Agentic-Bug-Hunter
AI-powered bug bounty hunting toolkit that works with or without subscription.
Agentic Bug Hunter is an AI-powered security testing toolkit that functions as both a Claude Code plugin and a standalone CLI tool for bug bounty reconnaissance and vulnerability discovery. It automates the full workflow from reconnaissance through vulnerability scanning, validation, and report generation for platforms like HackerOne and Bugcrowd. The toolkit supports multiple AI providers including free options like Ollama and Groq, making it accessible without requiring paid subscriptions. It identifies 26 web application vulnerability classes and 10 smart contract bug types, with built-in memory to learn patterns across hunting sessions.
Key Features
Use Cases
- 01Automated bug bounty reconnaissance to map attack surfaces and discover subdomains
- 02AI-assisted vulnerability hunting for IDOR, SSRF, XSS, SQL injection, and authentication bypasses
- 03Smart contract security audits for DeFi protocols and token contracts
- 04Validation of security findings before submitting to bug bounty platforms
- 05Generating professional security reports with impact analysis and proof-of-concept
- 06Training security researchers with integrated methodology and hunting patterns
Related Plugins
View moreandrej-karpathy-skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
claude-mem
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Understand-Anything
Graphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
rtk
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
Agentic-Bug-Hunter — FAQ
What is Agentic Bug Hunter and what does it do?+
Agentic Bug Hunter is an AI-powered security testing toolkit that automates bug bounty hunting from reconnaissance through vulnerability discovery, validation, and report generation. It can run as a Claude Code plugin or as a standalone CLI tool using various AI providers including free options.
How do I install Agentic Bug Hunter?+
For standalone mode, clone the repository and run './install.sh --agent standalone', then configure an AI provider with 'bughunter setup'. For Claude Code plugin mode, clone the repo, run './install_tools.sh' to install scanning dependencies, then './install.sh' to add skills and commands to Claude Code.
Which AI clients does this work with?+
It works with Claude Code as a native plugin and as a standalone CLI tool that supports multiple AI providers including Ollama (local), Groq, DeepSeek, Claude API, OpenAI, Grok, OpenRouter, and LiteLLM. It can also integrate with OpenCode, Pi Agent, and Codex.
Do I need API keys or a paid subscription?+
No subscription is required. You can use completely free options like Ollama (runs locally) or Groq's free tier. Paid providers like Claude API and OpenAI are supported but optional.
What are the prerequisites for using this tool?+
You need Python 3.10+, Go, and jq installed on your system. The install_tools.sh script will install required security scanning tools (subfinder, httpx, nuclei, etc.). An AI provider must be configured, but free options are available.
Is Agentic Bug Hunter free to use?+
Yes, the toolkit itself is MIT-licensed and free. You can use it completely free with local AI models via Ollama or free-tier cloud providers like Groq. Paid AI providers are optional for enhanced capabilities.
How do I install Agentic-Bug-Hunter?+
Open the source repository on GitHub and follow its README. Agentic-Bug-Hunter is a plugin — MCP Agents Market links you directly to the official repo.
Is Agentic-Bug-Hunter free?+
Agentic-Bug-Hunter is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.