Search
Bug bounty
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns. | awarexone/ | 5.3k | 3 repos | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 2 | Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments. | awarexone/ | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT | yesterday |
| 3 | Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys. | j3ssie/ | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 4 | WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws… | tanweai/ | 1.8k | — | ~1.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 5 | Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet. | awarexone/ | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | yesterday |
| 6 | A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization. | tradecatlabs/ | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | today |
| 7 | Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back. | samugit83/ | 3k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 8 | 8.Flounder Operates Flounder, an autonomous white-hat security auditor. | adshao/ | 519 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | 4 days ago |
| 9 | Review FastMCP vulnerability reports before accepting, rejecting, patching, scoring, or publishing them. | PrefectHQ/ | 28k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter. | elementalsouls/ | 4.8k | 1 repo | ~4.4k | Automated safety check: Pass | MIT | yesterday |
| 11 | Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. | elementalsouls/ | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 12 | 12.Write Structure and per-section format reference for a bug bounty report, aligned with YesWeHack's official guidance. | yeswehack/ | 109 | — | ~2.1k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 13 | 移动安全漏洞挖掘知识库,基于HackerOne公开报告提供Android和iOS应用的漏洞挖掘手法、技术细节和代码模式分析;用于安全研究人员和漏洞挖掘者学习参考、代码审计和漏洞检测指导。 | s7safe/ | 211 | — | ~631 | Automated safety check: Pass | No licence | 5 mo ago |
| 14 | Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 15 | Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology. | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations. | Gabson0x/ | 442 | — | ~1.2k | Automated safety check: Pass | No licence | 23 days ago |
| 17 | 17.Triage Self-validates a bug bounty report draft before submission. An agent skill from yeswehack/claude-kit. | yeswehack/ | 109 | — | ~1k | Automated safety check: Pass | GPL-3.0 | 1 mo ago |
| 18 | Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures. | Encod3d-Sec/ | 329 | — | ~611 | Automated safety check: Pass | MIT | 1 mo ago |
| 19 | Reference for ten classes of DeFi smart contract bugs, each with root cause, vulnerable code, fix, grep patterns and paid examples, for audits and bug bounty reviews. | tradecatlabs/ | 17k | 2 repos | ~10k | Automated safety check: Pass | MIT | today |
| 20 | Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup. | tradecatlabs/ | 17k | 2 repos | ~9.9k | Automated safety check: Pass | MIT | today |
| 21 | Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting. | tradecatlabs/ | 17k | 2 repos | ~7.7k | Automated safety check: Pass | MIT | today |
| 22 | Worked bug bounty case study of a yield aggregator: target scoring, fund-flow mapping, prior audit triage and a verdict per bug class, with role misconfiguration in focus. | tradecatlabs/ | 17k | 2 repos | ~3.5k | Automated safety check: Pass | MIT | today |
| 23 | Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring. | tradecatlabs/ | 17k | 2 repos | ~2.5k | Automated safety check: Pass | MIT | today |
| 24 | Records a Web3 bug bounty hunt on ZKsync Era that ended with no findings, using it to show what a hardened protocol looks like and when to drop a target. | tradecatlabs/ | 17k | 2 repos | ~2.2k | Automated safety check: Pass | MIT | today |
| 25 | Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus. | bugbountywithmarco/ | 122 | — | ~524 | Automated safety check: Pass | No licence | 2 mo ago |
| 26 | Spawning and hardening scan containers from the recon orchestrator: the security flags that look correct and break the container, and the sibling bind-mount path handling. | samugit83/ | 3k | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 27 | Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early. | awarexone/ | 5.3k | 3 repos | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 28 | A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every… | mtarcure/ | 164 | — | ~3.6k | Automated safety check: Pass | MIT | 18 days ago |
| 29 | Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus. | bugbountywithmarco/ | 122 | — | ~550 | Automated safety check: Pass | No licence | 2 mo ago |
| 30 | Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist. | awarexone/ | 5.3k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | yesterday |
| 31 | 31.Nmap Recon Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools | CommonHuman-Lab/ | 157 | — | ~639 | Automated safety check: Pass | Unknown | 2 days ago |
| 32 | Changing or adding a project setting / default value in RedAmon. | samugit83/ | 3k | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 33 | Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 34 | Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field. | samugit83/ | 3k | — | ~2.2k | Automated safety check: Pass | MIT | yesterday |
| 35 | Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste. | microsoft/ | 107 | — | ~1k | Automated safety check: Pass | MIT | today |
| 36 | A skill your agent uses when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a… | serejaris/ | 229 | — | ~3.4k | Automated safety check: Notes | MIT | 2 days ago |
| 37 | 37.Write Report Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus. | bugbountywithmarco/ | 122 | — | ~585 | Automated safety check: Pass | No licence | 2 mo ago |
| 38 | Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses. | Encod3d-Sec/ | 329 | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 39 | Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently… | samugit83/ | 3k | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 40 | Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 41 | Reference vocabulary for interpreting vulnerability findings — detector-vs-impact distinction, severity anchoring on demonstrated evidence, the eleven-item interpretation rubric, delegation… | provos/ | 612 | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 42 | 42.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | yesterday |
| 43 | Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking. | fabricioctelles/ | 106 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 44 | 44.Gotchas Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps. | yeswehack/ | 109 | — | ~4.3k | Automated safety check: Warn | GPL-3.0 | 1 mo ago |
| 45 | Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. | trailofbits/ | 7.4k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 46 | 46.Web Recon Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f | CommonHuman-Lab/ | 157 | — | ~907 | Automated safety check: Pass | Unknown | 2 days ago |
| 47 | Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi | sickn33/ | 47k | 1 repo | ~3.2k | Automated safety check: Pass | MIT | today |
| 48 | Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. | sickn33/ | 47k | 1 repo | ~5.4k | Automated safety check: Pass | MIT | today |