An AI web-application penetration-testing specialist for authorized bug-bounty and pentest work.
Built as a Claude Code subagent (pentest-web) plus a compounding library of methodology, scope-authorization,
and reporting assets. Orchestrator + advisor: you run the tools, the agent plans, interprets, and reports.
For good only. Every target-specific test is gated behind a written authorization scope. See the agent's
authorization rules and SCOPE.template.md.
pentest-agent/
├── .claude/agents/pentest-web.md — the agent (canonical source; also installed to ~/.claude/agents/)
├── SCOPE.template.md — per-engagement authorization record (the guardrail)
├── methodology/
│ ├── web-app-methodology.md — the recon → test → report playbook (your IP)
│ ├── payloads.md — detection/PoC probe reference (confirmation-first, no weaponization)
│ └── checklists/ — per-vuln-class checklists (index + 7 classes)
├── templates/
│ ├── finding-report.md — professional bug-bounty finding format
│ └── engagement-log.md — per-engagement audit trail (what/where/when/result)
└── engagements/ — one folder per program/target (gitignored; holds real scope, log, findings)
- Start an engagement:
cp SCOPE.template.md engagements/<program>/SCOPE.mdand fill it in from the program policy — in-scope assets, excluded vuln types, rate limits, required identifier header. Then open the audit trail:cp templates/engagement-log.md engagements/<program>/log.md(the agent appends to it as it works). - Invoke the agent (from anywhere, since it's installed globally):
"Use the pentest-web agent. Here's the scope: <paste or point at engagements/acme/SCOPE.md>. Let's start recon on the in-scope assets."
- You run the commands it gives you (subfinder, httpx, katana, nuclei, Burp, ffuf, …) and paste results back.
- The agent interprets, forms hypotheses, hands you the next probes, and writes findings with the template.
- No target-specific attack steps without an authorized scope. Permission is a document, not a claim.
- Hard-refuses: DoS/stress, social engineering, out-of-scope assets, real-user-data exfiltration, persistence/lateral-movement/destructive actions on targets you don't own.
- The agent has no
Bashand no scanning tools — it cannot send traffic. That's intentional: it advises, you execute. It keeps you fast and inside the lines.
- Now: advisor subagent + methodology/report library (this).
- Next: an
engagements/workflow, checklists per vuln class, a payload/wordlist reference. - Later (opt-in): a standalone Claude Agent SDK app that can run read-only recon tooling against in-scope targets under hard scope-gating — the productizable core. Nothing here is thrown away when you get there.
Only test what you're authorized to test. Bug-bounty authorization = the published program scope; pentest authorization = a signed rules-of-engagement. This tooling assumes and enforces that; it does not grant it.