# bug-reaper

> Use this tool when you need to identify and document web application vulnerabilities, as it provides evidence-based bug bounty hunting and automatic report writing capabilities, accepting website URLs as input and generating comprehensive vulnerability reports as output, ideal for security researchers and testers. It solves problems related to manual vulnerability discovery and reporting, streamlining the bug bounty hunting process. Effective in contexts where web application security testing is required.

Canonical page: https://skillsregistry.net/skills/shaniidev-bug-reaper  
JSON: https://api.skillsregistry.net/v1/skills/shaniidev-bug-reaper

## Description

Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer.

## Trust

- **Trust score (0–1):** 0.30
- **Verification tier:** unverified
- **Last scanned:** 2026-08-23

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** instructions
- **Runtime environment:** llm
- **Category:** security
- **Updated:** 2026-08-23

## Source

- **Source listing:** [ClawHub](https://clawskills.sh/skills/shaniidev-bug-reaper)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "shaniidev-bug-reaper"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/shaniidev-bug-reaper` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/shaniidev-bug-reaper/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
