No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by awarexone · Claude Skill · ★ 238
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is public-skills-builder safe to install? View the security audit →
Public Skills Builder Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups - no private reports needed. Feed it 500+ public bug bounty reports. Get back 18 ready-to-use Claude Code skill files - one per vulnerability class - packed with real-world techniques, payloads, and bypass patterns. Quick Start · Output · Sources · Usage Built and maintained by AwareXone - Website · X · GitHub Why Use This Bug bounty reports are the best training data for hunting. This tool reads hundreds of disclosed HackerOne reports and community writeups, then uses Claude to distill them into structured skill files you c
| Stars | 238 |
| Forks | 50 |
| Language | Python |
| Category | Claude Skill |
| Quality Score | 70.5185970262236/100 |
| Last Updated | 2026-09-21 |
| Created | 2026-03-10 |
| Platforms | claude-code, python |
| Est. Tokens | ~2k |
These tools work well together with public-skills-builder for enhanced workflows:
Looking for a public-skills-builder alternative? If you're comparing public-skills-builder with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
The AI Agent for Cyber Security.
One command installs 670+ security tools on Linux & Termux. Its authorization-gated MCP server works with Clau
AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions
Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents
An agent-native red-teaming workspace with a fast browser, direct HTTP traffic control, sandboxed execution, a
AI-powered subdomain enumeration tool with local LLM analysis via Ollama - 100% private, zero API costs
Explore other popular claude skill tools:
public-skills-builder is Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed. It is categorized as a Claude Skill with 238 GitHub stars.
public-skills-builder is primarily written in Python. It covers topics such as ai-security, bug-bounty, claude-ai.
You can find installation instructions and usage details in the public-skills-builder GitHub repository at github.com/awarexone/public-skills-builder. The project has 238 stars and 50 forks, indicating an active community.
The top alternatives to public-skills-builder on Agent Skills Hub include numasec, cybersec-toolkit, medusa. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: