Claude Code bug-hunting bundle packs 574 report patterns

ElementalSoul has released claude-bughunter, a self-contained skill bundle for Claude Code aimed at bug hunting and external red-team work. The package includes 51 skills, 15 slash commands, and more than 574 disclosed-report patterns across 24 vulnerability classes.

Claude Code bug-hunting bundle packs 574 report patterns

ElementalSoul has published claude-bughunter, a self-contained skill bundle for Claude Code that is meant to help with bug hunting and external red-team work. The project is described as a drop-in addition to Claude Code’s skills system, with 51 skills, 15 slash commands, and more than 574 disclosed-report patterns drawn from public HackerOne reports and other sources.

According to the project description, the bundle is designed to make Claude Code behave less like a chat assistant and more like a bug-hunting researcher or external red-team operator. It includes workflow guidance, payload and bypass tables, reporting templates, and discipline rules for validating findings before they are written up.

⚡ New to this?

This matters because it shows how security teams are starting to package AI tools around specific workflows, not just general chat. A skill bundle is a set of instructions and templates that changes how Claude Code behaves in a narrow task, in this case bug hunting and external red teaming. For non-experts, the key point is that the tool is aimed at helping security researchers test internet-facing systems more consistently.

🦞 OpenClaw angle

If you build self-hosted agent workflows, separate the hunting logic from the reporting logic the way this bundle does. Keep validation gates in a dedicated step so your agent does not turn every weak lead into a report, and store chained findings with stable IDs so sessions can pick them up later. If you support external security testing, add an explicit scope layer that blocks internal-only tactics, post-exploit steps, and persistence by default.

The package is organized around four layers. Those layers cover bug-bounty methodology, a set of 24 hunt-* skills for web applications, enterprise platform attack chains, and a validation-and-reporting layer that handles triage, evidence hygiene, and final writeup formatting.

The web-app hunting layer covers common bug classes such as SQL injection, XSS, IDOR, SSRF, file upload abuse, GraphQL issues, OAuth and SAML flaws, and race conditions. The project says those skills are curated from 574 disclosed reports and are intended to load automatically when a user describes the test in plain English.

The enterprise attack layer focuses on internet-facing targets such as Microsoft 365 and Entra ID, Okta, VMware vCenter, SharePoint, SSL VPN appliances, Android APK analysis, and supply-chain recon. The bundle also includes cloud misconfiguration and post-credential escalation paths, such as public S3 buckets, IMDS chains, and cross-account role assumptions.

ElementalSoul says the bundle is intended only for external attack surfaces - anything reachable from the internet without first compromising an internal endpoint. It explicitly excludes internal Active Directory attacks, C2 frameworks, post-exploit persistence, evasion, iOS, ICS, kernel, and browser exploitation work.

The project also includes a 6-phase loop: scope, recon, hunt, validate, capture, and report. During validation, the bundle uses a 7-Question Gate to decide whether a lead should be reported, downgraded, killed, or sent back for more chaining.

For red-team mode, the bundle adds a discipline layer that keeps testing in scope and watches for mid-engagement changes such as client-side patches or signs that a SOC, or Security Operations Center, is detecting the activity. The authors say that state is tracked across Claude Code sessions so chained findings can be cross-referenced later.

The bundle is available through slash commands in Claude Code and through a secondary terminal-native CLI called cbh. The project says the CLI can run deterministic recon, triage, and reporting tasks, while the Claude Code interface is meant for judgment-heavy hunting and chaining.

Installation places the skills into Claude’s skills directory and copies the commands into the user’s Claude commands folder. The project also lists public training platforms, including DVWA, OWASP Juice Shop, Hacker101, and testphp.vulnweb.com, as places where the bundle has been exercised.

Source: HN Show HN ↗

More from Security News