# Bug Bounty (agent skill)

> Bug Bounty is an agent skill (a SKILL.md file) from elementalsouls/Claude-BugHunter. Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind. It works with Claude Code, Codex and OpenCode and has 4,784 GitHub stars across a repository of 4 listed skills.

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security…

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/elementalsouls/Claude-BugHunter |
| Skill path | skills/bug-bounty/SKILL.md |
| Skill name | bug-bounty |
| GitHub stars | 4,784 |
| Installs on skills.sh | not listed |
| License | MIT |
| Skills in repo | 4 |
| Plugin marketplace | elementalsouls |
| Official | no |
| Works with | Claude Code, Codex, OpenCode |
| Category | Testing & QA |
| Last commit | Oct 6, 2026 |

## Add this skill

### Claude Code

```sh
/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsouls
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git
cp -r Claude-BugHunter/skills/bug-bounty .agents/skills/bug-bounty   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git
cp -r Claude-BugHunter/skills/bug-bounty .cursor/skills/bug-bounty   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/elementalsouls-bug-bounty
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
