
This is a complete autonomous bug bounty framework that runs inside Claude Code and other AI coding tools. You get 50 specialized agents for hunting SQLi, XSS, IDOR, and other vulns, plus two MCP servers that pull live program scopes from HackerOne and search through your own indexed writeup corpus. The standout piece is the 7-Question Gate validator that checks if findings are actually exploitable before you waste time writing reports, and a chain builder that links multiple weak findings into serious exploits. It scaffolds entire workspace directories per program with persistent brain tracking for endpoints you've already tested. The cross-IDE installer handles Cursor, Windsurf, Copilot, and others if you're not on Claude Code. Built by ara.so's security team, ships 2,500 lines of actual payloads rather than generic advice.
npx -y skills add aradotso/security-skills --skill pentest-agents-bug-bounty-framework --agent claude-codeInstalls into .claude/skills of the current project.
Select a file.