RadarTopicsBuildersWeeklyReads
Open Source Radar
elementalsouls/

Claude-BugHunter

GitHubWebsite

Claude-BugHunter is a Python-based Claude Code skill bundle with 82 skills, 15 slash commands, and 681 disclosed-report patterns across 24 vulnerability classes, released in 2026 and active as of last push on 2026-08-03.

3.3kstars
500forks
2issues
2026since
Star historydaily snapshots by VibeCrowd

Collecting history — the radar snapshots this repo daily. The trend line appears after 3 days of data (1 so far).

Alternatives & relatedmatched by topic overlap
usestrix/
strix
2.6k/wk

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

48k5.1kPython
KeygraphHQ/
shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

46k5.4kTypeScriptgiant
thedotmack/
claude-mem
660/wk

Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More

90k7.8kJavaScript
mukul975/
Anthropic-Cybersecurity-Skills
470/wk

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

27k3.3kPython
Egonex-AI/
Understand-Anything

Graphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.

77k6.5kTypeScriptgiant
code-yeongyu/
oh-my-openagent
483/wk

omo/lazycodex: The coding agent for tokenmaxxers;the one and only agent harness for complex codebases. For your Codex, for your OpenCode

67k5.5kTypeScript
Reviewgenerated from repository data · Aug 5, 2026

What it is

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. It provides 82 skills and 15 slash commands, plus an engagement scaffold and enterprise identity & infrastructure attack matrices to support bug hunting and external red-team work.

How it works

The bundle follows a 6-phase workflow: recon → map & rank → hunt → validate → report, with a 7-Question Gate before submission. It can be driven by plain English descriptions or by a /hunt scaffold plus cbh CLI. It includes an engagement engine that maps a target's attack surface and routes findings to appropriate skills.

Getting started

Quickstart options:

Option A — install as a Claude Code plugin (recommended).

/plugin marketplace add elementalsouls/Claude-BugHunter
/plugin install claude-bughunter@elementalsouls

All 82 skills + 15 commands load namespaced under claude-bughunter: and update when you bump the plugin version.

Option B — copy install (no plugin system / pin to a clone):

git clone https://github.com/elementalsouls/Claude-BugHunter.git
cd Claude-BugHunter
bash scripts/install.sh  # macOS / Linux
pwsh ./scripts/install.ps1   # Windows (PowerShell)

Both copy the skills into ~/.claude/ (macOS/Linux) or %USERPROFILE%\.claude\ (Windows) and wire the hunt engagement scaffolder.

What each path provides:

  • A — plugin: 82 skills + 15 slash commands, separate pipx install for cbh CLI, no clone required.
  • B — copy install: 82 skills + 15 slash commands copied into user path and cbh CLI available from the clone.

The plugin is the fastest path; the cbh runner installs standalone via:

pipx install git+https://github.com/elementalsouls/Claude-BugHunter

The hunt engagement scaffolder ships with the clone (Option B).

Then open Claude Code and describe what you’re testing in plain English to load the appropriate skills.

Recent releases

  • v2.1 (2026-06-05): Second major bundle release with 51 → 71 skills, a CI gate, a docs site, and security fixes to the toolkit's own code. Added 20 new hunt-* skills.
  • v2.0 (2026-05-25): Workstream A — Report-curation backfill across 11 hunt-* skills; improvements to missing surfaces, chains, and engagements.

Traction

Stars: 3290. Forks: 500. Open issues: 2.

Behind the repo

Not provided in the facts block.

Caveats

License: none listed. Created: 2026-05-05. Last push: 2026-08-03. The repository is a Python project focused on bug-hunting and red-team workflows, with an MIT LICENSE file not indicated in the facts. Documentation references multiple installation and usage guides. Security posture and authorization guidance are included in the documentation.

SharePost on XLinkedIn
All trending reposRevenue-verified startups →