Hunt Business Logic
elementalsouls/Claude-BugHunter
Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
Adversarial code auditor that hunts down bugs, logic errors, and security flaws.
$ npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills bugs-are-annoying --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bugs-are-annoying .claude/skills/bugs-are-annoying && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bugs-are-annoying" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/bugs-are-annoying into .claude/skills/bugs-are-annoying/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs-are-annoying", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/bugs-are-annoyingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills bugs-are-annoying --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/bugs-are-annoying .agents/skills/bugs-are-annoying && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bugs-are-annoying" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/bugs-are-annoying into .agents/skills/bugs-are-annoying/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs-are-annoying", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills bugs-are-annoying --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/bugs-are-annoying .cursor/skills/bugs-are-annoying && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bugs-are-annoying" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/bugs-are-annoying into .cursor/skills/bugs-are-annoying/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs-are-annoying", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/bugs-are-annoying--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills bugs-are-annoying --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/bugs-are-annoying .gemini/skills/bugs-are-annoying && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bugs-are-annoying" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/bugs-are-annoying into .gemini/skills/bugs-are-annoying/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs-are-annoying", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills bugs-are-annoyingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/bugs-are-annoying .github/skills/bugs-are-annoying && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bugs-are-annoying" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/bugs-are-annoying into .github/skills/bugs-are-annoying/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs-are-annoying", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills bugs-are-annoying --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/bugs-are-annoying .opencode/skills/bugs-are-annoying && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bugs-are-annoying" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/bugs-are-annoying into .opencode/skills/bugs-are-annoying/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bugs-are-annoying", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bugs-are-annoyingAdversarial code auditor that hunts down bugs, logic errors, and security flaws.
Bugs Are Annoying is an agent skill from sickn33/agentic-awesome-skills. Adversarial code auditor that hunts down bugs, logic errors, and security flaws. Use for deep correctness passes, not style reviews.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bugs Are Annoying loads about 2.6k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 1,408 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,408 words, ~2,571 tokens.
.claude/skills/bugs-are-annoying/SKILL.md (or your agent's skills folder).An adversarial QA pass for any codebase, in any language. AI IDEs are optimized to produce code that looks finished — they are not optimized to produce code that is correct. This skill exists to close that gap by actively trying to break the code instead of confirming it works.
Treat all code as guilty until proven innocent. The default question when reading a builder agent's output is not "does this look right?" — it's "how would this break, and what did the author not think of?"
This is an adversarial pass, not a confirmatory one. Do not skim and approve. Do not skip a category because it "seems fine." Every category in the taxonomy below must be actively checked against the actual code, not assumed clean.
Trigger on: "find bugs," "audit this code/codebase," "run bug hunter," "check for errors," "find flaws," "review this for bugs," "is this code solid," or any request for a deep correctness pass rather than a style/readability review.
Do not skip phases or collapse them into a single skim. Each phase catches things the others miss.
git diff), or a specific area. Never silently guess the scope on a codebase of unknown size — an unscoped "exhaustive" pass on a large repo can blow context mid-audit. Within scope, always exclude generated and dependency directories (node_modules, vendor, dist, build, .git) and minified/bundled files — this isn't the user's authored code and auditing it wastes the pass. Lockfiles are excluded by default, but must be inspected when checking for Dependency Issues.bugs.md — Use the exact format below. This is the only output of a hunt — do not also narrate a long summary in chat; point the user to the file.Language-agnostic. Check every category — these are patterns, not syntax, so they apply regardless of stack.
Stylistic or formatting preferences are explicitly not bugs. Do not log them.
