hunt-toolkit turns Claude Code into a reasoning-first bug-bounty partner. It ships a set of skills, subagents, and slash commands that make Claude hunt novel bugs in any authorized open-source codebase or live web / mobile / network target the way a senior researcher does understand deeply, recon prior-art, model the trust boundaries, then attack the load-bearing assumptions.
A bug is the gap between what the developer assumed and what the system enforces.
It is not a scanner. Nothing here fires payloads blindly it is a way of thinking about a target, encoded as skills Claude follows.
Authorized testing only. Every workflow assumes you have written permission to test the target (a bug-bounty program, a VDP, your own code, or a signed engagement). The skills refuse a target with no authorized scope. Staying in scope and within the law is on you.