Bb Methodology
Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master…
- Type
- Skill
- Repository
- awarexone/Agentic-Bug-Hunter
- GitHub stars
- 5.2k
- License
- MIT
- Repo last updated
- Sep 24, 2026
- Source file
- README.md
What Bb Methodology is
Bb Methodology is a skill published in the awarexone/Agentic-Bug-Hunter repository on GitHub, which has about 5.2k stars. The repository describes itself as: “AI-powered bug bounty hunting toolkit that works with or without subscription.”
A skill is a folder with a SKILL.md file: frontmatter with a name and a description, followed by instructions Claude follows. Claude loads a skill automatically when a task matches its description, and you can also run it directly with a slash and its name.
Skills work in Claude Code and in Claude Cowork, which makes Bb Methodology a portable way to give Claude the same method everywhere.
How to install Bb Methodology
Claude Code
- Download the bb-methodology folder from the repository.
- Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project.
- Claude loads it automatically when a task matches; you can also run it with / and its name.
Claude Cowork
- Zip the skill folder so SKILL.md sits at the top level of the folder.
- Open Customize → Skills, click +, then upload the ZIP.
- Start a task that matches the description, or call it by name with /.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from README.md, shared under the repository's MIT license. Read the full file on GitHub.
AI-powered bug bounty hunting — recon to report, in your terminal. What Is This · Trusted By · Free Setup · Quick Start · Commands · What It Finds · AXguard · Support · FAQ
Built and maintained by AwareXone · Website · X · GitHub
One gateway to the world's leading AI models AI model access & operations · partner for BugHunter standalone mode
Register with partner link → · promo AWAREXONE · Docs · Model Plaza
Get started (30 seconds)
uv tool install agentic-bug-hunter # install the CLI (or: pipx install agentic-bug-hunter)
bughunter setup # connect a free AI providerThen hunt — straight from your terminal:
bughunter hunt target.com # recon → find → validate → report…or drive it from inside Claude Code:
/hunt target.comThe CLI and AI hunting work on their own. Full recon also uses external tools (subfinder · httpx · nuclei · katana · ffuf · nmap) — install them with install_tools.sh from the repo. Output lands in ~/.bughunter/ .
Trusted By Engineers At
Where this project's stargazers say they work.
Compiled from public GitHub profiles of this repository's stargazers - 43 people across 30 organizations, counted from the employer each person lists on their own profile or from their public organization memberships. No individual accounts are named. These companies have not endorsed or sponsored this project; their logos are shown as trademarks of their respective owners.
What Is This?
Agentic Bug Hunter finds real, reportable bugs, not theoretical ones. Point it at a target and it runs recon, tests for vulnerabilities, validates findings against a strict gate, and writes a submission-ready report for HackerOne, Bugcrowd, Intigriti, or Immunefi.
It remembers everything: patterns found on one target inform the next, and sessions pick up where they left off.
Works as a Claude Code plugin, or as a fully standalone CLI (bughunter) with no subscription required.
Standalone Mode: No Subscription Required
You no longer need Claude Code, Claude Pro, or any paid AI subscription.
Install once, use the bughunter command from any terminal on your machine:
git clone https://github.com/Awarexone/Agentic-Bug-Hunter.git
cd Agentic-Bug-Hunter
./install.sh --agent standaloneRerun the same command after pulling updates. The installer detects and refreshes the active managed bughunter command, including older installations under /usr/local/bin or ~/.local/bin, while preserving your saved provider configuration in ~/.bughunter/config.json.
To uninstall the standalone command while keeping its configuration:
./uninstall.sh --agent standaloneUse --purge-config to also delete ~/.bughunter/config.json. The uninstaller also supports claude, opencode, pi, codex, agents, and all targets.
bughunter help # show every command
bughunter setup # choose your AI provider (Ollama is free + offline)
bughunter recon target.com # map the attack surface
bughunter hunt target.com # hunt for vulnerabilities
bughunter validate "finding" # 7-Question Gate on your finding
bughunter report # write a submission-ready report
bughunter chat # interactive AI hunting shell
bughunter providers # list all available AI providers
bughunter models # list models and show the selected one
bughunter status # check which provider is active
bughunter h target.com # short alias for hunt
bughunter r target.com # short alias for recon
bughunter v "finding" # short alias for validateFree AI Providers (auto-detected, free-first priority)
BugHunter auto-detects providers in this order: Ollama → Groq → DeepSeek → … → OrcaRouter → OpenRouter → Fluxion → Claude → OpenAI. LiteLLM is opt-in (selected explicitly or when LITELLM_API_KEY is set) so it never preempts a provider you already configured.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Bb Methodology?
Bb Methodology is a skill for Claude Code and Claude Cowork from the awarexone/Agentic-Bug-Hunter repository on GitHub. Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master…
How do I install Bb Methodology in Claude Code?
Download the bb-methodology folder from the repository. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project. Claude loads it automatically when a task matches; you can also run it with / and its name.
Can I use Bb Methodology in Claude Cowork?
Zip the skill folder so SKILL.md sits at the top level of the folder. Open Customize → Skills, click +, then upload the ZIP. Start a task that matches the description, or call it by name with /.
Is Bb Methodology safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Mcp Config Configure MCP (Model Context Protocol) servers for Claude Code. Manage MCP servers at user or project scope with best practices to avoid… Skill · libukai/awesome-agent-skills
- Analyzing Dotnet Performance Scans .NET code for ~50 performance anti-patterns across async, memory, strings, collections, LINQ, regex, serialization, and I/O with… Skill · dotnet/skills
- Swiftui Pro Comprehensively reviews SwiftUI code for best practices on modern APIs, maintainability, and performance. Use when reading, writing, or… Skill · twostraws/SwiftUI-Agent-Skill
- Text To Lottie Create, edit, or fix Lottie/Bodymovin JSON animations for the local Skia Skottie player. Use for text-to-Lottie, SVG/logo/type animation… Skill · diffusionstudio/lottie
- Remotion Best Practices Best practices for Remotion - Video creation in React Skill · remotion-dev/skills
- Antfu Anthony Fu's opinionated tooling and conventions for JavaScript/TypeScript projects. Use when setting up new projects, configuring… Skill · antfu/skills
- Quickdesign Use the `quickdesign` CLI to generate AI media — UGC promo videos, image edits, product creatives, video upscales — through Seedance, Kling, Sora2, Nano Banana, and GPT Image. Invoke this skill whenever the user asks for a talking-avatar video, multi-segment ad / promo / explainer, image edit (object swap, angle change, state change), product photoshoot, or video upscale via QuickDesign. Skill · anthropics/claude-plugins-community
- Dev Browser Browser automation with persistent named pages via the dev-browser CLI. Use when users ask to navigate websites, fill forms, take screenshots, extract web data, test web apps, log into sites, or automate browser workflows. Trigger phrases include "go to [url]", "click on", "fill out the form", "take a screenshot", "scrape", "automate", "test the website", "log into", "open the browser", or any… Skill · SawyerHood/dev-browser