security
May 20, 2026
By Teun
Claude Code bug-hunting bundle packs 574 report patterns
ElementalSoul has released claude-bughunter, a self-contained skill bundle for Claude Code aimed at bug hunting and external red-team work. The package includes 51 skills, 15 slash commands, and more than 574 disclosed-report patterns across 24 vulnerability classes.
ElementalSoul has published claude-bughunter, a self-contained skill bundle for Claude Code that is meant to help with bug hunting and external red-team work. The project is described as a drop-in addition to Claude Code’s skills system, with 51 skills, 15 slash commands, and more than 574 disclosed-report patterns drawn from public HackerOne reports and other sources.
According to the project description, the bundle is designed to make Claude Code behave less like a chat assistant and more like a bug-hunting researcher or external red-team operator. It includes workflow guidance, payload and bypass tables, reporting templates, and discipline rules for validating findings before they are written up.
The package is organized around four layers. Those layers cover bug-bounty methodology, a set of 24 hunt-* skills for web applications, enterprise platform attack chains, and a validation-and-reporting layer that handles triage, evidence hygiene, and final writeup formatting.
The web-app hunting layer covers common bug classes such as SQL injection, XSS, IDOR, SSRF, file upload abuse, GraphQL issues, OAuth and SAML flaws, and race conditions. The project says those skills are curated from 574 disclosed reports and are intended to load automatically when a user describes the test in plain English.
The enterprise attack layer focuses on internet-facing targets such as Microsoft 365 and Entra ID, Okta, VMware vCenter, SharePoint, SSL VPN appliances, Android APK analysis, and supply-chain recon. The bundle also includes cloud misconfiguration and post-credential escalation paths, such as public S3 buckets, IMDS chains, and cross-account role assumptions.
ElementalSoul says the bundle is intended only for external attack surfaces - anything reachable from the internet without first compromising an internal endpoint. It explicitly excludes internal Active Directory attacks, C2 frameworks, post-exploit persistence, evasion, iOS, ICS, kernel, and browser exploitation work.
The project also includes a 6-phase loop: scope, recon, hunt, validate, capture, and report. During validation, the bundle uses a 7-Question Gate to decide whether a lead should be reported, downgraded, killed, or sent back for more chaining.
For red-team mode, the bundle adds a discipline layer that keeps testing in scope and watches for mid-engagement changes such as client-side patches or signs that a SOC, or Security Operations Center, is detecting the activity. The authors say that state is tracked across Claude Code sessions so chained findings can be cross-referenced later.
The bundle is available through slash commands in Claude Code and through a secondary terminal-native CLI called cbh. The project says the CLI can run deterministic recon, triage, and reporting tasks, while the Claude Code interface is meant for judgment-heavy hunting and chaining.
Installation places the skills into Claude’s skills directory and copies the commands into the user’s Claude commands folder. The project also lists public training platforms, including DVWA, OWASP Juice Shop, Hacker101, and testphp.vulnweb.com, as places where the bundle has been exercised.