Bugwolf
Description
BugWolf — all-round bug bounty hunting skill for Claude Code: parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, CI/CD attacks, LLM/agentic AI security, and submission-ready reports for HackerOne, Bugcrowd, Intigriti & Immunefi
Installation
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open the source below and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
README
BugWolf
██████╗ ██╗ ██╗ ██████╗ ██╗ ██╗ ██████╗ ██╗ ███████╗
██╔══██╗██║ ██║██╔════╝ ██║ ██║██╔═══██╗██║ ██╔════╝
██████╔╝██║ ██║██║ ███╗██║ █╗ ██║██║ ██║██║ █████╗
██╔══██╗██║ ██║██║ ██║██║███╗██║██║ ██║██║ ██╔══╝
██████╔╝╚██████╔╝╚██████╔╝╚███╔███╔╝╚██████╔╝███████╗██║
╚═════╝ ╚═════╝ ╚═════╝ ╚══╝╚══╝ ╚═════╝ ╚══════╝╚═╝
██╗ ██╗██╗ ██╗███╗ ██╗████████╗███████╗██████╗
██║ ██║██║ ██║████╗ ██║╚══██╔══╝██╔════╝██╔══██╗
███████║██║ ██║██╔██╗ ██║ ██║ █████╗ ██████╔╝
██╔══██║██║ ██║██║╚██╗██║ ██║ ██╔══╝ ██╔══██╗
██║ ██║╚██████╔╝██║ ╚████║ ██║ ███████╗██║ ██║
╚═╝ ╚═╝ ╚═════╝ ╚═╝ ╚═══╝ ╚═╝ ╚══════╝╚═╝ ╚═╝
All-round authorized security-research skill for Claude Code and Freebuff — parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, local tooling orchestration, and submission-ready reports for HackerOne, Bugcrowd, Intigriti & Immunefi.
**AI Pentesting Tool:** Run isolated, cloud-hosted pentesting sandboxes at **[bugwolf.xyz](https://bugwolf.xyz)** — your AI key, your Firecracker microVM, your report. Pipeline: recon → hunt → triage → H1-ready report. AI slop gets you rate-limited; BugWolf gets you paid.
**New in v1.0.0:** LLM / Agentic AI security track (OWASP GenAI LLM Top 10 2026 + Agentic Top 10 ASI01–ASI10), RAG & embedding attacks, MCP security, mobile + cloud-native vectors, and a zero-day LLM attack-surface detector. See [CHANGELOG.md](CHANGELOG.md).
**Operating mode:** Production campaigns run only from an operator-supplied target specification and attestation. The operator defines the exact boundary and Rules of Engagement; BugWolf records that provenance and applies maximum capability inside it. Local fixtures (VulnBank, Anvil, LocalStack, and stubs) validate the pipeline only; they are not the production boundary.
APT Commander — Strict Workflow, Uncensored Execution
BugWolf is architected as an **APT Commande
Related Skills
Fastapi Review
Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu
Security Defense in Depth
Implement multi-layered testing and security best practices.
Security SecLists Official Repository
[OWASP Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)
Security Threat Hunting with Sigma Rules
Use Sigma detection rules to hunt for threats and analyze security events
Security Maintenance Walkthrough - 2026-03-29
- Re-triaged the full 2026-03-15 security finding set against current `main` and wrote a fresh current-head re
Security Google Workspace Model Armor
Filter user-generated content for safety
Security Related Agents
Django Reviewer
Expert Django code reviewer specializing in ORM correctness, DRF patterns, migration safety, security misconfi
Token Auditor
Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d
Gitnexus Security Boundary Reviewer
GitNexus security and trust-boundary reviewer. Use for auth, permissions, secrets, injection, unsafe parsing,