bug-reaper — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by shaniidev · Agent Tool · ★ 71

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is bug-reaper safe to install? View the security audit →

About bug-reaper

BugReaper Structured web2 bug bounty AI skill — 18 vulnerability classes, 4 bug bounty platforms, zero AI slop. Compatible with OpenClaw, Cursor, Claude Code, Antigravity, and Windsurf. BugReaper is an Agent Skill that turns any compatible AI agent into a disciplined web2 bug bounty hunter. It enforces evidence-ba

Quick Facts

Stars71
Forks10
LanguagePython
CategoryAgent Tool
LicenseMIT
Quality Score66.4167066552218/100
Open Issues1
Last Updated2026-02-21
Created2026-02-21
Platformsbrowser, python
Est. Tokens~9k

Compatible Skills

These tools work well together with bug-reaper for enhanced workflows:

  • communitytools — semantic(0.20)+complementary+shared_fw(anthropic)+same_lang+similar_pop+shared_platform (65%)
  • h1-brain — semantic(0.42)+complementary+same_lang+similar_pop+shared_platform (65%)

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular Python Agent Tools

Frequently Asked Questions

What is bug-reaper?

bug-reaper is Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.. It is categorized as a Agent Tool with 71 GitHub stars.

What programming language is bug-reaper written in?

bug-reaper is primarily written in Python.

How do I install or use bug-reaper?

You can find installation instructions and usage details in the bug-reaper GitHub repository at github.com/shaniidev/bug-reaper. The project has 71 stars and 10 forks, indicating an active community.

What license does bug-reaper use?

bug-reaper is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools