← 返回 Skills 市场
yang1002378395-cmyk

Bug Bounty

作者 yang1002378395-cmyk · GitHub ↗ · v1.0.3 · MIT-0
cross-platform ⚠ suspicious
314
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install bug-bounty
功能描述
Bug Bounty 猎人 - 自动扫描漏洞、生成报告、追踪奖励。适合:安全研究员、白帽子。
使用说明 (SKILL.md)

Bug Bounty 猎人 Skill

自动扫描漏洞,帮你赚取 Bug Bounty 奖励。

核心功能

1. 漏洞扫描

  • SQL 注入检测
  • XSS 漏洞扫描
  • CSRF 漏洞检测
  • 敏感信息泄露

2. 报告生成

  • 专业漏洞报告
  • 复现步骤
  • 修复建议

3. 奖励追踪

  • 项目奖励范围
  • 提交状态
  • 收入统计

使用方法

扫描目标

扫描 example.com 的常见漏洞

生成报告

为发现的漏洞生成 Bug Bounty 报告

查找项目

推荐适合新手的 Bug Bounty 项目

创建:2026-03-11

安全使用建议
This skill is an instruction-only 'bug bounty hunter' that outlines scanning and reporting capabilities but is vague about how scans are performed and lacks safeguards or integrations. Before installing or enabling it: (1) confirm you trust the skill author and understand provenance — source/homepage is unknown; (2) require explicit scope and authorization checks to prevent unauthorized scanning (limit to targets you own or are permitted to test); (3) ask the author for details about what tools or network access the skill expects (e.g., does it call external scanners, require API keys for bounty platforms?); (4) do not grant agent autonomous, unfettered network scanning rights unless you have clear legal authorization and logging; (5) if you plan to use reward-tracking features, require explicit declarations of which services are integrated and any credentials needed, and prefer using dedicated, audited integrations rather than giving broad access. If you need higher assurance, request a more detailed SKILL.md that specifies tooling, safety checks, and required integrations, or decline until provenance and scope are clarified.
功能分析
Type: OpenClaw Skill Name: bug-bounty Version: 1.0.3 The skill bundle defines a 'Bug Bounty Hunter' agent designed to perform automated vulnerability scanning (SQLi, XSS, CSRF) and sensitive information discovery. While the stated intent is security research, these are high-risk capabilities that involve automated network attacks and could be used for unauthorized scanning. No implementation code was provided, but the instructions in SKILL.md define a high-risk operational profile for the AI agent.
能力评估
Purpose & Capability
Name and description (bug bounty scanning, reporting, reward tracking) are consistent with the SKILL.md content. The skill requests no binaries, credentials, or installs — which is plausible for a purely instructional skill, but incomplete: reward-tracking normally requires API credentials or service integration, and automated scanning typically needs explicit tooling (scan engines, rulesets) which are not declared.
Instruction Scope
SKILL.md contains high-level instructions to 'scan example.com for common vulnerabilities' and to generate reports, but it is vague and grants the agent broad discretion about how to perform scans. There are no explicit safeguards, target-scoping rules, or legal/authorization checks. That openness increases the risk the agent could be directed to run intrusive/networked actions against third parties without safeguards.
Install Mechanism
No install spec and no code files — lowest technical risk from installation (nothing is written to disk or downloaded).
Credentials
The skill requests no environment variables or credentials (which reduces risk). However, some advertised features (reward tracking, submission status, income statistics) typically require integrations (HackerOne/Bugcrowd/API keys, email access) that are not declared; the lack of those requirements may mean the feature is conceptual only or incomplete.
Persistence & Privilege
always:false (default) and agent-invocable is normal. The skill does not request persistent system presence or modifications to other skills/config — no elevated privileges requested.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install bug-bounty
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /bug-bounty 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.3
- Added SKILL.md with detailed description, usage instructions, and core features of the bug bounty skill. - Introduced core functions: automated vulnerability scanning, professional report generation, and bounty tracking. - Outlined example commands for scanning, report generation, and project recommendations. - Provided clear scope for intended users: security researchers and white hats.
元数据
Slug bug-bounty
版本 1.0.3
许可证 MIT-0
累计安装 1
当前安装数 1
历史版本数 1
常见问题

Bug Bounty 是什么?

Bug Bounty 猎人 - 自动扫描漏洞、生成报告、追踪奖励。适合:安全研究员、白帽子。 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 314 次。

如何安装 Bug Bounty?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install bug-bounty」即可一键安装,无需额外配置。

Bug Bounty 是免费的吗?

是的,Bug Bounty 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Bug Bounty 支持哪些平台?

Bug Bounty 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Bug Bounty?

由 yang1002378395-cmyk(@yang1002378395-cmyk)开发并维护,当前版本 v1.0.3。

💬 留言讨论