51 skills · 15 commands · 574+ H1 patterns

Turn Claude into Bug hunter

51 specialized skills built from real bug bounty disclosures. Auto-load by context. 7-Question Gate before every submission.

Browse all skillsView on GitHub
/hunt-sqli·/hunt-xss·/hunt-oauth·/hunt-idor·/hunt-ssrf·/hunt-rce·/osint-methodology·/cloud-iam-deep·/triage-validation·/hunt-saml·/apk-redteam-pipeline·/hunt-csrf·/report-writing·/web3-audit·/m365-entra-attack·/supply-chain-attack-recon·/hunt-graphql·/evidence-hygiene·/hunt-auth-bypass·/redteam-mindset·/hunt-sqli·/hunt-xss·/hunt-oauth·/hunt-idor·/hunt-ssrf·/hunt-rce·/osint-methodology·/cloud-iam-deep·/triage-validation·/hunt-saml·/apk-redteam-pipeline·/hunt-csrf·/report-writing·/web3-audit·/m365-entra-attack·/supply-chain-attack-recon·/hunt-graphql·/evidence-hygiene·/hunt-auth-bypass·/redteam-mindset·
51
Production-ready skills — ready to install today
8
Attack domains
15
Slash commands
574
H1 patterns sourced
Two ways to use

Static review
or live hunt

Every skill works in Claude Chat for code review artifacts. Connect Claude Code and the same skill gains live HTTP access, tool execution, and streaming output.

Chat ✓
Claude Chat
Upload ZIP → paste code → get findings artifact
Code ✓
Claude Code
Install bundle → /hunt target.com → live scan
cbug — hunt session
Featured skills
all 6 have demos

The full workflow, one command at a time

Purpose-built for each attack class. Each card below has a recorded demo — click to watch it run live.

View all 51 skills →
Workflow

Three steps. No setup.

Click any node to explore what happens at each step of the hunting workflow.

Choose domain

Browse 8 security attack domains

Select skill

One skill or the full domain

Download ZIP

From GitHub in one click

cbug

claude.ai

/customize/skills

Upload to Claude

claude.ai/customize/skills

Run command

/hunt-sqli, /hunt-xss, /triage...

Get findings

Report-ready markdown artifact

Choose domain

Browse 8 security attack domains

Select skill

One skill or the full domain

Download ZIP

From GitHub in one click

Upload to Claude

claude.ai/customize/skills

Run command

/hunt-sqli, /hunt-xss, /triage...

Get findings

Report-ready markdown artifact

↑ click any node to explore

How it works

Three steps to your first finding

01
Install the skill bundle
Download the ZIP from GitHub. Upload to claude.ai/customize/skills or drop the folder in your Claude Code project. No API keys, no infrastructure.
02
Claude auto-loads by context
Skills activate on signal — paste a JWT and the auth skill loads. Drop an APK path and the mobile pipeline loads. No manual selection.
03
Gate before submit
Every finding runs through the 7-Question Gate. One wrong answer kills the report. Your N/A ratio stays clean and your reputation stays intact.
Attack domains

8 domains, one install

Install a single skill or an entire domain. Each subfolder is independent.

Quality gate

The 7-Question Gate

Every finding must clear all 7 before a report gets written. One wrong answer kills it. This is how your N/A ratio stays clean.

01Is this in scope?
02Can I prove it's exploitable?
03Is there real impact?
04Did I reproduce it twice?
05Is the PoC clean?
06Have I checked for duplicates?
07Would I be proud to send this?
Read the full gate
Why cbug

The foundation for bug hunting AI.

Purpose-built
Every skill was designed for a specific attack class — not adapted from a generic template.
Zero setup
Download a ZIP, upload to Claude. No API keys, no infrastructure, no code.
MIT License
Fork the repo, edit the SKILL.md files, upload your version. 100% open source.
Live target ready
Claude Code mode gives skills real HTTP access, tool execution, and streaming output.

Ready to install your first skill? Start in minutes.

Browse all 8 attack domains — 51 specialized skills, MIT licensed.

Browse all 8 domainsRead the install guide

Works with Claude Free, Pro, Teams, and Enterprise · MIT License