
Agentic-Bug-Hunter
AI-powered bug bounty hunting toolkit that works with or without subscription.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Vulnerability Assessment Scanner with Report Generation

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Proof-of-concept demonstrating a SQL injection vulnerability in Bookea-tu-Mesa with vulnerable code analysis and a prepared statement fix.

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

This skill helps Claude write secure code and prevent common vulnerabilities.