Skip to content

Repository files navigation

BugSkill AI Logo

BugSkill AI: HackerOne Bug Bounty Intelligence & Awesome AI Agent Skills

Python Version License: MIT HackerOne API Disclosed Reports Total Bounty Paid Curated Skills Zero Dependencies

An enterprise-grade repository combining 9,950+ real-world disclosed HackerOne bug bounty reports ($3.26M+ in bounties paid) with two curated, modular collections comprising 162 Universal AI Agent Skills (Awesome-Claude-Code-Agent-Skills/ [159 skills across 10 specialized domains] & Personal-Claude-Code-Agent-Skills/ [3 deep HackerOne vulnerability intelligence skills]) built for next-generation AI coding assistants: Claude Code, Gemini CLI, Google Antigravity, ChatGPT / Codex CLI, and Cursor.


πŸ“‘ Table of Contents


πŸ“Š Dataset Overview

The repository includes an offline intelligence dataset of 9,950 disclosed vulnerability reports fetched directly from the official HackerOne Hacktivity REST API.

Metric Details
Total Disclosed Reports 9,950 vulnerabilities
Total Bounty Value Paid $3,264,576.00+
Bounty Rewarded Reports 1,832 reports (Average: $1,781.97 per rewarded bug)
Top Rewarded Vulnerability $50,000.00 (Shopify GitHub access token exposure)
Dataset File hackerone_public_reports.json (13.7 MB JSON)
Key Vulnerability Classes IDOR, SSRF, OTP/2FA Bypass, Rate Limiting, RCE, OAuth Flaws, ATO, Race Conditions

πŸ“¦ Curated Agent Skills Collections

1. Awesome Claude Code Skills (Awesome-Claude-Code-Agent-Skills/)

A curated, production-ready collection of 159 specialized offensive security, penetration testing, reverse engineering, and AI agent skills organized across 10 security domains:

Domain Skills Count Focus Highlights
🎯 Reconnaissance, Footprinting & OSINT 15 Skills Apex & root domain discovery, BGP/ASN mapping, Subdomain enumeration & takeover, PCAP analysis
🌐 Web Application Exploitation & Injections 45 Skills SQLi, SSRF, SSTI, XSS, XXE, Command injection, Cache deception, Request smuggling, Race conditions
πŸ”‘ Authentication, Authorization & Access Control 25 Skills 401/403 bypasses, BAC/IDOR, JWT & OAuth flaws, SAML SSO, business logic flaws
🏒 Active Directory & Windows Exploitation 7 Skills AD ACL abuse, AD CS, Kerberos ticket attacks, NTLM relay coercion, AV evasion, lateral movement
🐧 Linux, Containers & Cloud Security 6 Skills Container breakout, Kubernetes auditing, Linux privilege escalation & lateral movement, tunneling
⚑ Binary Exploitation, Reverse Engineering & macOS 16 Skills Heap exploitation, format strings, kernel flaws, V8 engine, symbolic execution, macOS injection
πŸ“± Mobile & Smart Contract Security 12 Skills Android/iOS pentesting tricks, SSL pinning bypass, Smart contract & DeFi exploit patterns
πŸ” Cryptography & Cryptanalysis 6 Skills Classical ciphers, Hash cracking, Lattice attacks, RSA attacks, Steganography, Symmetric ciphers
🧠 AI / LLM Security & Agent Orchestration 10 Skills Prompt injection, AI/ML security, Multi-agent orchestrators (skillabc, hack, mcp-builder)
πŸ›‘οΈ DevSecOps, Defense & Workflow Automation 17 Skills Tabletop exercises, Bug bounty workflows, Code auditing, Dependency confusion, WAF bypasses
πŸ” Expand Full Directory of 159 Awesome Skills (Click to View Complete Table)

Category Breakdown of Awesome Skills (159 Skills)

🎯 Reconnaissance, Footprinting & OSINT (15 Skills)

