Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计提醒

hackeronehackerone 搜索

Agent Skill

hackerone 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

1,091

周安装

45

GitHub Stars

222

下载量

356
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:hackerone(hackerone 搜索)
来源仓库:https://github.com/transilienceai/communitytools
仓库路径:skills/hackerone
安装命令:
npx skills add https://github.com/transilienceai/communitytools --skill hackerone
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/transilienceai/communitytools --skill hackerone

简介

用于查找、检索和筛选相关信息,支持关键词匹配与线索定位。

  • 适合在需要快速获取候选结果时使用,覆盖 HackerOne 安全漏洞场景。
  • 安装方式:通过 GitHub 仓库安装,命令为 npx skills add https://github.com/transilienceai/communitytools --skill hackerone。
  • 使用前请确认权限范围和维护状态,避免触发不必要的联网或文件操作。
  • 注意:搜索结果需人工复核,确保来源可靠且符合实际业务需求。

SKILL.md

HackerOne Bug Bounty Hunting

Automates HackerOne workflows: scope parsing → parallel testing → PoC validation → submission reports.

Quick Start

1. Input: HackerOne program URL or CSV file
2. Parse scope and program guidelines
3. Deploy Pentester agents in parallel (one per asset)
4. Validate PoCs (poc.py + poc_output.txt required)
5. Generate HackerOne-formatted reports

Workflows

Option 1: HackerOne URL

- [ ] Fetch program data and guidelines
- [ ] Download scope CSV
- [ ] Parse eligible assets
- [ ] Deploy agents in parallel
- [ ] Validate PoCs
- [ ] Generate submissions

Option 2: CSV File

- [ ] Parse CSV scope file
- [ ] Extract eligible_for_submission=true assets
- [ ] Collect program guidelines
- [ ] Deploy agents
- [ ] Validate and generate reports

Scope CSV Format

Expected columns:

  • identifier - Asset URL/domain
  • asset_type - URL, WILDCARD, API, CIDR
  • eligible_for_submission - Must be "true"
  • max_severity - critical, high, medium, low
  • instruction - Asset-specific notes

Use tools/csv_parser.py to parse.

Agent Deployment

Coordinator per asset — spawned inline using role prompts:

coordinator_role = Read("skills/coordination/SKILL.md")
Agent(prompt=f"{coordinator_role}\n\nTARGET: {asset_url}\nSCOPE: {program_guidelines}\nOUTPUT_DIR: ...",
      run_in_background=True)

Parallel Execution:

  • 10 assets = 10 coordinator agents in parallel
  • Each spawns executor agents from skills/coordination/reference/executor-role.md
  • Time: 2-4 hours vs 20-40 sequential

PoC Validation (CRITICAL)

Every finding MUST have:

  1. poc.py - Executable exploit script
  2. poc_output.txt - Timestamped execution proof
  3. workflow.md - Manual steps (if applicable)
  4. Evidence screenshots/videos

Experimentation: Test edge cases, verify impact, document failures.

Report Format

Required sections (HackerOne standard):

  1. Summary (2-3 sentences)
  2. Severity (CVSS + business impact)
  3. Steps to Reproduce (numbered, clear)
  4. Visual Evidence (screenshots/video)
  5. Impact (realistic attack scenario)
  6. Remediation (actionable fixes)

Use tools/report_validator.py to validate.

Output Structure

Per OUTPUT.md - Bug Bounty format:

{OUTPUT_DIR}/
├── findings/
│   ├── finding-001/
│   │   ├── report.md           # HackerOne report
│   │   ├── poc.py              # Validated PoC
│   │   ├── poc_output.txt      # Proof
│   │   └── workflow.md         # Manual steps
├── reports/
│   ├── submissions/
│   │   ├── H1_CRITICAL_001.md  # Ready to submit
│   │   └── H1_HIGH_001.md
│   └── SUBMISSION_GUIDE.md
└── evidence/
    ├── screenshots/
    └── http-logs/

Program Selection

High-Value:

  • New programs (< 30 days)
  • Fast response (< 24 hours)
  • High bounties (Critical: $5,000+)
  • Large attack surface

Avoid:

  • Slow response (> 1 week)
  • Low bounties (Critical: < $500)
  • Overly restrictive scope

Critical Rules

MUST DO:

  • Validate ALL PoCs before reporting
  • Sanitize sensitive data
  • Test only eligible_for_submission=true assets
  • Follow program-specific guidelines
  • Generate CVSS scores

NEVER:

  • Report without validated PoC
  • Test out-of-scope assets
  • Include real user data
  • Cause service disruption

Quality Checklist

Before submission:

  • Working PoC with poc_output.txt
  • Accurate CVSS score
  • Step-by-step reproduction
  • Visual evidence
  • Impact analysis
  • Remediation guidance
  • Sensitive data sanitized

Tools

  • tools/csv_parser.py - Parse HackerOne scope CSVs
  • tools/report_validator.py - Validate report completeness
  • skills/coordination/SKILL.md — Coordinator skill (spawns executors/validators)

Integration

Uses skills/coordination/SKILL.md for coordination workflow. Follows OUTPUT.md for submission format.

Common Rejections

Out of Scope: Check eligible_for_submission=true Cannot Reproduce: Validate PoC, include poc_output.txt Duplicate: Search disclosed reports, submit quickly Insufficient Impact: Show realistic attack scenario

Usage

/hackerone <program_url_or_csv_path>

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.31%
按下载量换算126

Claude

28.2%
按下载量换算100

Cursor

17.06%
按下载量换算61

Gemini CLI

10.04%
按下载量换算36

安全审计

Gen Agent Trust Hub

可疑

Socket

通过

Snyk

可疑

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills