HUNT LAB maps your target's attack surface, ranks likely vulnerability classes, and drafts structured findings. Every output lands in a human-verified report. Built for researchers who are tired of doing the boring 80% by hand.
Subdomains, live hosts, open services, tech fingerprinting. Normalized into one inventory.
Signals ranked by likely impact: auth flows, upload paths, admin panels, forgotten endpoints.
Every candidate output: evidence, reproduction path, severity hypothesis, written in report format.
Nothing submits itself. The agent stops; you verify, then report. That's the contract.
Point HUNT LAB at a target you're authorized to test. It runs the recon pipeline and returns findings you can act on.
# give it a scope file, get back a triage report $ huntlab run --scope program.txt --out ./findings # findings/YYYY-MM-DD-host.example.com.md ## Finding: admin.example.com exposes /debug/vars Severity: hypothesis: medium (info disclosure) Evidence: HTTP 200, 14 metric lines, no auth Next step: confirm token exposure in go runtime vars
HUNT LAB ships as a skills.sh package. Any compatible agent gets the full triage procedure in one install.
# install into your agent $ npx skills add yourname/huntlab-recon
HUNT LAB is built for authorized work: bug bounty programs, VDPs, your own infrastructure. It reads the program's scope file first and treats out-of-scope as a wall.
| 01 | Reads in-scope / out-of-scope from your program file before anything runs |
| 02 | Hard-stops on out-of-scope hosts — recon never touches them |
| 03 | Rate-limited, low-noise requests by default. No aggressive scanning |
| 04 | Findings are drafts. A human reads, verifies, and owns every report |
Private beta. Bring a program you're authorized to hunt on.
# contact $ echo "hello@huntlab.my.id" | mail