Bug Bounty
Bug Bounty is an agent skill (a SKILL.md file) from elementalsouls/Claude-BugHunter. Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind. It works with Claude Code, Codex and OpenCode and has 4,784 GitHub stars across a repository of 4 listed skills.
github.com/elementalsouls/Claude-BugHunter/skills/bug-bounty (opens in a new tab)
- Multi-skill repo
- Plugin marketplace
- Needs API key
- Testing & QA
- Actively maintained
Add this skill
Claude
This repository is a Claude Code plugin marketplace. In Claude Code:
/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsoulsIn the Claude apps, zip the bug-bounty folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).
ChatGPT / Codex
Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:
git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git
cp -r Claude-BugHunter/skills/bug-bounty .agents/skills/bug-bounty # repo; ~/.agents/skills for all projectsStandalone skills also load in the ChatGPT desktop app.
Cursor
Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:
git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git
cp -r Claude-BugHunter/skills/bug-bounty .cursor/skills/bug-bounty # project; ~/.cursor/skills for all projectsSource (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), code.claude.com/docs/en/plugin-marketplaces (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)
What this skill does
Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security…
More skills in elementalsouls/Claude-BugHunter
4 skills are listed from this repository.
Similar skills
More testing & qa skills
Systematic Debugging
obra/superpowers
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
Testing & QAShellTest Driven Development
obra/superpowers
Use when implementing any feature or bugfix, before writing implementation code.
Testing & QAShellVerification Before Completion
obra/superpowers
Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims…
Testing & QAShellFinishing A Development Branch
obra/superpowers
Use when implementation is complete, all tests pass, and you need to decide how to integrate the work.
Testing & QAShellDiagnosing Superpowers
obra/superpowers
Use when a superpowers session went wrong and your human partner wants to know why — repeated work, ignored plans, stumbles, poor results, a skill that didn't fire, "it took too long", "why is it so…
Testing & QAShellTDD
mattpocock/skills
Test-driven development. Use when the user wants to build features or fix bugs test-first, mentions "red-green-refactor", or wants integration tests.
Testing & QAShell
What is the Bug Bounty skill?
Bug Bounty is an agent skill (a SKILL.md file) from elementalsouls/Claude-BugHunter. Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind. It works with Claude Code, Codex and OpenCode and has 4,784 GitHub stars across a repository of 4 listed skills. Its SKILL.md lives at github.com/elementalsouls/Claude-BugHunter/skills/bug-bounty.
How do I install the Bug Bounty skill?
In Claude Code, run /plugin marketplace add elementalsouls/Claude-BugHunter and then /plugin install claude-bughunter@elementalsouls. For Codex or Cursor, copy the bug-bounty folder into .agents/skills/ or .cursor/skills/.
Is the Bug Bounty skill free?
Yes. The repository is open source under the MIT license. The skill mentions an API key or token for an external service, which may need its own account.
Is Bug Bounty maintained?
The repository's most recent commit was on Oct 6, 2026. Its latest release is v2.1. appsgit only lists skills from repositories with a commit in the last six months.