@accounta/dsh-bounty-hunt
v0.1.0
Published
DeepSeek Harness plugin for bug bounty hunting automation
Maintainers
Readme
DSH Bounty Hunt Plugin
DeepSeek Harness plugin for automated bug bounty hunting workflows.
Features
- Target Management: Add, track, and scope targets across multiple bounty programs
- Finding Tracking: Log, verify, and organize security findings
- IDOR Testing: Dedicated tools for testing insecure direct object reference vulnerabilities
- Report Generation: Automatic markdown/JSON/HTML report generation
- Agent Presets: Pre-configured agents for reconnaissance, exploitation, and reporting
Installation
Quick Install (Recommended)
cd ~/bounty-lab/dsh-bounty-hunt
./install.shThis automatically registers the plugin in your DSH Web profile.
Manual Install
- Get the absolute path:
echo ~/bounty-lab/dsh-bounty-hunt
# Output: /home/edslawn/bounty-lab/dsh-bounty-hunt (or your actual path)- Edit
~/.dsh/profiles/web/cordis.patch.yml:
patch:
- insert:
- id: bounty-hunt-plugin
name: /home/edslawn/bounty-lab/dsh-bounty-hunt/src/index.ts
config:
enabled: true- Start DSH:
dsh webVerify Installation
dsh bounty/list-targets
# Should return: { ok: true, targets: [] }Usage
Add a Target
dsh bounty/add-target \
--name "Acme Inc" \
--domain "acme.com" \
--program "HackerOne" \
--scope '["*.acme.com","api.acme.com"]' \
--outOfScope '["test.acme.com"]'Test IDOR Vulnerability
dsh bounty/test-idor \
--endpoint "https://api.target.com/submissions/\{id\}" \
--idParam "id" \
--authHeader "Bearer YOUR_TOKEN" \
--testIds '["submission_1","submission_2","submission_3"]'Log a Finding
dsh bounty/add-finding \
--targetName "Acme Inc" \
--severity "critical" \
--title "SQL Injection in Login Form" \
--description "The username field is vulnerable to SQL injection" \
--endpoint "https://acme.com/login" \
--proof "' OR '1'='1"Generate Report
dsh bounty/generate-report \
--targetName "Acme Inc" \
--format "markdown"Agent Presets
Recon Agent
Specialized for target enumeration and attack surface discovery:
dsh --preset recon-agentCapabilities:
- Add and manage targets
- Verify scope compliance
- List active targets
Exploit Agent
Specialized for vulnerability discovery and testing:
dsh --preset exploit-agentCapabilities:
- Test IDOR vulnerabilities
- Log findings with proof
- Verify reproducibility
Reporting Agent
Specialized for documentation and submission:
dsh --preset reporting-agentCapabilities:
- List findings by severity
- Generate formatted reports
- Manage submission status
Workflow Example
1. Start with Recon
dsh --preset recon-agent
# Claude> Add target Acme Inc...
# Claude> Verify scope for api.acme.com...2. Switch to Exploitation
dsh --preset exploit-agent
# Claude> Test IDOR on /api/submissions/{id}...
# Claude> Log critical finding...3. Generate Report
dsh --preset reporting-agent
# Claude> Generate markdown report for Acme Inc...
# Claude> Summarize findings by severity...Integration with Bounty-Lab
The plugin integrates with your existing bounty-lab infrastructure:
~/bounty-lab/
├── dsh-bounty-hunt/ # This plugin
├── methodology/ # Your existing methodology docs
├── targets/ # Your target research
└── nuclei-templates/ # Your custom templatesFuture enhancements can bridge:
- Nuclei template execution
- Existing exploit PoCs
- Historical finding data
- Methodologies and playbooks
Architecture
The plugin uses Cordis' service model:
interface BountyHuntService {
targets: BountyTarget[]
findings: Finding[]
addTarget(target: BountyTarget): void
addFinding(finding: Finding): void
verifyFinding(id: string): void
}All state is maintained in memory during the session. For persistence, hook into ctx.storage to save findings to SQLite.
Extending the Plugin
Add a Custom Tool
ctx.tools.define('bounty/my-custom-scan', {
description: 'My custom vulnerability scanner',
parameters: { /* ... */ },
}, async (args) => {
// Implementation
return { ok: true, result: 'data' }
})Add an Agent Preset
Edit dsh-bundle.yml and add to preset-agents:
preset-agents:
my-agent:
description: Custom hunting agent
tools: [bounty/...]
systemPrompt: >
Custom instruction...Known Limitations
- Current IDOR testing is a framework; actual HTTP testing requires integration with curl/fetch
- Findings stored in memory only (not persisted between sessions)
- No platform API integration yet (HackerOne, Intigriti, Bugcrowd)
Roadmap
- [ ] HTTP client integration (real IDOR testing)
- [ ] SQLite persistence for findings
- [ ] Platform API connectors
- [ ] Nuclei integration
- [ ] Multi-target orchestration
- [ ] Automated verification checks
- [ ] Slack/Discord reporting
Contributing
Open an issue or PR to improve the plugin!
