public-skills-builder: Mining the Collective Memory of Bug Hunters

How a specialized ETL pipeline transforms disclosed vulnerabilities into a high-signal Shadow-Brain for AI security agents.

shuvonsec/public-skills-builder

A massive pile of disorganized scrolls being fed into a sleek brass funnel, outputting a single glowing gemstone.
Transforming unstructured vulnerability reports into high-signal skill files.

Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed

shuvonsec, Project Creator · shuvonsec/public-skills-builder

Key Takeaways

The End of the Generic Security Prompt

Context bloat is the enemy of the agentic workflow. An AI given generic instructions to act as a penetration tester will inevitably hallucinate, relying on broad assumptions rather than specific, actionable exploit paths.

public-skills-builder approaches this problem differently. Instead of relying on a model's foundational training, it treats human intuition as a raw material. By mining thousands of disclosed HackerOne reports and GitHub writeups, it distills the insights of elite bug hunters into focused, procedural memory files.

Portrait of shuvonsec

From Raw Disclosure to Executable Logic

The architecture relies on a specialized Extract, Transform, Load (ETL) pipeline written in Python. It pulls unstructured JSON and Markdown from public feeds, bypassing the need for authenticated APIs or private data access.

A keyword-matching routing system categorizes the incoming flood of data into 18 distinct vulnerability classes. The Anthropic API is then invoked not as a creative writer, but as a rigid summarization filter. It strips away the narrative fluff of a bug bounty writeup, extracting only the payloads, grep patterns, and bypass techniques.

Gate 0: The Hallucination Firewall

The most critical feature of the generated skill files is a defensive prompt engineering tactic known as Gate 0. This is a validation checklist embedded into every output file.

Before the AI agent is allowed to report a vulnerability, Gate 0 forces a reality check. The agent must prove the exploit is currently viable, preventing the common failure mode where an LLM confidently reports a theoretical or patched vulnerability.

A heavy iron gate with a zero engraved on the lock. A human hand holds the latch shut against a robotic hand, pointing to a checklist.
Gate 0 forces the AI to validate its findings against reality before reporting.

The New Security Stack

These generated Markdown files are designed to live directly in a developer's local environment. By copying them into a specific directory, the user injects a persistent security methodology directly into Claude Code.

Bug bounty reports are the best training data for hunting. This tool reads hundreds of disclosed HackerOne reports and community writeups, then uses Claude to distill them into structured skill files you can load directly into Claude Code.

shuvonsec, Project Creator · shuvonsec/public-skills-builder
ApproachStrengthsWeaknesses
Legacy Scanners (e.g., Nuclei)Fast, deterministic execution.Misses complex business logic and novel bypasses.
Generic LLMsCreative and conversational.Prone to hallucinations, lacks specific methodology.
Skill-Augmented AgentsContext-aware, grounded in real bypasses.Requires initial generation and setup.

This shifts the paradigm from using static, rules-based scanners to employing an augmented intelligence setup. The AI becomes a specialist, executing a highly specific methodology derived from actual, successful exploits.