Agent skill

Security Bounty Hunter

by affaan-m in affaan-m/ECC

Hunt for exploitable, bounty-worthy security issues in repositories.

MITAuto-check passedSecurity

Install Security Bounty Hunter

skills CLI
$ npx skills add affaan-m/ECC --skill security-bounty-hunter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC security-bounty-hunter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-bounty-hunter .claude/skills/security-bounty-hunter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-bounty-hunter
GitHub stars
277k
Used in
2 other repos
Token cost
~907 tokens
SKILL.md length
393 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

Hunt for exploitable, bounty-worthy security issues in repositories.

  • Works in 7 steps: Check scope first: program rules,… → Find real entrypoints: HTTP handlers,… → Run static tooling where it helps, but… → …
  • Hunting reportable
  • SKILL.md covers When to Use, How It Works, In-Scope Patterns and Skip These, plus 4 more sections
  • Calls semgrep

What it does

Security Bounty Hunter is an agent skill from affaan-m/ECC. Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings. Use when hunting reportable, remotely reachable vulnerabilities in a repository.

Its SKILL.md is about 910 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Hunting reportable
  • Remotely reachable vulnerabilities in a repository

Example prompts

  • “/security-bounty-hunter”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Check scope first: program rules, SECURITY.md, disclosure channel, and exclusions.
  2. Find real entrypoints: HTTP handlers, uploads, background jobs, webhooks, parsers, and integration endpoints.
  3. Run static tooling where it helps, but treat it as triage input only.
  4. Read the real code path end to end.
  5. Prove user control reaches a meaningful sink.
  6. Confirm exploitability and impact with the smallest safe PoC possible.
  7. Check for duplicates before drafting a report.

What it can do on your machine

Read from SKILL.md and the folder at commit 2d515e4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Bounty Hunter loads about 907 tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 393 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~907

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 2d515e4, republished under its MIT licence (© affaan-m). 393 words, ~907 tokens.

Download SKILL.mdSave it as .claude/skills/security-bounty-hunter/SKILL.md (or your agent's skills folder).
name
security-bounty-hunter
description
Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings. Use when hunting reportable, remotely reachable vulnerabilities in a repository.
metadata.version
1.0.0
metadata.origin
ECC direct-port adaptation

Security Bounty Hunter

Use this when the goal is practical vulnerability discovery for responsible disclosure or bounty submission, not a broad best-practices review.

When to Use

  • Scanning a repository for exploitable vulnerabilities
  • Preparing a Huntr, HackerOne, or similar bounty submission
  • Triage where the question is "does this actually pay?" rather than "is this theoretically unsafe?"

How It Works

Bias toward remotely reachable, user-controlled attack paths and throw away patterns that platforms routinely reject as informative or out of scope.

In-Scope Patterns

These are the kinds of issues that consistently matter:

PatternCWETypical impact
SSRF through user-controlled URLsCWE-918internal network access, cloud metadata theft
Auth bypass in middleware or API guardsCWE-287unauthorized account or data access
Remote deserialization or upload-to-RCE pathsCWE-502code execution
SQL injection in reachable endpointsCWE-89data exfiltration, auth bypass, data destruction
Command injection in request handlersCWE-78code execution
Path traversal in file-serving pathsCWE-22arbitrary file read or write
Auto-triggered XSSCWE-79session theft, admin compromise

Skip These

These are usually low-signal or out of bounty scope unless the program says otherwise:

  • Local-only pickle.loads, torch.load, or equivalent with no remote path
  • eval() or exec() in CLI-only tooling
  • shell=True on fully hardcoded commands
  • Missing security headers by themselves
  • Generic rate-limiting complaints without exploit impact
  • Self-XSS requiring the victim to paste code manually
  • CI/CD injection that is not part of the target program scope
  • Demo, example, or test-only code
Show full SKILL.md (158 more words)Show less

Workflow

  1. Check scope first: program rules, SECURITY.md, disclosure channel, and exclusions.
  2. Find real entrypoints: HTTP handlers, uploads, background jobs, webhooks, parsers, and integration endpoints.
  3. Run static tooling where it helps, but treat it as triage input only.
  4. Read the real code path end to end.
  5. Prove user control reaches a meaningful sink.
  6. Confirm exploitability and impact with the smallest safe PoC possible.
  7. Check for duplicates before drafting a report.

Example Triage Loop

bash
semgrep --config=auto --severity=ERROR --severity=WARNING --json

Then manually filter:

  • drop tests, demos, fixtures, vendored code
  • drop local-only or non-reachable paths
  • keep only findings with a clear network or user-controlled route

Report Structure

markdown
## Description
[What the vulnerability is and why it matters]

## Vulnerable Code
[File path, line range, and a small snippet]

## Proof of Concept
[Minimal working request or script]

## Impact
[What the attacker can achieve]

## Affected Version
[Version, commit, or deployment target tested]

Quality Gate

Before submitting:

  • The code path is reachable from a real user or network boundary
  • The input is genuinely user-controlled
  • The sink is meaningful and exploitable
  • The PoC works
  • The issue is not already covered by an advisory, CVE, or open ticket
  • The target is actually in scope for the bounty program

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/security-bounty-hunter of affaan-m/ECC.

Open the folder on GitHubat commit 2d515e4

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in affaan-m/ECC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Bounty Hunter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Bounty Hunter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Bounty Hunter this skillaffaan-m/ECC277k2 repos~907Automated safety check: PassMIT
Elasticsearch Auditaspectrr/deer405—~1.7kAutomated safety check: PassMIT
Azure API Management Security Reviewthomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT
Bom Evidencecdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0
Php Auth Audit0xShe/PHP-Code-Audit-Skill4021 repos~951Automated safety check: PassNone
Create Templatemathematic-inc/earl113—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Azure API Management Security Review

    thomast1906/github-copilot-agent-skills

    Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

    202 GitHub stars~3.1k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check passed
  • Php Auth Audit

    0xShe/PHP-Code-Audit-Skill

    PHP Web 源码鉴权机制审计工具。从源码中识别所有认证/鉴权实现并分析风险,输出路由-鉴权映射与漏洞分析(含 PoC 与修复建议)。

    402 GitHub starsUsed in 1 repo~951 tokens
    SecurityAuto-check passed
  • Create Template

    mathematic-inc/earl

    Creates a new Earl HCL template for a specific API, database, or shell command.

    113 GitHub stars~2.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Onvifscan

    BrownFineSecurity/iothackbot

    ONVIF device security scanner for testing authentication and brute-forcing credentials.

    859 GitHub starsUsed in 1 repo~608 tokens
    SecurityAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Questions about Security Bounty Hunter

What does Security Bounty Hunter do?

Hunt for exploitable, bounty-worthy security issues in repositories. Security Bounty Hunter is an agent skill from affaan-m/ECC. Hunt for exploitable, bounty-worthy security issues in repositories.

When should I use Security Bounty Hunter?

Security Bounty Hunter fits situations like: hunting reportable; remotely reachable vulnerabilities in a repository.

How do I install Security Bounty Hunter in Claude Code?

Run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a claude-code`. Or copy the skill folder (skills/security-bounty-hunter in affaan-m/ECC) into .claude/skills/security-bounty-hunter in your project. Claude Code loads it when a task matches its description.

How do I install Security Bounty Hunter in Codex?

Run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a codex`. Or copy the skill folder (skills/security-bounty-hunter in affaan-m/ECC) into .agents/skills/security-bounty-hunter in your project. Codex loads it when a task matches its description.

Can I use Security Bounty Hunter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill security-bounty-hunter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-bounty-hunter, .gemini/skills/security-bounty-hunter, .github/skills/security-bounty-hunter and .opencode/skills/security-bounty-hunter in your project.

What does Security Bounty Hunter need to run?

Going by SKILL.md and its folder, Security Bounty Hunter needs the command-line tools its instructions call (semgrep).

Does Security Bounty Hunter access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Bounty Hunter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Bounty Hunter use?

Security Bounty Hunter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Bounty Hunter use?

About 907 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Bounty Hunter?

Skills that share tags, products or a category with Security Bounty Hunter: Elasticsearch Audit (aspectrr/deer, 405 stars), Azure API Management Security Review (thomast1906/github-copilot-agent-skills, 202 stars), Bom Evidence (cdxgen/cdxgen, 1.1k stars) and Php Auth Audit (0xShe/PHP-Code-Audit-Skill, 402 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Bounty Hunter?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,673 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 11, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.