Dormant bugs: if a bug sits on a code path that isn't currently reachable or used (e.g. a variable that's computed but never read), it still gets the severity it would have if active — do not downgrade it for being unreachable. Add a one-line note to the entry that it isn't currently triggered, e.g. "Not yet triggered — finalPricePerItem is computed but unused."
bugs.mdWrite this file at the root of the project being audited (or the relevant scope if auditing a subfolder). Use this exact structure:
# Bug Report — [project/scope name] — [date]
## Summary
- Critical: N open, N fixed
- Intermediate: N open, N fixed
- Normal: N open, N fixed
## 🔴 Critical
### BUG-001: [Short title]
- **File:** path/to/file.ext:line
- **Issue:** what is actually wrong
- **Trigger:** the exact input/sequence that causes it
- **Impact:** what breaks because of it
- **Suggested Fix:** described or sketched, not applied
- **Confidence:** *(omit if fully confirmed in-scope; include "Needs Verification" if it depends on code outside the audited scope)*
- **Status:** Open
## 🟡 Intermediate
...
## 🟢 Normal
...
## ✅ Resolved
### BUG-0XX: [Title] — Fixed [date]
(kept for history, moved here once fixed)Rules for entries:
file:line reference — never "somewhere in this file."BUG-001, BUG-002, ...), even across multiple runs.When bugs-are-annoying is run again on a codebase that already has a bugs.md:
Open bug against the current code — if it's actually fixed now, move it to ✅ Resolved with the date.The file is a running history of the codebase's health, not a disposable report.
bugs.md. Code is only changed if the user explicitly asks afterward (e.g. "fix BUG-003," "fix all Critical bugs"). Until then, every fix described in bugs.md is a suggestion only.bugs.md.Confidence: Needs Verification rather than asserting it as certain.bugs.md with the Summary counts and the date — a clean result is part of the history, not a no-op.Only enters this mode when the user explicitly asks to fix something — e.g. "fix BUG-001," "fix all Critical bugs," "apply the suggested fixes for the Intermediate ones."
bugs.md and locate the specified bug ID(s) or severity tier.© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/bugs-are-annoying of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit b84d35a
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Bugs Are Annoying next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bugs Are Annoying this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Hunt Business Logicelementalsouls/Claude-BugHunter | 4.9k | 1 repos | ~4.4k | Automated safety check: Pass | MIT | |
| Bug Hunt SwarmDimillian/Skills | 4k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Bug Bountyawarexone/Agentic-Bug-Hunter | 5.3k | — | ~20k | Automated safety check: Warn | MIT | |
| Web3 Hunt Foundationtradecatlabs/vibe-coding-cn | 17k | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Bug Huntdanpeg/bug-hunt | 146 | — | ~968 | Automated safety check: Pass | MIT |
elementalsouls/Claude-BugHunter
Hunting skill for business logic vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
Dimillian/Skills
Parallel read-only multi-agent root-cause investigation for bugs, regressions, crashes, flaky behavior, or unexplained failures.
awarexone/Agentic-Bug-Hunter
Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling…
tradecatlabs/vibe-coding-cn
Starting guide for Web3 bug bounty hunts: validating each finding, ten checks per external function, six questions to disprove your own bug, plus recon setup and target scoring.
danpeg/bug-hunt
Run adversarial bug hunting on your codebase. An agent skill from danpeg/bug-hunt.
tw93/Mole
A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Adversarial code auditor that hunts down bugs, logic errors, and security flaws. Bugs Are Annoying is an agent skill from sickn33/agentic-awesome-skills. Adversarial code auditor that hunts down bugs, logic errors, and security flaws.
Bugs Are Annoying fits situations like: deep correctness passes; not style reviews.
Run `npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a claude-code`. Or copy the skill folder (skills/bugs-are-annoying in sickn33/agentic-awesome-skills) into .claude/skills/bugs-are-annoying in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a codex`. Or copy the skill folder (skills/bugs-are-annoying in sickn33/agentic-awesome-skills) into .agents/skills/bugs-are-annoying in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill bugs-are-annoying -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bugs-are-annoying, .gemini/skills/bugs-are-annoying, .github/skills/bugs-are-annoying and .opencode/skills/bugs-are-annoying in your project.
Going by SKILL.md and its folder, Bugs Are Annoying needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bugs Are Annoying is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bugs Are Annoying: Hunt Business Logic (elementalsouls/Claude-BugHunter, 4.9k stars), Bug Hunt Swarm (Dimillian/Skills, 4k stars), Bug Bounty (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Web3 Hunt Foundation (tradecatlabs/vibe-coding-cn, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.