Skill Directory Description
ApexDiscovery Comprehensive apex/root domain discovery using multiple techniques. USE WHEN user mentions find related domains, apex domains, root ...
api-recon-and-docs API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs,...
AsnRecon ASN and IPv4 range reconnaissance using bgp.he.net. USE WHEN user mentions ASN lookup, find IP ranges, company IP space, BGP reconna...
crawl Deep web crawling using hakrawler and gospider for subdomain discovery, endpoint extraction, and JavaScript analysis. Use this skill...
jsa Specialized offensive security skill.
JsAnalyzer Static analysis for JavaScript files targeting security vulnerabilities. USE WHEN user says 'analyze js', 'scan javascript', 'find s...
network-protocol-attacks Network protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDNS poisoning, WPAD ...
osint-enrich Specialized offensive security skill.
pulse-template Specialized offensive security skill.
recon-and-methodology Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fingerprinting technology, and building a s...
recon-for-sec Entry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, ...
subdomain-takeover Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned...
SubdomainEnum Subdomain enumeration with Light and Full workflows, plus intelligent target prioritization. USE WHEN user mentions subdomain enumer...
traffic-analysis-pcap Traffic analysis and PCAP forensics playbook. Use when analyzing network captures including Wireshark filters, protocol analysis (HT...
web-fingerprinting Identify web server type/version, framework, and application entry points via banner grabbing, HTTP header analysis (Server, ...

🌐 Web Application Exploitation & Injections (45 Skills)

Skill Directory Description
CacheDeception Web cache deception and poisoning exploitation. USE WHEN user mentions cache deception, cache poisoning, CDN bypass, URL parsing dis...
clickjacking Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are prope...
clickjacking-testing Clickjacking overlays a target page in a transparent or hidden iframe, tricking victims into clicking UI elements they cannot see. ...
cmd-injection OS command injection occurs when user input is passed unsanitized to a system shell via dangerous APIs: Java Runtime.exec(), Python ...
cmdi-command-injection Command injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind ...
cors-cross-origin-misconfiguration CORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed browser reads, origin reflection, prefli...
cors-misconfig CORS misconfiguration allows attacker-controlled origins to read sensitive cross-origin responses when servers echo the Origin ...
crlf-injection CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files wher...
cspt Use when hunting Client-Side Path Traversal (CSPT) vulnerabilities where attacker- controlled input is unsafely concatenated into the ...
csrf Cross-Site Request Forgery (CSRF) tricks authenticated users into submitting forged requests to a target application by exploiting ...
csrf-cross-site-request-forgery CSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, an...
csv-formula-injection CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*). Use when exports, imports, or user fields feed sp...
dangling-markup-injection Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, sanitizer strips e...
dom-xss DOM-based XSS occurs when JavaScript reads attacker-controlled sources (location.hash, document.referrer, window.name, ...
email-header-injection Email header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or any feature that ...
expression-language-injection Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in ...
file-access-vuln Entry P1 category router for file access and upload workflows. Use when testing download endpoints, file paths, local file inclusion...
http-host-header-attacks HTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generating URLs, routing ...
http-parameter-pollution HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when...
http-request-smuggling HTTP request smuggling exploits disagreements between a front-end proxy and back-end server on where one HTTP request ends and the ...
http2-specific-attacks HTTP/2 protocol-specific attack playbook. Use when the target supports HTTP/2 and you need to exploit binary framing, HPACK compress...
injection-checking Entry P1 category router for injection testing. Use when routing between XSS, SQLi, SSRF, XXE, SSTI, command injection, and NoSQL in...
jndi-injection JNDI injection playbook. Use when Java applications perform JNDI lookups with attacker-controlled names, especially via Log4j2, Spri...
open-redirect Open redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users...
open-redirect-testing Use when testing redirect or return-URL parameters for open redirect vulnerabilities. Trigger on: ?redirect=, ?url=, ?next=, ...
path-traversal-lfi Path traversal and LFI playbook. Use when file paths, download endpoints, include operations, archive extraction, or wrapper behavio...
prototype-pollution Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON bodies, deep assi...
prototype-pollution-advanced Advanced prototype pollution playbook β€” server-side RCE, client-side gadgets, filter bypasses, and detection techniques. Companion t...
race-condition Race condition and TOCTOU testing for web apps. Use when testing one-time operations, concurrent HTTP abuse, rate-limit bypass, Turb...
request-smuggling HTTP request smuggling and desynchronization testing. Use when front proxies, CDNs, or load balancers disagree with the origin on me...
sql-injection SQL injection occurs when untrusted user input is interpolated directly into database queries, allowing attackers to alter query ...
sqli-sql-injection SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blin...
ssrf Server-Side Request Forgery (SSRF) occurs when user-controlled input is used to construct URLs that the server fetches, enabling ...
ssrf-server-side-request-forgery SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networ...
ssti Server-Side Template Injection (SSTI) occurs when user input is embedded directly into a template engine (Jinja2, Twig, Freemarker, ...
ssti-server-side-template-injection SSTI playbook. Use when template expressions, server-side rendering, preview features, or templating engines may evaluate attacker-c...
type-juggling PHP type juggling and weak comparison (==) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose ...
web-cache-deception Web cache deception and poisoning playbook. Use when CDN, reverse proxy, or application caching may serve sensitive authenticated co...
websocket-security WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifi...
xslt-injection XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfa...
xss-cross-site-scripting XSS playbook. Use when user-controlled content reaches HTML, attributes, JavaScript, DOM sinks, uploads, or multi-context rendering ...
xss-reflected Reflected XSS occurs when user-supplied input is echoed in an HTTP response without sanitization, allowing script execution in the ...
xss-stored Stored XSS (persistent XSS) occurs when attacker-supplied input is saved server-side and later rendered unencoded to other users. ...
xxe XML External Entity (XXE) injection exploits XML parsers that process DTD external entity declarations, enabling local file disclosure ...
xxe-xml-external-entity XXE playbook. Use when XML, SVG, OOXML, SOAP, or parser-driven imports may resolve external entities, files, or internal network res...

πŸ”‘ Authentication, Authorization & Access Control (25 Skills)

Skill Directory Description
401-403-bypass-techniques 401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers p...
403Bypass Automated 403 Forbidden bypass testing using Jason Haddix's techniques. USE WHEN you encounter 403 responses during recon, content d...
api-auth-and-jwt-abuse API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and ...
api-authorization-and-bola API authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or w...
api-sec Entry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter wor...
auth-bypass Bypass authentication via forced browsing to protected URLs, parameter tampering (authenticated=yes, debug=true, fromtrustIP=true), ...
auth-sec Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OA...
authbypass-authentication-flaws Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token pr...
authz-bypass Test horizontal and vertical authorization bypass via session ID swapping between accounts, IDOR through parameter manipulation ...
bac-analyzer Passive traffic analyzer that examines captured HTTP traffic (HAR, Caido JSON, Burp XML) to identify potential Broken Access Control...
bola-idor Use when hunting Broken Object Level Authorization (BOLA) or Insecure Direct Object Reference (IDOR) vulnerabilities in APIs or web ...
business-logic-flaws Business logic flaws are application vulnerabilities where valid functions are abused in unintended ways: price manipulation via ...
business-logic-vuln Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state at...
business-logic-vulnerabilities Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state ...
cookie-attacks Audit and attack session cookies via missing Secure/HttpOnly/SameSite attributes, overly broad Domain/Path scope, non-expiring ...
default-credentials Identify and exploit default or weak credentials on web application login forms, admin panels, CMS backends (WordPress wp-admin, ...
graphql-idor-via-introspection-leak Covers object-level authorization bypass in GraphQL APIs where introspection reveals hidden fields or mutations that accept arbitrary ...
idor-broken-object-authorization IDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fiel...
jwt-misconfig Use when testing JWT-based authentication for algorithm confusion, alg:none bypass, weak HMAC secrets, missing expiration, kid ...
jwt-oauth-token-attacks JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, a...
mass-assignment Use when testing APIs and web frameworks for mass assignment vulnerabilities where user-controlled request body fields are bound ...
oauth-oidc-misconfiguration OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token ...
password-reset-flaws Exploit weak password reset and change flows via CSRF on reset forms, cross-user password modification by swapping username ...
saml-sso-assertion-attacks SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, ...
session-fixation Detect and exploit session fixation (WSTG-SESS-01, WSTG-SESS-03) and session exposure (WSTG-SESS-04) by testing whether the server ...

🏒 Active Directory & Windows Exploitation (7 Skills)

Skill Directory Description
active-directory-acl-abuse Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights...
active-directory-certificate-services AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abu...
active-directory-kerberos-attacks Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silve...
ntlm-relay-coercion NTLM relay and authentication coercion playbook. Use when capturing and relaying NTLM authentication to escalate privileges via SMB,...
windows-av-evasion AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, ...
windows-lateral-movement Windows lateral movement playbook. Use when pivoting between Windows hosts via PsExec, WMI, WinRM, DCOM, RDP, pass-the-hash, overpas...
windows-privilege-escalation Windows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to escalate via token ...

🐧 Linux, Containers & Cloud Security (6 Skills)

Skill Directory Description
container-escape-techniques Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via p...
kubernetes-pentesting Kubernetes penetration testing playbook. Use when targeting Kubernetes clusters via API server, RBAC enumeration, service account ab...
linux-lateral-movement Linux lateral movement playbook. Use after gaining initial access to pivot across Linux hosts via SSH hijacking, credential harvesti...
linux-privilege-escalation Linux privilege escalation playbook. Use when you have low-privilege shell access and need to escalate to root via SUID/SGID binarie...
linux-security-bypass Linux security mechanism bypass playbook. Use when facing restricted bash/rbash, read-only or noexec filesystems, AppArmor, SELinux,...
tunneling-and-pivoting Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Li...

⚑ Binary Exploitation, Reverse Engineering & macOS (16 Skills)

Skill Directory Description
anti-debugging-techniques Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, tim...
arbitrary-write-to-rce Arbitrary write to RCE playbook. Use when you have an arbitrary write primitive (from heap exploitation, format string, or OOB write...
binary-protection-bypass Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, a...
browser-exploitation-v8 Browser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities including JIT type confusion, incorrect ...
code-obfuscation-deobfuscation Code obfuscation analysis and deobfuscation playbook. Use when reversing binaries protected by junk code, opaque predicates, self-mo...
format-string-exploitation Format string exploitation playbook. Use when printf-family functions receive user-controlled format strings, enabling arbitrary sta...
ghost-bits-cast-attack Java "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narro...
heap-exploitation Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities including UAF, double free, overflow, off-by-one...
kernel-exploitation Linux kernel exploitation playbook. Use when exploiting kernel vulnerabilities (UAF, OOB, race condition, type confusion) for privil...
macos-process-injection macOS process injection playbook. Use when you need to inject code into running or launching macOS processes via dylib hijacking, DY...
macos-security-bypass macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, o...
memory-forensics-volatility Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential extraction, process...
sandbox-escape-techniques Sandbox escape playbook. Use when breaking out of Python sandbox, Lua sandbox, seccomp filter, chroot jail, container/Docker, browse...
stack-overflow-and-rop Stack overflow and ROP playbook. Use when exploiting buffer overflows to hijack control flow via return address overwrite, ROP chain...
symbolic-execution-tools Symbolic execution and constraint solving playbook. Use when solving CTF reversing challenges, recovering keys, bypassing checks, or...
vm-and-bytecode-reverse Custom VM and bytecode reverse engineering playbook. Use when CTF challenges or protected software implement custom virtual machines...

πŸ“± Mobile & Smart Contract Security (12 Skills)

Skill Directory Description
android-pentesting-tricks Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnera...
defi-attack-patterns DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attacks, governance exp...
ios-pentesting-tricks iOS pentesting playbook. Use when testing iOS applications for keychain extraction, URL scheme hijacking, Universal Links exploitati...
mobile-auth-bypass Detects authentication and biometric bypass vulnerabilities in mobile apps (Android/iOS). Trigger on: BiometricPrompt, ...
mobile-code-quality Detects code quality vulnerabilities in mobile apps (Android/iOS). Trigger on: SQL injection in SQLite, JavaScript injection in ...
mobile-insecure-storage Detects sensitive data stored insecurely on mobile devices (Android/iOS). Trigger on: SharedPreferences, NSUserDefaults, SQLite, Room ...
mobile-network-security Detects insecure network communication in mobile apps (Android/iOS). Trigger on: cleartext HTTP, TLS misconfiguration, certificate ...
mobile-platform-interaction Detects insecure platform interaction in mobile apps (Android/iOS). Trigger on: exported Activity, exported Service, exported ...
mobile-resilience Detects weak reverse engineering and tampering protections in mobile apps (Android/iOS). Trigger on: root detection bypass, jailbreak ...
mobile-ssl-pinning-bypass Mobile SSL pinning bypass playbook. Use when intercepting HTTPS traffic from mobile applications that implement certificate pinning,...
mobile-weak-crypto Detects weak or misconfigured cryptography in mobile apps (Android/iOS). Trigger on: hardcoded keys, ECB mode, DES, 3DES, RC4, MD5, ...
smart-contract-vulnerabilities Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, de...

πŸ” Cryptography & Cryptanalysis (6 Skills)

Skill Directory Description
classical-cipher-analysis Classical cipher analysis playbook. Use when encountering substitution ciphers, Vigenere, transposition, XOR, or encoded text in CTF...
hash-attack-techniques Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based ...
lattice-crypto-attacks Lattice-based cryptanalysis playbook. Use when attacking RSA via Coppersmith small roots, recovering DSA/ECDSA nonces from bias, sol...
rsa-attack-techniques RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to recover plaintext by e...
steganography-techniques Steganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audio (spectrogram, DT...
symmetric-cipher-attacks Symmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-and-paste, bit flipp...

🧠 AI / LLM Security & Agent Orchestration (10 Skills)

Skill Directory Description
ai-ml-security AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model p...
amend-skill Inspects a skill's SKILL.md and its observations/runs.md log, identifies failure patterns, and proposes a targeted amendment to ...
artifacts-builder Suite of tools for creating elaborate, multi-component claude.ai HTML artifacts using modern frontend web technologies (React, Tailw...
distill-skill Use when the user wants to extract reusable offensive security knowledge from any source and generate a SKILL.md file. Trigger on: ...
hack Entry P0 primary router for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerab...
llm-prompt-injection LLM prompt injection playbook. Use when testing AI/LLM applications for direct injection, indirect injection via RAG/browsing, tool ...
mcp-builder Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through wel...
observe-skill Logs the outcome of a skill execution to observations//runs.md. Trigger on: "log this run", "skill worked", "skill ...
skill-creator Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) t...
skillabc Intelligent orchestration layer that analyzes requests, selects the most relevant OpenCode skills, combines workflows intelligently,...

πŸ›‘οΈ DevSecOps, Defense & Workflow Automation (17 Skills)

Skill Directory Description
BugBountyWorkflow Bug bounty hunting workflow and report writing expertise. USE WHEN user mentions bug bounty, vulnerability report, HackerOne, Bugcro...
cicd-bot-command-injection Use when hunting CI/CD bot comment command vulnerabilities where issue_comment or pull_request_review_comment triggers invoke ...
code-security-auditor Perform pre-execution security audits of untrusted codebases through static analysis. Use when analyzing a codebase for potential ma...
csp-bypass-advanced Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy ...
dependency-confusion Supply-chain testing via package-manager dependency confusion: when internal package names resolve to attacker-controlled public reg...
deserialization-insecure Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unse...
dns-rebinding-attacks DNS rebinding attack playbook. Use when testing applications that trust DNS resolution for origin checks, interact with internal ser...
github-actions-cache-poisoning Use when hunting GitHub Actions cache poisoning vulnerabilities where an attacker can inject malicious content into the CI/CD cache ...
github-actions-script-injection Use when auditing GitHub Actions workflows for script injection vulnerabilities via unsanitized context expressions. Trigger on: ...
graphql-and-hidden-parameters GraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, s...
insecure-source-code-management Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup...
java-backend-architect Comprehensive skill for designing and building scalable Spring Boot backend systems with clean architecture, JWT auth, MySQL, REST A...
pwn-request Use when hunting Pwn Request vulnerabilities where pull_request_target workflows checkout attacker-controlled PR code and execute it ...
self-hosted-runner-poisoning Use when hunting self-hosted GitHub Actions runner vulnerabilities where fork pull requests can execute on privileged non-ephemeral ...
TabletopExercise Comprehensive cybersecurity tabletop exercise design and facilitation framework. USE WHEN designing incident response scenarios, cre...
waf-bypass-techniques WAF bypass methodology and generic evasion techniques. Use when a web application firewall blocks injection payloads (SQLi, XSS, RCE...
webapp-testing Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debuggi...

2. Personal Bug Bounty Intelligence Skills (Personal-Claude-Code-Agent-Skills/)

Custom, deep vulnerability analysis skills derived directly from real-world HackerOne disclosed reports:

Skill Directory Target Vulnerability Class Reference Report Included Tooling
otp-bruteforce-testing OTP Brute-Force, Rate Limiting Bypass & Response Oracle Detection HackerOne #3265780 scripts/otp_bruteforce.py (Multi-threaded, proxy support, response oracle detection)
stack-bounds-format-auditing Stack Buffer Overflow via String Format / Copy Bounds Arithmetic (snprintf, swprintf, memcpy) HackerOne #2551512 scripts/fmt_bounds_audit.py (Static bounds arithmetic scanner, PoC crash generator & validation harness)
url-parser-confusion-testing URL Parser Inconsistencies & SSRF Filter Bypass (Triple-Slash, Delimiters, Numeric IPs) HackerOne #3923212 scripts/url_parser_diff.py (Differential parser testing across Python, cURL, and Node.js)

πŸ“ Clean Repository Layout

.
β”œβ”€β”€ README.md                              # Repository documentation & universal agent guide
β”œβ”€β”€ Assets/                                # Media assets & project branding
β”‚   └── BugSkill-AI-Logo.png               # Official BugSkill AI Logo
β”œβ”€β”€ requirements.txt                       # Dependency notes (Zero external dependencies)
β”œβ”€β”€ search_reports.py                      # Offline multi-filter search CLI (Python stdlib)
β”œβ”€β”€ hackerone_public.py                    # HackerOne API Hacktivity downloader (Python stdlib)
β”œβ”€β”€ hackerone_public_reports.json          # Offline dataset (9,950 disclosed reports)
β”‚
β”œβ”€β”€ Awesome-Claude-Code-Agent-Skills/      # 🌟 Curated Security Skills (159 Skills across 10 Domains)
β”‚   β”œβ”€β”€ 01-Reconnaissance-and-OSINT/       # ApexDiscovery, AsnRecon, SubdomainEnum, crawl, jsa...
β”‚   β”œβ”€β”€ 02-Web-Application-Security/       # SQLi, SSRF, SSTI, XSS, XXE, CMDi, CacheDeception...
β”‚   β”œβ”€β”€ 03-Authentication-and-Access-Control/ # 401/403 bypass, BOLA/IDOR, JWT/OAuth, SAML...
β”‚   β”œβ”€β”€ 04-Active-Directory-and-Windows/   # AD CS, Kerberos, NTLM relay, PrivEsc, AV evasion...
β”‚   β”œβ”€β”€ 05-Linux-Containers-and-Cloud/     # Kubernetes, container escapes, Linux PrivEsc...
β”‚   β”œβ”€β”€ 06-Binary-and-Reverse-Engineering/ # Heap, format strings, kernel, V8, macOS injection...
β”‚   β”œβ”€β”€ 07-Mobile-and-Smart-Contracts/     # Android/iOS pentesting, SSL pinning, DeFi...
β”‚   β”œβ”€β”€ 08-Cryptography-and-Cryptanalysis/ # RSA, Lattice, Hash attacks, Steganography...
β”‚   β”œβ”€β”€ 09-AI-Security-and-Orchestration/  # Prompt injection, AI/ML security, skillabc, hack...
β”‚   └── 10-DevSecOps-and-Defense/          # TabletopExercise, BugBountyWorkflow, Code auditor...
β”‚
└── Personal-Claude-Code-Agent-Skills/     # πŸ›‘οΈ HackerOne Intelligence Skills (Custom Reports)
    β”œβ”€β”€ Note.md                            # Master ledger of converted HackerOne report IDs
    β”œβ”€β”€ otp-bruteforce-testing/            # OTP Brute-Force & Oracle Testing (H1 #3265780)
    β”œβ”€β”€ stack-bounds-format-auditing/      # Stack Buffer Overflow & Bounds Auditing (H1 #2551512)
    └── url-parser-confusion-testing/      # URL Parser Inconsistencies & SSRF Bypass (H1 #3923212)

⚑ Zero External Dependencies

All core utilities, dataset search tools, and primary skill scripts are written natively using the Python 3 Standard Library (Python 3.8+):

No third-party packages or pip install steps are required for core operations.


πŸ€– Universal Agent Skills Framework ("Using It")

Every skill in this repository contains structured instructions and workflows making it compatible across all major agent environments.

1. Cross-Agent Compatibility Matrix

AI Agent Platform Global / Personal Scope Project / Repository Scope
Claude Code ~/.claude/skills/<skill-name>/ .claude/skills/<skill-name>/
Gemini CLI ~/.gemini/skills/ or ~/.agents/skills/ .gemini/skills/ or .agents/skills/
Google Antigravity ~/.agents/skills/<skill-name>/ .agents/skills/<skill-name>/
ChatGPT / Codex CLI ~/.codex/skills/ or ~/.agents/skills/ .agents/skills/<skill-name>/
Cursor / VS Code @mention SKILL.md .cursorrules / .vscode/

2. One-Command Universal Sync

Install all skills into your local agent environment with a single command:

Linux / macOS (Bash / Zsh):

# Sync ALL skills to Claude Code (Project Scope)
mkdir -p .claude/skills
cp -r Awesome-Claude-Code-Agent-Skills/*/* .claude/skills/
cp -r "Personal-Claude-Code-Agent-Skills/"* .claude/skills/

# Sync ALL skills to Claude Code (Global Scope)
mkdir -p ~/.claude/skills
cp -r Awesome-Claude-Code-Agent-Skills/*/* ~/.claude/skills/
cp -r "Personal-Claude-Code-Agent-Skills/"* ~/.claude/skills/

# Sync ALL skills to Gemini CLI, Google Antigravity & Codex
mkdir -p ~/.agents/skills
cp -r Awesome-Claude-Code-Agent-Skills/*/* ~/.agents/skills/
cp -r "Personal-Claude-Code-Agent-Skills/"* ~/.agents/skills/

Windows (PowerShell):

# Sync ALL skills to Claude Code (Project Scope)
New-Item -ItemType Directory -Force -Path ".claude\skills"
Get-ChildItem -Path "Awesome-Claude-Code-Agent-Skills\*\*" -Directory | Copy-Item -Destination ".claude\skills\" -Recurse -Force
Copy-Item -Recurse -Force "Personal-Claude-Code-Agent-Skills\*" ".claude\skills\"

# Sync ALL skills to Gemini CLI, Google Antigravity & Codex
New-Item -ItemType Directory -Force -Path "$HOME\.agents\skills"
Get-ChildItem -Path "Awesome-Claude-Code-Agent-Skills\*\*" -Directory | Copy-Item -Destination "$HOME\.agents\skills\" -Recurse -Force
Copy-Item -Recurse -Force "Personal-Claude-Code-Agent-Skills\*" "$HOME\.agents\skills\"

3. Using with Claude Code

Direct Slash Commands

/403Bypass
/SubdomainEnum
/ApexDiscovery
/JsAnalyzer
/TabletopExercise
/otp-bruteforce-testing
/url-parser-confusion-testing
/stack-bounds-format-auditing

Natural Prompting (Auto-Invocation)

Claude Code automatically indexes skill descriptions and activates them dynamically when you describe relevant security tasks:

"Perform subdomain enumeration and prioritize live targets for example.com." "Audit our authentication API for OTP brute-force bypasses."


4. Using with Gemini CLI & Google Antigravity

  • Auto-Discovery: Antigravity and Gemini CLI automatically load and execute any skill located in .agents/skills/ or ~/.agents/skills/.
  • Natural Execution: Prompt the agent with the target domain or source code to audit.

5. Using with ChatGPT / Codex CLI

  • Codex CLI reads skills from .agents/skills/ or ~/.codex/skills/.
  • List active skills with codex /skills.

6. Using with Cursor / VS Code

  • Add skill references in .cursorrules or @mention any SKILL.md file directly in the chat panel.

πŸ”Ž Offline Report Search & Intelligence CLI (search_reports.py)

Search and analyze the 9,950+ disclosed reports dataset offline with sub-second execution:

# 1. Global keyword search
python search_reports.py "OTP"
python search_reports.py "IDOR"
python search_reports.py "SSRF"

# 2. Filter by severity and minimum bounty
python search_reports.py "bypass" --severity critical --min-bounty 2500

# 3. Filter by CWE category
python search_reports.py --cwe "CWE-307"
python search_reports.py --cwe "CWE-79" --limit 10

# 4. Filter by target company/program
python search_reports.py --program "shopify" --severity high

# 5. Inspect deep report details by ID
python search_reports.py --id 3265780
python search_reports.py --id 2551512

# 6. Display high-level dataset statistics
python search_reports.py --stats

# 7. Output structured JSON for scripts and CI/CD pipelines
python search_reports.py "RCE" --severity critical --json

⚑ HackerOne Hacktivity Downloader (hackerone_public.py)

To refresh or append newly disclosed reports directly from the HackerOne REST API:

  1. Obtain your API Identifier and Token from HackerOne Settings -> API.
  2. Set your environment variables:
# Linux / macOS
export H1_API_IDENTIFIER="YOUR_IDENTIFIER"
export H1_API_TOKEN="YOUR_TOKEN"

# Windows (PowerShell)
$env:H1_API_IDENTIFIER="YOUR_IDENTIFIER"
$env:H1_API_TOKEN="YOUR_TOKEN"
  1. Run the downloader:
# Download latest 10 pages (500 reports)
python hackerone_public.py --max-pages 10

# Download all disclosed reports (0 = unlimited)
python hackerone_public.py --max-pages 0 --output hackerone_public_reports.json

πŸ“œ License & Responsible Disclosure

  • License: Distributed under the MIT License.
  • Responsible Disclosure & Ethics: All disclosed vulnerability reports in this dataset are public data published by HackerOne under mutual agreement with respective security teams. This toolkit is intended solely for authorized security assessments, defensive hardening, and educational research. Always obtain explicit authorization before testing any third-party infrastructure.