Fizz
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.
$ npx skills add Gabson0x/bountyforge --skill web2-recon -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Gabson0x/bountyforge web2-recon --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/web2-recon .claude/skills/web2-recon && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "web2-recon" agent skill from https://github.com/Gabson0x/bountyforge/tree/main/skills/web2-recon into .claude/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Gabson0x/bountyforge/tree/main/skills/web2-reconType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Gabson0x/bountyforge --skill web2-recon -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Gabson0x/bountyforge web2-recon --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/web2-recon .agents/skills/web2-recon && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "web2-recon" agent skill from https://github.com/Gabson0x/bountyforge/tree/main/skills/web2-recon into .agents/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Gabson0x/bountyforge --skill web2-recon -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Gabson0x/bountyforge web2-recon --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/web2-recon .cursor/skills/web2-recon && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "web2-recon" agent skill from https://github.com/Gabson0x/bountyforge/tree/main/skills/web2-recon into .cursor/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Gabson0x/bountyforge.git --path skills/web2-recon--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Gabson0x/bountyforge --skill web2-recon -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Gabson0x/bountyforge web2-recon --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/web2-recon .gemini/skills/web2-recon && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "web2-recon" agent skill from https://github.com/Gabson0x/bountyforge/tree/main/skills/web2-recon into .gemini/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Gabson0x/bountyforge web2-reconInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Gabson0x/bountyforge --skill web2-recon -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/web2-recon .github/skills/web2-recon && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "web2-recon" agent skill from https://github.com/Gabson0x/bountyforge/tree/main/skills/web2-recon into .github/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Gabson0x/bountyforge --skill web2-recon -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Gabson0x/bountyforge web2-recon --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/web2-recon .opencode/skills/web2-recon && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "web2-recon" agent skill from https://github.com/Gabson0x/bountyforge/tree/main/skills/web2-recon into .opencode/skills/web2-recon/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web2-recon", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
web2-reconWeb2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.
Web2 Recon is an agent skill from Gabson0x/bountyforge. Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing. Trust-first asset discovery.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Fuzzing. The repository describes itself as: all round pentest skill.
Read from SKILL.md and the folder at commit 068399d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.mail.tmcrt.shdns.projectdiscovery.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CHAOS_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Web2 Recon loads about 1.6k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 230 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 230 words (~1,582 tokens).
“Map the attack surface before hunting. Every endpoint is a trust boundary. Find them all.”
Just SKILL.md in skills/web2-recon of Gabson0x/bountyforge.
Open the folder on GitHubat commit 068399d
Web2 Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Web2 Recon this skillGabson0x/bountyforge | 442 | — | ~1.6k | Automated safety check: Pass | None | |
| Fizzpashov/skills | 1.2k | 2 repos | ~11k | Automated safety check: Pass | MIT | |
| Fizz Syncpashov/skills | 1.2k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Research FuzzerARA-Labs/Agent-Native-Research-Artifact | 692 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Vuln Researchtanweai/xianzhi-research | 185 | — | ~847 | Automated safety check: Pass | None | |
| Binary Reverse Engineering Audittihanyin/REx-skill | 108 | — | ~5.1k | Automated safety check: Pass | MIT |
pashov/skills
Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.
pashov/skills
Reconcile an existing Fizz harness with a changed source tree.
ARA-Labs/Agent-Native-Research-Artifact
Treat an open-ended investigation the way a fuzzer treats a program.
tanweai/xianzhi-research
安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.
tihanyin/REx-skill
Guides evidence-first reverse engineering of compiled programs to find and prove defects, from triage and decompilation to fuzzing, patch diffing and firmware.
provos/ironcurtain
Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…
Gabson0x/bountyforge
Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.
Gabson0x/bountyforge
HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.
Gabson0x/bountyforge
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection…
Gabson0x/bountyforge
Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.
Gabson0x/bountyforge
Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.
Categories
Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing. Web2 Recon is an agent skill from Gabson0x/bountyforge. Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.
Web2 Recon fits situations like: tasks that involve Fuzzing.
Run `npx skills add Gabson0x/bountyforge --skill web2-recon -a claude-code`. Or copy the skill folder (skills/web2-recon in Gabson0x/bountyforge) into .claude/skills/web2-recon in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Gabson0x/bountyforge --skill web2-recon -a codex`. Or copy the skill folder (skills/web2-recon in Gabson0x/bountyforge) into .agents/skills/web2-recon in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Gabson0x/bountyforge --skill web2-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web2-recon, .gemini/skills/web2-recon, .github/skills/web2-recon and .opencode/skills/web2-recon in your project.
Going by SKILL.md and its folder, Web2 Recon needs the command-line tools its instructions call (curl and jq) and credentials named CHAOS_API_KEY. Our summary lists: A credential in CHAOS_API_KEY.
SKILL.md names 3 domains. In commands or code: api.mail.tm, crt.sh and dns.projectdiscovery.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
No licence was found for Web2 Recon or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Web2 Recon: Fizz (pashov/skills, 1.2k stars), Fizz Sync (pashov/skills, 1.2k stars), Research Fuzzer (ARA-Labs/Agent-Native-Research-Artifact, 692 stars) and Vuln Research (tanweai/xianzhi-research, 185 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Gabson0x (a GitHub user) maintains it in Gabson0x/bountyforge, which has 442 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 16, 2026.
Source: Gabson0x/bountyforge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.