
Web2 bug bounty Agent Skill — 증거 기반, AI 쓰레기 없음. HackerOne, Bugcrowd, Intigriti 및 YesWeHack에서 18개의 취약점 클래스를 다룹니다.
구조화된 web2 버그 바운티 AI 스킬 — 18가지 취약점 클래스, 4개 버그 바운티 플랫폼, AI 노이즈 제로. OpenClaw, Cursor, Claude Code, Antigravity, Windsurf와 호환 가능.
BugReaper는 Agent Skill로, 호환되는 AI 에이전트를 훈련된 web2 버그 바운티 헌터로 바꿔줍니다. 증거 기반 검증을 강제하고, HackerOne, Bugcrowd, Intigriti, YesWeHack의 실제 트라이지 과정을 시뮬레이션하며, 낮은 심각도의 버그를 연결하여 치명적인 발견으로 만듭니다. 모든 발견은 보고 전에 작동하는 PoC가 필요합니다.
| 에이전트 | 지원 | 스킬 디렉토리 |
|---|---|---|
| OpenClaw | ✅ 네이티브 | ClawHub를 통해 설치 |
| Cursor | ✅ 네이티브 | .cursor/skills/bug-reaper/ |
| Claude Code | ✅ 네이티브 | .claude/skills/bug-reaper/ |
| Antigravity | ✅ 네이티브 | .agents/skills/bug-reaper/ |
| Windsurf | ✅ 네이티브 | Skills directory |
| Goose | ✅ 지원 | Skills directory |
Agent Skills 형식은 2025년 12월에 공개 표준이 되었습니다. BugReaper는 수정 없이 모든 호환 에이전트에 설치됩니다.
bug-reaper/
├── SKILL.md # 에이전트 트리거 + 4단계 워크플로우
├── references/
│ ├── recon.md # 7단계 리콘 방법론
│ ├── audit-rules.md # 엄격한 증거 요구 사항
│ ├── exploit-validation.md # 입력 → 싱크 추적
│ ├── false-positive-elimination.md # 적대적 FP 체크리스트
│ ├── severity-guide.md # CVSS 점수 + 플랫폼 등급 맵
│ ├── waf-bypass.md # 15개 WAF 제품, 10가지 우회 기술
│ ├── chaining.md # 8개 체인 템플릿 (P3 → P1 상향)
│ ├── platforms/ # HackerOne · Bugcrowd · Intigriti · YesWeHack
│ └── vulnerabilities/ # 18개 사냥 방법론 파일
└── scripts/
├── analyze_scope.py # 프로그램 범위 파싱 → 구조화된 JSON
└── generate_report.py # 플랫폼별 마크다운 보고서 생성
18가지 취약점 방법론 — 각각 확인 페이로드, 우회 기술, 증거 요구 사항, 실제 트라이지 패턴을 반영한 "보고하지 마세요" 규칙이 포함됩니다.
/install bug-reaper
또는 ClawHub에서 bug-reaper를 검색하세요.
# 프로젝트 루트에서 실행
git clone https://github.com/shaniidev/bug-reaper .cursor/skills/bug-reaper # Cursor
git clone https://github.com/shaniidev/bug-reaper .claude/skills/bug-reaper # Claude Code
git clone https://github.com/shaniidev/bug-reaper .agents/skills/bug-reaper # Antigravity
이 스킬은 에이전트 대화에서 bug bounty, pentest, find vulnerabilities 또는 취약점 클래스 이름을 언급하면 자동으로 트리거됩니다.
1단계 — RECON (references/recon.md)
수동 서브도메인 열거, 기술 핑거프린팅, JS 번들 마이닝, 엔드포인트 발견, 공격 표면 매핑. 단일 페이로드를 사용하기 전에 7단계의 구조화된 절차를 따릅니다.
2단계 — AUDIT (references/vulnerabilities/)
18가지 취약점 클래스가 바운티 ROI 순서로 정렬됩니다. 각 클래스에 대한 관련 방법론 파일을 읽어 확인 페이로드, 우회 기술, 악용 가능성을 주장하기 전에 검증해야 할 방어책을 확인합니다.
3단계 — VALIDATE (references/exploit-validation.md + references/false-positive-elimination.md)
공격자가 제어하는 입력을 진입점에서 위험한 싱크까지 추적합니다. 보고 전에 각 발견을 능동적으로 반증하려는 적대적 체크리스트를 적용합니다. 실제 PoC 출력이 제공될 때까지 발견은 이론적 상태로 유지됩니다.
4단계 — REPORT (references/platforms/ + scripts/generate_report.py)
플랫폼에 적합한 보고서를 생성합니다. 트라이지 체크리스트, 심각도 점수, 보고서 템플릿이 대상 플랫폼의 실제 승인 기준과 일치합니다.
| 카테고리 | 포함 |
|---|---|
| 인증 및 접근 | IDOR/BOLA, Auth/OAuth/JWT Bypass, CORS, CSRF |
| 인젝션 | SQL, NoSQL (MongoDB $ne/$gt/$regex), XXE, SSRF, SSTI, LFI |
| 최신 공격 | API/GraphQL (BOLA, BFLA, batching), Prototype Pollution, HTTP Request Smuggling |
| 인프라 | Subdomain Takeover (14 service fingerprints), RCE, Business Logic |
| 클라이언트 측 | XSS (reflected/stored/DOM), Open Redirect (OAuth chain) |
각 파일에는 다음이 포함됩니다: 탐지 프로브 · 확인 페이로드 · 방어 우회 기술 · 증거 요구 사항 · 영향 분류 · "보고하지 마세요" 규칙.
프로그램 범위 파일 분석:
python scripts/analyze_scope.py hackerone_program.md --output scope.json
플랫폼별 취약점 보고서 생성:
python scripts/generate_report.py \
--platform hackerone \
--vuln-type idor \
--input finding.json \
--output report.md
지원되는 플랫폼: hackerone · bugcrowd · intigriti · yeswehack
지원되는 취약점 유형: xss · sqli · nosqli · ssrf · idor · auth · biz-logic · cors · csrf · rce · ssti · lfi · xxe · open-redirect · subdomain-takeover · prototype-pollution · http-smuggling · api-graphql
BugReaper가 취약점을 발견하면 다음 구조를 사용합니다:
Title: IDOR on Order History — Any User's Orders Accessible
Severity: High
Confidence: Confirmed
Attack Prerequisites: Authenticated user (any account)
Vulnerable Endpoint: GET /api/v2/orders/{order_id}
Attack Path:
1. Authenticate as User A, place an order → note order_id
2. Authenticate as User B
3. Request GET /api/v2/orders/<User_A_order_id>
4. Full order details returned — items, address, payment summary
Why This Is Exploitable: No ownership check on the orders endpoint. The
backend retrieves the order by ID alone with no session validation.
Realistic Impact: Any authenticated user reads another user's full order
history including shipping address and last 4 card digits.
PoC Request:
GET /api/v2/orders/10482 HTTP/1.1
Authorization: Bearer <User_B_token>
Suggested Verification: Run the above request. Confirm order 10482 belongs
to a different account than the token.
Recommended Fix: Validate req.user.id === order.userId before returning.
PR 환영합니다 — 추가 플랫폼 지원, 새로운 취약점 클래스, 업데이트된 우회 기술, 개선된 트라이지 체크리스트. 중요한 변경 사항은 먼저 이슈를 열어주세요.
MIT © 2026 shaniidev