Agent skill

Security Bounty Hunter

by affaan-m in affaan-m/ECC

リポジトリ内の悪用可能なバウンティ対象のセキュリティ問題を発見します。ノイズの多いローカルのみの発見ではなく、実際のレポートに適格なリモートから到達可能な脆弱性に焦点を当てます。

MITAuto-check passedSecurity

Install Security Bounty Hunter

skills CLI
$ npx skills add affaan-m/ECC --skill security-bounty-hunter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC security-bounty-hunter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/ja-JP/skills/security-bounty-hunter .claude/skills/security-bounty-hunter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-bounty-hunter
GitHub stars
276k
Token cost
~523 tokens
SKILL.md length
100 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

リポジトリ内の悪用可能なバウンティ対象のセキュリティ問題を発見します。ノイズの多いローカルのみの発見ではなく、実際のレポートに適格なリモートから到達可能な脆弱性に焦点を当てます。

  • Works in 7 steps: まず範囲を確認:… → 実際のエントリーポイントを見つける: HTTP… → 静的ツールが役立つ場合は実行するが、トリアージ入力としてのみ扱う。 → …
  • Security work in your project
  • SKILL.md covers 使用するタイミング, 動作の仕組み, 対象範囲内のパターン and スキップするもの, plus 4 more sections
  • Calls semgrep

What it does

Security Bounty Hunter is an agent skill from affaan-m/ECC. リポジトリ内の悪用可能なバウンティ対象のセキュリティ問題を発見します。ノイズの多いローカルのみの発見ではなく、実際のレポートに適格なリモートから到達可能な脆弱性に焦点を当てます。

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/security-bounty-hunter”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. まず範囲を確認: プログラムルール、SECURITY.md、開示チャネル、および除外事項。
  2. 実際のエントリーポイントを見つける: HTTP ハンドラー、アップロード、バックグラウンドジョブ、Webhook、パーサー、統合エンドポイント。
  3. 静的ツールが役立つ場合は実行するが、トリアージ入力としてのみ扱う。
  4. 実際のコードパスをエンドツーエンドで読む。
  5. ユーザー制御が意味のあるシンクに到達することを証明する。
  6. 可能な限り小さな安全な PoC で悪用可能性と影響を確認する。
  7. レポートを作成する前に重複を確認する。

What it can do on your machine

Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Bounty Hunter loads about 523 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 100 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~523

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 100 words, ~523 tokens.

Download SKILL.mdSave it as .claude/skills/security-bounty-hunter/SKILL.md (or your agent's skills folder).
name
security-bounty-hunter
description
リポジトリ内の悪用可能なバウンティ対象のセキュリティ問題を発見します。ノイズの多いローカルのみの発見ではなく、実際のレポートに適格なリモートから到達可能な脆弱性に焦点を当てます。
origin
ECC direct-port adaptation
version
1.0.0

Security Bounty Hunter

責任ある開示やバウンティ提出のための実際的な脆弱性発見が目的の場合に使用します。広範なベストプラクティスレビューではありません。

使用するタイミング

  • リポジトリの悪用可能な脆弱性をスキャンする場合
  • Huntr、HackerOne、または類似のバウンティ提出を準備する場合
  • 「これは実際に報酬が出るか?」であり「これは理論的に安全でないか?」ではないトリアージ

動作の仕組み

リモートから到達可能なユーザー制御の攻撃パスに偏り、プラットフォームが定期的に情報提供または範囲外として却下するパターンを排除します。

対象範囲内のパターン

継続的に重要な問題の種類:

パターンCWE典型的な影響
ユーザー制御の URL による SSRFCWE-918内部ネットワークアクセス、クラウドメタデータの窃取
ミドルウェアまたは API ガードでの認証バイパスCWE-287不正なアカウントまたはデータアクセス
リモートデシリアライゼーションまたはアップロードから RCE へのパスCWE-502コード実行
到達可能なエンドポイントでの SQL インジェクションCWE-89データ流出、認証バイパス、データ破壊
リクエストハンドラーでのコマンドインジェクションCWE-78コード実行
ファイル提供パスでのパストラバーサルCWE-22任意のファイルの読み取りまたは書き込み
自動トリガーされる XSSCWE-79セッション窃取、管理者の侵害

スキップするもの

プログラムが別途指定しない限り、通常は低シグナルまたはバウンティの範囲外です:

  • リモートパスのないローカルのみの pickle.loads、torch.load、または同等
  • CLI のみのツールでの eval() または exec()
  • 完全にハードコードされたコマンドの shell=True
  • セキュリティヘッダーのみの欠如
  • 悪用の影響のない一般的なレート制限の不満
  • 被害者がコードを手動で貼り付ける必要のあるセルフ XSS
  • ターゲットプログラムの範囲外の CI/CD インジェクション
  • デモ、サンプル、またはテスト専用のコード

ワークフロー

  1. まず範囲を確認: プログラムルール、SECURITY.md、開示チャネル、および除外事項。
  2. 実際のエントリーポイントを見つける: HTTP ハンドラー、アップロード、バックグラウンドジョブ、Webhook、パーサー、統合エンドポイント。
  3. 静的ツールが役立つ場合は実行するが、トリアージ入力としてのみ扱う。
  4. 実際のコードパスをエンドツーエンドで読む。
  5. ユーザー制御が意味のあるシンクに到達することを証明する。
  6. 可能な限り小さな安全な PoC で悪用可能性と影響を確認する。
  7. レポートを作成する前に重複を確認する。

トリアージループの例

bash
semgrep --config=auto --severity=ERROR --severity=WARNING --json

次に手動でフィルタリング:

  • テスト、デモ、フィクスチャ、ベンダーコードを除外
  • ローカルのみまたは到達不可能なパスを除外
  • ネットワークまたはユーザー制御の明確なルートがある所見のみを保持

レポート構造

markdown
## 説明
[脆弱性の内容とその重要性]

## 脆弱なコード
[ファイルパス、行範囲、および小さなスニペット]

## 概念実証
[最小限の動作するリクエストまたはスクリプト]

## 影響
[攻撃者が達成できること]

## 影響を受けるバージョン
[テストされたバージョン、コミット、またはデプロイターゲット]

品質ゲート

提出前に:

  • コードパスが実際のユーザーまたはネットワーク境界から到達可能
  • 入力が真にユーザー制御可能
  • シンクが意味があり悪用可能
  • PoC が動作する
  • 問題がアドバイザリー、CVE、またはオープンチケットでまだカバーされていない
  • ターゲットがバウンティプログラムの実際の範囲内

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/ja-JP/skills/security-bounty-hunter of affaan-m/ECC.

Open the folder on GitHubat commit 4eb71d9

Compare with similar skills

Security Bounty Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Bounty Hunter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Bounty Hunter this skillaffaan-m/ECC276k—~523Automated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Categories

Questions about Security Bounty Hunter

What does Security Bounty Hunter do?

リポジトリ内の悪用可能なバウンティ対象のセキュリティ問題を発見します。ノイズの多いローカルのみの発見ではなく、実際のレポートに適格なリモートから到達可能な脆弱性に焦点を当てます。. Security Bounty Hunter is an agent skill from affaan-m/ECC.

When should I use Security Bounty Hunter?

Security Bounty Hunter fits situations like: security work in your project.

How do I install Security Bounty Hunter in Claude Code?

Run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a claude-code`. Or copy the skill folder (docs/ja-JP/skills/security-bounty-hunter in affaan-m/ECC) into .claude/skills/security-bounty-hunter in your project. Claude Code loads it when a task matches its description.

How do I install Security Bounty Hunter in Codex?

Run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a codex`. Or copy the skill folder (docs/ja-JP/skills/security-bounty-hunter in affaan-m/ECC) into .agents/skills/security-bounty-hunter in your project. Codex loads it when a task matches its description.

Can I use Security Bounty Hunter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-bounty-hunter, .gemini/skills/security-bounty-hunter, .github/skills/security-bounty-hunter and .opencode/skills/security-bounty-hunter in your project.

What does Security Bounty Hunter need to run?

Going by SKILL.md and its folder, Security Bounty Hunter needs the command-line tools its instructions call (semgrep).

Does Security Bounty Hunter access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Bounty Hunter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Bounty Hunter use?

Security Bounty Hunter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Bounty Hunter use?

About 523 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Bounty Hunter?

Skills that share tags, products or a category with Security Bounty Hunter: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Bounty Hunter?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.