Agentic Bug Hunter is an open-source AI bug bounty toolkit from AwareXone. Point it at an authorized target and it runs recon, hunts for vulnerabilities, validates findings, and drafts a submission-ready report. It works as a standalone CLI (bughunter) or as skills and commands inside agent harnesses such as Claude Code, OpenCode, Pi, and Codex. An MCP server exposes the same research engine to AI agents.

What it does

  1. Recon — map subdomains, live hosts, URLs, and attack surface
  2. Hunt — test vulnerability classes against in-scope assets
  3. Validate — run the 7-Question Gate before you write a report
  4. Report — draft platform-ready write-ups (HackerOne, Bugcrowd, Intigriti, Immunefi)
  5. Memory — keep patterns and session context for the next hunt
MCP is an adapter over that engine — not a second scanner. Active tools require scope and explicit approval.

Ways to run it

Authorized testing only

Only test systems you have written permission to assess. Read the program policy and scope before any active request. Reports are never auto-submitted.