Bugwolf banner
youseefhamdi youseefhamdi

Bugwolf

Security community

Description

BugWolf — all-round bug bounty hunting skill for Claude Code: parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, CI/CD attacks, LLM/agentic AI security, and submission-ready reports for HackerOne, Bugcrowd, Intigriti & Immunefi

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

README

BugWolf

██████╗ ██╗   ██╗ ██████╗ ██╗    ██╗ ██████╗ ██╗      ███████╗
██╔══██╗██║   ██║██╔════╝ ██║    ██║██╔═══██╗██║      ██╔════╝
██████╔╝██║   ██║██║  ███╗██║ █╗ ██║██║   ██║██║      █████╗
██╔══██╗██║   ██║██║   ██║██║███╗██║██║   ██║██║      ██╔══╝
██████╔╝╚██████╔╝╚██████╔╝╚███╔███╔╝╚██████╔╝███████╗██║
╚═════╝  ╚═════╝  ╚═════╝  ╚══╝╚══╝  ╚═════╝ ╚══════╝╚═╝

██╗  ██╗██╗   ██╗███╗   ██╗████████╗███████╗██████╗
██║  ██║██║   ██║████╗  ██║╚══██╔══╝██╔════╝██╔══██╗
███████║██║   ██║██╔██╗ ██║   ██║   █████╗  ██████╔╝
██╔══██║██║   ██║██║╚██╗██║   ██║   ██╔══╝  ██╔══██╗
██║  ██║╚██████╔╝██║ ╚████║   ██║   ███████╗██║  ██║
╚═╝  ╚═╝ ╚═════╝ ╚═╝  ╚═══╝   ╚═╝   ╚══════╝╚═╝  ╚═╝

All-round authorized security-research skill for Claude Code and Freebuff — parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, local tooling orchestration, and submission-ready reports for HackerOne, Bugcrowd, Intigriti & Immunefi.

**AI Pentesting Tool:** Run isolated, cloud-hosted pentesting sandboxes at **[bugwolf.xyz](https://bugwolf.xyz)** — your AI key, your Firecracker microVM, your report. Pipeline: recon → hunt → triage → H1-ready report. AI slop gets you rate-limited; BugWolf gets you paid.

**New in v1.0.0:** LLM / Agentic AI security track (OWASP GenAI LLM Top 10 2026 + Agentic Top 10 ASI01–ASI10), RAG & embedding attacks, MCP security, mobile + cloud-native vectors, and a zero-day LLM attack-surface detector. See [CHANGELOG.md](CHANGELOG.md).

**Operating mode:** Production campaigns run only from an operator-supplied target specification and attestation. The operator defines the exact boundary and Rules of Engagement; BugWolf records that provenance and applies maximum capability inside it. Local fixtures (VulnBank, Anvil, LocalStack, and stubs) validate the pipeline only; they are not the production boundary.


APT Commander — Strict Workflow, Uncensored Execution

BugWolf is architected as an **APT Commande