以前拿 Claude Code 做安全研究,很多时候还是得自己一步步引导。
This is a dev post classified by Jev as Security (a tool drop), kept by the Dev Radar because it carries real work, not commentary.
以前拿 Claude Code 做安全研究,很多时候还是得自己一步步引导。 Claude-BugHunter 则是专门给它补了一套漏洞研究能力的 Skill。 目前包含 83 项安全技能,覆盖 Web 应用、API、企业网络等多个场景,还整理了 681 个 HackerOne 公开案例,把常见漏洞类型和测试思路做成了可调用的知识模块。 用自然语言描述你正在测试的目标,它会根据场景加载对应技能,不用自己记一堆复杂流程。 而且项目强调了授权范围和安全边界,更适合用于合法的安全测试、漏洞研究和学习。 🔗 https://github.com/elementalsouls/Claude-BugHunter
Posted by lumxss (24.8k followers) 1 h ago · 0 likes · 156 views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: claude-bughunter.
More dev work like this
- Applications today can pull thousands of third-party packages, and AI agents are… — @depthfirstlabs
- Useful tool for cybersecurity researchers and red teamers. — @0x0SojalSec
- A malicious npm package was published with **completely valid provenance**. — @shehackspurple
- Grok @bot has a @1Password integration! You ask it to connect to your account, it… — @altryne
- Embedding a Gemini API key in client-side code can expose it to anyone using your app. — @freeCodeCamp
- With a $150K maximum reward, the stakes just got higher on CertiK Hunt. 🎯 — @CertiK
- Africans can build. what! — @Dominus_Kelvin
- 🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected… — @DarkWebInformer
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 23k posts from 5k X accounts over the last 21 days, 2.7k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-24 00:15 UTC. Full method.