Authorized targets only · VDP & bug bounty

Bug bounty recon & triage, reduced to one agent call.

HUNT LAB maps your target's attack surface, ranks likely vulnerability classes, and drafts structured findings. Every output lands in a human-verified report. Built for researchers who are tired of doing the boring 80% by hand.

01

Surface map

Subdomains, live hosts, open services, tech fingerprinting. Normalized into one inventory.

02

Class ranking

Signals ranked by likely impact: auth flows, upload paths, admin panels, forgotten endpoints.

03

Finding drafts

Every candidate output: evidence, reproduction path, severity hypothesis, written in report format.

04

Human sign-off

Nothing submits itself. The agent stops; you verify, then report. That's the contract.

One loop, structured output

Point HUNT LAB at a target you're authorized to test. It runs the recon pipeline and returns findings you can act on.

# give it a scope file, get back a triage report
$ huntlab run --scope program.txt --out ./findings

# findings/YYYY-MM-DD-host.example.com.md
## Finding: admin.example.com exposes /debug/vars
Severity: hypothesis: medium (info disclosure)
Evidence: HTTP 200, 14 metric lines, no auth
Next step: confirm token exposure in go runtime vars

Runs as an agent skill

HUNT LAB ships as a skills.sh package. Any compatible agent gets the full triage procedure in one install.

# install into your agent
$ npx skills add yourname/huntlab-recon
Claude CodeCodexCursor GooseOpenCode+ any skill.sh agent

Scope is the contract

HUNT LAB is built for authorized work: bug bounty programs, VDPs, your own infrastructure. It reads the program's scope file first and treats out-of-scope as a wall.

01Reads in-scope / out-of-scope from your program file before anything runs
02Hard-stops on out-of-scope hosts — recon never touches them
03Rate-limited, low-noise requests by default. No aggressive scanning
04Findings are drafts. A human reads, verifies, and owns every report

Get early access

Private beta. Bring a program you're authorized to hunt on.

# contact
$ echo "hello@huntlab.my.id" | mail