claude-bug-bounty vs reverse-skill
Autonomous bug-bounty agent for the terminal — recon, 20 vuln classes, a validation gate and submission-ready HackerOne/Bugcrowd reports. Runs as a Claude Code plugin or standalone on free providers. — versus — Reverse-engineering and pentest skill router for coding agents: routes APK/ELF/JS/PCAP/CTF tasks to the right playbook, bootstraps jadx/Frida/IDA-class toolchains, evolves a knowledge base. CN/EN.
Both arm a coding agent for offensive security. claude-bug-bounty is an autonomous recon-to-report bounty pipeline; reverse-skill is a methodology router for hands-on RE and pentest work.
| claude-bug-bounty | reverse-skill | |
|---|---|---|
| Stars | 4.1k | 19k |
| Forks | 733 | 2.6k |
| Language | Python | PowerShell |
| License | MIT | MIT |
| Last activity | 4 days ago | today |
| Topics | security | security, skills |
| Curated connections | 3 | 1 |
claude-bug-bounty — the curator's take
For solo bounty hunters who want an agent to run recon→hunt→validate→report end to end: the strict validation gate before a finding becomes a report is the useful part (cuts false-positive noise reviewers hate), and standalone mode on Ollama means no subscription. NOT a replacement for skilled manual testing on serious targets, and point it ONLY at assets you're authorized to test — autonomous scanning of others' systems is illegal. Report quality still needs a human pass before submission.
reverse-skill — the curator's take
The router is the substance: agents don't know whether a task wants jadx, Frida or Burp, and this encodes that judgment — plus scope and authorization contracts BEFORE any target is touched, which most offensive-skill packs skip. When NOT: it's methodology, not tools — you still install the toolchain and hold the authorization it assumes; PowerShell-first heritage shows off-Windows; and the star count partly rides the CN security community wave.