{"id":"43ad7720-c267-406e-9245-aed0ecc746f1","slug":"shaniidev-bug-reaper","name":"bug-reaper","description":"Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open redirect, API/GraphQL bugs; auditing locally downloaded GitHub repos or source code (white-box/source code review); writing platform-specific reports. Trigger on: 'pentest', 'find bugs', 'security audit', 'bug bounty', 'find vulnerabilities', 'source code review', 'audit this repo', 'review repo', 'white-box', 'local repo', vulnerability class names, or program/target names. Reports only real, confirmed medium+ severity bugs that pass real triage.","canonicalUrl":"https://www.xpersona.co/agent/shaniidev-bug-reaper","sourceUrl":"https://github.com/shaniidev/bug-reaper","homepage":null,"source":"GITHUB_OPENCLEW","vendor":{"slug":"shaniidev","label":"Shaniidev","url":"https://github.com/shaniidev/bug-reaper"},"protocols":["OPENCLEW"],"capabilities":[],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":null,"freshnessAt":"2026-04-15T01:12:40.584Z","freshnessLabel":"Apr 15, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Apr 15, 2026"},{"label":"Vendor","value":"Shaniidev"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"Unpublished"}],"factsPreview":[{"factKey":"vendor","label":"Vendor","value":"Shaniidev","category":"vendor","href":"https://github.com/shaniidev/bug-reaper","sourceUrl":"https://github.com/shaniidev/bug-reaper","sourceType":"profile","confidence":"medium","observedAt":"2026-04-15T05:21:22.124Z","isPublic":true,"metadata":{}},{"factKey":"protocols","label":"Protocol compatibility","value":"OpenClaw","category":"compatibility","href":"https://www.xpersona.co/api/v1/agents/shaniidev-bug-reaper/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/shaniidev-bug-reaper/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-04-15T05:21:22.124Z","isPublic":true,"metadata":{}},{"factKey":"traction","label":"Adoption signal","value":"33 GitHub stars","category":"adoption","href":"https://github.com/shaniidev/bug-reaper","sourceUrl":"https://github.com/shaniidev/bug-reaper","sourceType":"profile","confidence":"medium","observedAt":"2026-04-15T05:21:22.124Z","isPublic":true,"metadata":{}},{"factKey":"docs_crawl","label":"Crawlable docs","value":"6 indexed pages on the official domain","category":"integration","href":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceUrl":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceType":"search_document","confidence":"medium","observedAt":"2026-04-15T05:03:46.393Z","isPublic":true,"metadata":{}},{"factKey":"handshake_status","label":"Handshake status","value":"UNKNOWN","category":"security","href":"https://www.xpersona.co/api/v1/agents/shaniidev-bug-reaper/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/shaniidev-bug-reaper/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true,"metadata":{}}],"highlights":["33 GitHub stars","Trust evidence available"],"agentCard":{"name":"bug-reaper","description":"Web2 bug bounty hunting agent — evidence-based vulnerability finder and report writer. Use when: auditing web apps/APIs for HackerOne, Bugcrowd, Intigriti, YesWeHack; hunting XSS, SQLi, NoSQLi, SSRF, IDOR, auth bypass, RCE, SSTI, LFI, XXE, CORS, CSRF, prototype pollution, subdomain takeover, HTTP smuggling, open redirect, API/GraphQL bugs; auditing locally downloaded GitHub repos or source code (white-box/source code review); writing platform-specific reports. Trigger on: 'pentest', 'find bugs', 'security audit', 'bug bounty', 'find vulnerabilities', 'source code review', 'audit this repo', 'review repo', 'white-box', 'local repo', vulnerability class names, or program/target names. Reports only real, confirmed medium+ severity bugs that pass real triage.","source":"GITHUB_OPENCLEW","sourceId":"github:1163342243","repository":"https://github.com/shaniidev/bug-reaper","documentation":"https://www.xpersona.co/agent/shaniidev-bug-reaper","protocols":["OPENCLEW"],"languages":["typescript"],"install":{"command":"git clone https://github.com/shaniidev/bug-reaper.git","ecosystem":"git"},"examples":[{"kind":"example","language":"text","snippet":"python scripts/generate_report.py --platform <platform> --vuln-type <type> --input findings.json"},{"kind":"example","language":"text","snippet":"Title:\nSeverity: [Critical/High/Medium/Low]\nConfidence: [Confirmed / Probable / Theoretical]\nAttack Prerequisites: [none / low-priv auth / admin access / ...]\nVulnerable Endpoint: [METHOD /path/to/endpoint]\nAttack Path: [step-by-step]\nWhy This Is Exploitable: [specific technical reason defenses are bypassed]\nRealistic Impact: [what attacker concretely achieves]\nPoC Request: [raw HTTP or payload]\nSuggested Verification: [if Theoretical — exact command/request for user to run]\nRecommended Fix:"}]}}