweb-huntingbothVIEW →
21
Local Toolkit
Local toolchain setup for bug bounty — ffuf, nuclei, sqlmap, burp configura...
/bb-local-toolkitweb-huntingcodeVIEW →
22
Security Arsenal
Curated command arsenal for web security testing — one-liner reference for ...
/security-arsenalweb-huntingbothVIEW →
23
OAuth Hunter
OAuth 2.0 and OIDC vulnerabilities — CSRF on redirect_uri, state fixation, ...
/hunt-oauthauthboth19VIEW →
24
ATO Hunter
Account takeover chains — password reset poisoning, username enumeration, t...
/hunt-atoauthbothVIEW →
25
Auth Bypass Hunter
Authentication bypass — JWT alg=none, weak HMAC secrets, path traversal in ...
/hunt-auth-bypassauthbothVIEW →
26
MFA Bypass Hunter
Multi-factor authentication bypass — code reuse, race conditions on OTP val...
/hunt-mfa-bypassauthbothVIEW →
27
SAML Hunter
SAML SSO vulnerabilities — signature wrapping, XML comment injection, NameI...
/hunt-samlauthbothVIEW →
28
API Misconfig Hunter
API security misconfiguration — mass assignment, JWT attacks, prototype pol...
/hunt-api-misconfigapi-infrabothVIEW →
29
Cloud Misconfig Hunter
Cloud storage and service misconfiguration — S3 bucket ACL, GCS bucket enum...
/hunt-cloud-misconfigapi-infrabothVIEW →
30
GraphQL Deep Dive
GraphQL security deep dive — introspection bypass, batching amplification, ...
/hunt-graphqlapi-infrabothVIEW →
31
NTLM Info Hunter
NTLM information disclosure — internal hostname/domain leak via 401 challen...
/hunt-ntlm-infoapi-infracodeVIEW →
32
Cloud IAM Deep
Cloud IAM attack chains across AWS, Azure, GCP — STS/AssumeRole chaining, M...
/cloud-iam-deepenterpriseboth6VIEW →
33
M365/Entra Attack
Microsoft 365 and Entra ID attack surface — OAuth app consent phishing, tok...
/m365-entra-attackenterprisebothVIEW →
34
Okta Attack
Okta attack patterns — password spray against admin portal, impersonation A...
/okta-attackenterprisebothVIEW →
35
SharePoint Hunter
SharePoint and OneDrive attack surface — anonymous file access, OOTB webpar...
/hunt-sharepointenterprisebothVIEW →
36
Enterprise VPN Attack
Enterprise VPN attack surface — Pulse Secure, Fortinet, Cisco AnyConnect pr...
/enterprise-vpn-attackenterprisebothVIEW →
37
VMware vCenter Attack
VMware vCenter attack chain — CVE-2021-21985, CVE-2021-22005 pre-auth RCE, ...
/vmware-vcenter-attackenterprisebothVIEW →
38
APK Red-Team Pipeline
End-to-end Android APK red-team — automated acquisition, jadx decompilation...
/apk-redteam-pipelinered-teamcode1VIEW →
39
Supply Chain Recon
Supply chain attack reconnaissance — dependency confusion targets, npm/PyPI...
/supply-chain-attack-reconred-teambothVIEW →
40
IR Detection Awareness
Mid-engagement IR detection signals — EDR telemetry patterns, SIEM correlat...
/mid-engagement-ir-detectionred-teambothVIEW →
41
Red Team Mindset
Red team cognitive framework — objective-first thinking, OPSEC discipline, ...
/redteam-mindsetred-teambothVIEW →
42
OSINT Methodology
5-stage recon pipeline with 29 asset types, identity-fabric mapping (Entra/...
/osint-methodologyreconbothVIEW →
43
Offensive OSINT
Offensive OSINT techniques for authorized red-team engagements — breach cor...
/offensive-osintreconbothVIEW →
44
Subdomain Hunter
Subdomain enumeration and takeover identification — passive/active discover...
/hunt-subdomainreconcodeVIEW →
45
Triage Validation
7-Question Gate pre-submission workflow — 4 pre-submission gates, always-re...
/triage-validationreportingbothVIEW →
46
Report Writing
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — impact-first...
/report-writingreportingbothVIEW →
47
Evidence Hygiene
Evidence collection and hygiene — screenshot standards, video PoC requireme...
/evidence-hygienereportingbothVIEW →
48
Bugcrowd Reporting
Bugcrowd-specific report templates, VRT alignment, P1–P5 severity mapping, ...
/bugcrowd-reportingreportingbothVIEW →
49
Red Team Report
Executive and technical red team report template — attack narrative, kill c...
/redteam-report-templatereportingbothVIEW →
50
Web3 Smart Contract Audit
Smart contract security audit — 10 DeFi bug classes, Foundry PoC template, ...
/web3-auditspecializedbothVIEW →
51
Meme Coin Audit
Meme coin and low-TVL token audit — rug-pull pattern detection, honeypot id...
/meme-coin-auditspecializedbothVIEW →