No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by elementalsouls · Claude Skill · ★ 4.6k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is Claude-BugHunter safe to install? View the security audit →
claude-bughunter A self-contained Claude skill bundle for bug hunting and external red-team work · 51 skills · 15 slash commands · 574+ disclosed-report patterns across 24 vulnerability classes · enterprise identity + infrastructure attack matrices · engagement-folder scaffolding · Burp MCP integration · battle-tested across authorized red-team and bug-hunting engagements, plus public training platforms (DVWA, OWASP Juice Shop, Hacker101, testphp.vulnweb.com). Built by Sachin Sharma — Bug Hunting & GenAI Security Research. What is this? is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug-hunting researcher or red-team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: + + — how to think. 5-phase non-linear hunting workflow, critical-thinking framework, developer-psychology heuristics, anomaly detection patterns, and the red-team operator-discipline corrections (when scope is "external red team" not "bug hunting / WAPT"). 24 skills + — what to look for in webapps.
| Stars | 4,610 |
| Forks | 692 |
| Language | Python |
| Category | Claude Skill |
| License | MIT |
| Quality Score | 62.0408002540041/100 |
| Open Issues | 3 |
| Last Updated | 2026-09-22 |
| Created | 2026-05-05 |
| Platforms | browser, claude-code, python |
| Est. Tokens | ~25k |
Looking for a Claude-BugHunter alternative? If you're comparing Claude-BugHunter with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
AI-powered bug bounty hunting toolkit that works with or without subscription.
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report ge
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows — particular
Explore other popular claude skill tools:
Claude-BugHunter is A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identi. It is categorized as a Claude Skill with 4.6k GitHub stars.
Claude-BugHunter is primarily written in Python. It covers topics such as ai-security, anthropic, application-security.
You can find installation instructions and usage details in the Claude-BugHunter GitHub repository at github.com/elementalsouls/Claude-BugHunter. The project has 4.6k stars and 692 forks, indicating an active community.
Claude-BugHunter is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to Claude-BugHunter on Agent Skills Hub include pentest-ai-agents, pentest-ai, Agentic-Bug-Hunter. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: