Pentest Agents Bug Bounty Framework
Skill by ara.so — Security Skills collection.
Autonomous bug-bounty framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw. Ships 50 agents, 26 commands, 19 CLI tools, 11 skills, and 2 MCP servers (bounty platforms + writeup search). Includes 2,500 lines of concrete payloads, 7-Question Gate validation, autonomous hunt loops, A→B exploit chain building, persistent brain with endpoint tracking, and cross-IDE installer.
Installation
For Claude Code (Native)
For Other AI Coding Tools
Installer Commands
MCP Servers
Bounty Platforms Server (16 Platforms)
HackerOne (full API), Bugcrowd, Intigriti, Immunefi, YesWeHack + 11 stubs.
Configuration:
7 MCP Tools:
list_platforms- List all configured platformsget_program_scope- Fetch in/out-of-scope assetsget_program_policy- Get submission rulessearch_hacktivity- Find similar reportssync_program- Download scope to local braindraft_report- Prepare submissionsubmit_report- Submit to platform
Writeup Search Server (BYO Index)
Three search modes (auto-detected, graceful fallback):
Configuration:
Build Your Own Index:
Edit rag-builder/repos.yaml to customize the 146-entry seed list of CTF archives, bug-bounty reports, and payload collections.
4 MCP Tools:
search_writeups- Semantic/keyword search for prior artget_writeup- Full writeup content by IDsearch_techniques- Exploitation techniques by vuln classsearch_payloads- Curated payloads fromrules/payloads.md
Core Workflow
Key Commands (26 Total)
In Claude Code Session
Scaffold Tool
This generates:
~/bounties/<platform>-<program>/directoryCLAUDE.md,AGENTS.md,.codex/,.gemini/,.cursor/configs.mcp.jsonwith platform + writeup server config.agents/skills/with all framework skills
Agent System (50 Agents)
Key orchestrator agents:
chain-builder- Links findings into exploit chains (A→B)correlator- Cross-references findings with brainrecon-ranker- Prioritizes attack surfacehunt-orchestrator- Coordinates active huntingvalidator- 7-Question Gate compliance
Specialized hunters:
sqli-hunter,xss-hunter,ssrf-hunterauthz-hunter,jwt-hunter,idor-hunterapi-hunter,graphql-hunter,websocket-hunter
Agents inherit model via model: "inherit" frontmatter. Orchestrators dispatch to specialized agents automatically.
Configuration Files
.mcp.json (Claude Code)
cost_hook.py (Automatic Cost Tracking)
Add to Claude Code settings.json:
Logs to cost-tracking.json:
Brain System (Persistent Memory)
Python API:
Payload System
Rules Engine
Framework ships rules/payloads.md with 2,500 lines of categorized payloads:
Payload categories:
- SQL injection (MySQL, PostgreSQL, MSSQL, Oracle)
- XSS (reflected, stored, DOM)
- SSRF (cloud metadata, internal endpoints)
- XXE, SSTI, command injection
- JWT manipulation
- GraphQL introspection/batching
- NoSQL injection
Custom Payloads
Add to workspace payloads/<vuln-class>.md:
Agents will query both shipped and custom payloads.
7-Question Gate (Validation)
Every finding must pass before submission:
Exploit Chain Builder
Python API:
Platform Integration Examples
HackerOne
Bugcrowd
Autonomous Hunt Loop
Modes:
--paranoid- Extra validation, slower--normal- Balanced (default)--aggressive- Fast, more false positives
Troubleshooting
MCP Server Not Starting
Writeup Search Falls Back to Local
Brain Not Persisting
Cost Tracking Not Working
Installer Conflicts
Provider Bundle Out of Sync
Cross-IDE Compatibility
All targets get the same 50 agents, 26 commands, 2 MCP servers — only the file format differs.


