No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by shaniidev · Agent Tool · ★ 71
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is bug-reaper safe to install? View the security audit →
BugReaper Structured web2 bug bounty AI skill — 18 vulnerability classes, 4 bug bounty platforms, zero AI slop. Compatible with OpenClaw, Cursor, Claude Code, Antigravity, and Windsurf. BugReaper is an Agent Skill that turns any compatible AI agent into a disciplined web2 bug bounty hunter. It enforces evidence-ba
| Stars | 71 |
| Forks | 10 |
| Language | Python |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 66.4167066552218/100 |
| Open Issues | 1 |
| Last Updated | 2026-02-21 |
| Created | 2026-02-21 |
| Platforms | browser, python |
| Est. Tokens | ~9k |
These tools work well together with bug-reaper for enhanced workflows:
Explore other popular agent tool tools:
bug-reaper is Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.. It is categorized as a Agent Tool with 71 GitHub stars.
bug-reaper is primarily written in Python.
You can find installation instructions and usage details in the bug-reaper GitHub repository at github.com/shaniidev/bug-reaper. The project has 71 stars and 10 forks, indicating an active community.
bug-reaper is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: