Agent skill

Security Bounty Hunter

by affaan-m in affaan-m/ECC

在仓库中寻找可利用、值得赏金的安全问题。专注于远程可访问的漏洞,这些漏洞符合实际报告的条件,而不是嘈杂的仅本地发现. An agent skill from affaan-m/ECC.

MITAuto-check passedSecurity

Install Security Bounty Hunter

skills CLI
$ npx skills add affaan-m/ECC --skill security-bounty-hunter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC security-bounty-hunter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/zh-CN/skills/security-bounty-hunter .claude/skills/security-bounty-hunter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-bounty-hunter
GitHub stars
276k
Token cost
~384 tokens
SKILL.md length
81 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

在仓库中寻找可利用、值得赏金的安全问题。专注于远程可访问的漏洞,这些漏洞符合实际报告的条件,而不是嘈杂的仅本地发现. An agent skill from affaan-m/ECC.

  • Works in 7 steps: 首先检查范围:项目规则、SECURITY.md、披露渠道和排除项。 → 寻找真实入口点:HTTP处理器、上传功能、后台任务、Webhook、解析器和集成端… → 在适用时运行静态工具,但仅将其作为分类输入。 → …
  • Security work in your project
  • SKILL.md covers 使用场景, 工作原理, 有效模式 and 跳过这些, plus 4 more sections
  • Calls semgrep

What it does

Security Bounty Hunter is an agent skill from affaan-m/ECC. 在仓库中寻找可利用、值得赏金的安全问题。专注于远程可访问的漏洞,这些漏洞符合实际报告的条件,而不是嘈杂的仅本地发现。

Its SKILL.md is about 380 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/security-bounty-hunter”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. 首先检查范围:项目规则、SECURITY.md、披露渠道和排除项。
  2. 寻找真实入口点:HTTP处理器、上传功能、后台任务、Webhook、解析器和集成端点。
  3. 在适用时运行静态工具,但仅将其作为分类输入。
  4. 从头到尾阅读实际代码路径。
  5. 证明用户控制能到达有意义的接收点。
  6. 使用最小安全PoC确认可利用性和影响。
  7. 在起草报告前检查重复项。

What it can do on your machine

Read from SKILL.md and the folder at commit 4eb71d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Bounty Hunter loads about 384 tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 81 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~384

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 4eb71d9, republished under its MIT licence (© affaan-m). 81 words, ~384 tokens.

Download SKILL.mdSave it as .claude/skills/security-bounty-hunter/SKILL.md (or your agent's skills folder).
name
security-bounty-hunter
description
在仓库中寻找可利用、值得赏金的安全问题。专注于远程可访问的漏洞,这些漏洞符合实际报告的条件,而不是嘈杂的仅本地发现。
origin
ECC direct-port adaptation
version
1.0.0

安全赏金猎人

当目标是针对负责任披露或赏金提交的实际漏洞发现,而非广泛的实践审查时使用此方法。

使用场景

  • 扫描代码库以发现可利用漏洞
  • 准备 Huntr、HackerOne 或类似赏金平台的提交材料
  • 判断"这个漏洞是否真的能获得赏金"而非"理论上是否不安全"的优先级分类

工作原理

优先关注远程可达、用户可控的攻击路径,并剔除平台通常判定为信息性或超出范围的模式。

有效模式

以下是持续具有影响力的漏洞类型:

模式CWE典型影响
通过用户可控URL的SSRFCWE-918内网访问、云元数据窃取
中间件或API防护中的认证绕过CWE-287未授权账户或数据访问
远程反序列化或上传至RCE路径CWE-502代码执行
可达端点中的SQL注入CWE-89数据泄露、认证绕过、数据破坏
请求处理程序中的命令注入CWE-78代码执行
文件服务路径中的路径遍历CWE-22任意文件读取或写入
自动触发的XSSCWE-79会话窃取、管理员权限沦陷

跳过这些

除非项目另有说明,以下通常属于低信号或超出赏金范围:

  • 仅限本地的 pickle.loads、torch.load 或等效且无远程路径的漏洞
  • 仅限CLI工具中的 eval() 或 exec()
  • 完全硬编码命令上的 shell=True
  • 单独缺失安全标头
  • 无利用影响的通用速率限制投诉
  • 需要受害者手动粘贴代码的自XSS
  • 不属于目标项目范围的CI/CD注入
  • 演示、示例或仅测试代码

工作流程

  1. 首先检查范围:项目规则、SECURITY.md、披露渠道和排除项。
  2. 寻找真实入口点:HTTP处理器、上传功能、后台任务、Webhook、解析器和集成端点。
  3. 在适用时运行静态工具,但仅将其作为分类输入。
  4. 从头到尾阅读实际代码路径。
  5. 证明用户控制能到达有意义的接收点。
  6. 使用最小安全PoC确认可利用性和影响。
  7. 在起草报告前检查重复项。

分类循环示例

bash
semgrep --config=auto --severity=ERROR --severity=WARNING --json

然后手动过滤:

  • 删除测试、演示、固定代码、供应商代码
  • 删除仅限本地或不可达路径
  • 仅保留具有明确网络或用户控制路由的发现

报告结构

markdown
## 描述
[漏洞是什么及其重要性]

## 漏洞代码
[文件路径、行号范围及代码片段]

## 概念验证
[最小化可运行的请求或脚本]

## 影响
[攻击者能够实现的目标]

## 受影响版本
[已测试的版本、提交或部署目标]

质量关卡

提交前需确认:

  • 代码路径可从真实用户或网络边界到达
  • 输入确实由用户控制
  • 接收点有意义且可利用
  • PoC有效
  • 该问题尚未被公告、CVE或公开工单覆盖
  • 目标确实在赏金计划范围内

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/zh-CN/skills/security-bounty-hunter of affaan-m/ECC.

Open the folder on GitHubat commit 4eb71d9

Compare with similar skills

Security Bounty Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Bounty Hunter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Bounty Hunter this skillaffaan-m/ECC276k—~384Automated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4811 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    481 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Categories

Questions about Security Bounty Hunter

What does Security Bounty Hunter do?

在仓库中寻找可利用、值得赏金的安全问题。专注于远程可访问的漏洞,这些漏洞符合实际报告的条件,而不是嘈杂的仅本地发现. An agent skill from affaan-m/ECC. Security Bounty Hunter is an agent skill from affaan-m/ECC.

When should I use Security Bounty Hunter?

Security Bounty Hunter fits situations like: security work in your project.

How do I install Security Bounty Hunter in Claude Code?

Run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a claude-code`. Or copy the skill folder (docs/zh-CN/skills/security-bounty-hunter in affaan-m/ECC) into .claude/skills/security-bounty-hunter in your project. Claude Code loads it when a task matches its description.

How do I install Security Bounty Hunter in Codex?

Run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a codex`. Or copy the skill folder (docs/zh-CN/skills/security-bounty-hunter in affaan-m/ECC) into .agents/skills/security-bounty-hunter in your project. Codex loads it when a task matches its description.

Can I use Security Bounty Hunter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-bounty-hunter, .gemini/skills/security-bounty-hunter, .github/skills/security-bounty-hunter and .opencode/skills/security-bounty-hunter in your project.

What does Security Bounty Hunter need to run?

Going by SKILL.md and its folder, Security Bounty Hunter needs the command-line tools its instructions call (semgrep).

Does Security Bounty Hunter access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Bounty Hunter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Bounty Hunter use?

Security Bounty Hunter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Bounty Hunter use?

About 384 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Bounty Hunter?

Skills that share tags, products or a category with Security Bounty Hunter: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars), Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 481 stars) and Security Alert Triage (elastic/agent-skills, 592 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Bounty Hunter?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,111 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 10, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.