ZBS Index What actually exists in applied AI, with the source next to it

skill

bb-local-toolkit

Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to resolve where tools, wordlists, and clones are installed on the local machine (jhaddix, SecLists, trufflehog, ffuf, dalfox, ghauri); for pure orchestration/routing use the bug-bounty skill. Workflow it covers — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, submission checklist). Use when you need the local install path of a tool / wordlist / clone for a hunt, or as the full-workflow variant when operating from this local toolkit; for general routing use the bug-bounty skill. 中文触发词:漏洞赏金、安全测试、渗透测试、漏洞挖掘、信息收集、子域名枚举、XSS测试、SQL注入、SSRF、安全审计、漏洞报告

Description as published by the maintainer. Source

  • active

active — Most recent push to the repository was 2026-08-03.

Signals

These are separate measurements of different things. They are deliberately not combined into one score, because a popularity number that mixes website traffic with saves and stars cannot be checked or acted on.

Signal Value What it measures Window Observed Source
GitHub stars 3,319 Stars on the repository that contains this skill, not on the skill itself. A collection of fifty skills shares one number, so it says nothing about this particular skill. cumulative, all time GitHub
Last commit 2026-08-03 Most recent push to the containing repository. It may reflect work on a different skill in the same collection. point in time GitHub
repository status active The repository holding this skill exists and is not archived. as of fetch GitHub

Will this work with your setup?

Install location suggests this is meant for claude-code. The author tagged this repository "claude-skills" on GitHub. That is their statement of intent, not a test result.

We have not run this skill against a task with and without it enabled, so we cannot tell you whether it improves anything, what it costs in tokens, or whether it duplicates behaviour your harness already has. When we have run that test, the result will appear on this page with the task, the versions and the budget it used.

The skill definition lives at skills/bb-local-toolkit/SKILL.md in https://github.com/elementalsouls/Claude-BugHunter.

Where to get it

Related, by what their authors tagged them

  • elementalsouls-claude-bughunter-apk-redteam-pipeline — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx…
  • elementalsouls-claude-bughunter-bb-methodology — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next.…
  • elementalsouls-claude-bughunter-bug-bounty — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source c…
  • elementalsouls-claude-bughunter-bugcrowd-reporting — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exa…
  • elementalsouls-claude-bughunter-cloud-iam-deep — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-dis…
  • elementalsouls-claude-bughunter-enterprise-vpn-attack — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix Net…
  • elementalsouls-claude-bughunter-evidence-hygiene — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to ma…
  • elementalsouls-claude-bughunter-hunt-api-misconfig — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering. Mass assignment: send {…
  • elementalsouls-claude-bughunter-hunt-aspnet — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser…
  • elementalsouls-claude-bughunter-hunt-ato — last commit 2026-08-03, shares ai-security, application-security, bug-bounty
    Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1) password reset flaws (host-header inj…

These share tags the maintainers applied themselves, such as ai-security, application-security, bug-bounty, bugbounty. Common tags like "mcp" or "ai" are ignored for this: agreeing with six hundred other projects is not a similarity.

This is not a recommendation and not a test result. It is a map of what the authors said their work is about.

Also from elementalsouls

How the author describes it

Topics the maintainer set on GitHub: ai-security, anthropic, application-security, bug-bounty, bugbounty, bugcrowd, claude, claude-code, claude-skills, ethical-hacking, hackerone, offensive-security, pentesting, red-team, security-tools, web-security.

Bring your own setup

We take apart real AI setups every week and show what broke, what cost too much, and what the trace actually said. If you run agents on real work, that is where the useful conversation is.

Join ZBS AI Practice Lab

Sources

  1. elementalsouls/Claude-BugHunter on GitHub — GitHub, observed , trust tier 3.