Chain Builder — Development agent for Claude Code
Exploit chain builder.
How to install Chain Builder
Installs to ~/.claude/agents/mikacr1138-claude-bug-bounty-chain-builder.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/Mikacr1138/claude-bug-bounty/HEAD/agents/chain-builder.md -o ~/.claude/agents/mikacr1138-claude-bug-bounty-chain-builder.md Restart Claude Code, or start a new session, for it to be picked up.
What Chain Builder does
name: chain-builder description: Exploit chain builder. Given bug A, identifies B and C candidates to chain for higher severity and payout. Knows all major chain patterns — IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth, prompt injection→IDOR, subdomain takeover→OAuth redirect. Use when you have a low/medium finding that needs a chain to be submittable. tools: Read, Bash, WebFetch model: claude-sonnet-4-6
Chain Builder Agent
You are
Alternatives in Development
- Recon Ranker — Attack surface ranking agent 4.5k ★
- Correlator — Finding correlation engine 812 ★
- Parts Contributor — Use when adding or modifying a part in the Cosmos parts library — a new switch, microcontroller, display, trac 662 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Zp Class Hunter
ZeroProtocol single-class vulnerability hunter. Use to hunt exactly one vulnerability class against one in-sco
Dynamic Verifier
静的解析結果を動的に検証するエージェント。SQLi/XSS/Auth/CSRF/SSRF/File検証対応。
Penetration Tester
Use this agent for AUTHORIZED penetration testing of your own applications on local or staging environments on
Ssrf Hunter
Active SSRF hunter for an ingested program. Consumes webvuln-surface injection points (ssrf_likely params + UR
XSS Hunter
Active XSS hunter for an ingested program. Consumes webvuln-surface injection points (reflected params + DOM s
Aiskills Code Reviewer
Reviews diffs and pull requests with visible per-dimension passes and severity-classified findings (Blocker/Ma
Related Skills
Chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common ch
/chain
Build an A→B→C exploit chain for higher severity and payout.
Vibesec
Helps write secure code by preventing common vulnerabilities including IDOR, XSS, SQL injection, SSRF, and wea