public-skills-builder: Mining the Collective Memory of Bug Hunters
How a specialized ETL pipeline transforms disclosed vulnerabilities into a high-signal Shadow-Brain for AI security agents.

Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed
- Public-skills-builder distills thousands of disclosed bug reports into procedural memory files for AI security agents.
- The ETL pipeline uses a keyword router and the Anthropic API to strip narrative fluff from writeups into structured bypass techniques.
- A mandatory Gate 0 validation checklist prevents AI agents from reporting theoretical or patched vulnerabilities.
- Injecting these distilled skill files into Claude Code replaces generic security prompts with specific human-derived methodologies.
The End of the Generic Security Prompt
Context bloat is the enemy of the agentic workflow. An AI given generic instructions to act as a penetration tester will inevitably hallucinate, relying on broad assumptions rather than specific, actionable exploit paths.
public-skills-builder approaches this problem differently. Instead of relying on a model's foundational training, it treats human intuition as a raw material. By mining thousands of disclosed HackerOne reports and GitHub writeups, it distills the insights of elite bug hunters into focused, procedural memory files.
From Raw Disclosure to Executable Logic
The architecture relies on a specialized Extract, Transform, Load (ETL) pipeline written in Python. It pulls unstructured JSON and Markdown from public feeds, bypassing the need for authenticated APIs or private data access.
A keyword-matching routing system categorizes the incoming flood of data into 18 distinct vulnerability classes. The Anthropic API is then invoked not as a creative writer, but as a rigid summarization filter. It strips away the narrative fluff of a bug bounty writeup, extracting only the payloads, grep patterns, and bypass techniques.
Gate 0: The Hallucination Firewall
The most critical feature of the generated skill files is a defensive prompt engineering tactic known as Gate 0. This is a validation checklist embedded into every output file.
Before the AI agent is allowed to report a vulnerability, Gate 0 forces a reality check. The agent must prove the exploit is currently viable, preventing the common failure mode where an LLM confidently reports a theoretical or patched vulnerability.
The New Security Stack
These generated Markdown files are designed to live directly in a developer's local environment. By copying them into a specific directory, the user injects a persistent security methodology directly into Claude Code.

Bug bounty reports are the best training data for hunting. This tool reads hundreds of disclosed HackerOne reports and community writeups, then uses Claude to distill them into structured skill files you can load directly into Claude Code.
| Approach | Strengths | Weaknesses |
|---|---|---|
| Legacy Scanners (e.g., Nuclei) | Fast, deterministic execution. | Misses complex business logic and novel bypasses. |
| Generic LLMs | Creative and conversational. | Prone to hallucinations, lacks specific methodology. |
| Skill-Augmented Agents | Context-aware, grounded in real bypasses. | Requires initial generation and setup. |
This shifts the paradigm from using static, rules-based scanners to employing an augmented intelligence setup. The AI becomes a specialist, executing a highly specific methodology derived from actual, successful exploits.