Summary
- Adds first-class Deepseek Pro setup and temporary project binding support.
- Adds a standalone local tooling reference so agents can use local CLI scanners and fuzzers.
- Expands web/API attack coverage (CSV injection, open redirect, path traversal, parameter pollution, HTTP response splitting).
- Integrates local-tooling references into agent bundles so agents can act on environment info instead of README-only guidance.
- Updates
SKILL.md banner to display "bountyforge".
- Cleans and clarifies
README.md including an "Enabling Claude Code Execution" section.
- Misc: tidy up attack vector docs and agent instructions.
Highlights
- New files:
references/setup.md — Deepseek CLI env and export usage
references/local-tooling.md — standalone local tooling + vuln coverage guide
- Key updates:
SKILL.md — banner changed to bountyforge; bundles now include setup.md and local-tooling.md
README.md — Deepseek Pro environment examples (macOS/Linux + PowerShell), instructions for enabling Claude Code execution
references/attack-vectors/web-api-vectors.md — added CSV injection, open redirect, path traversal, parameter pollution
references/hacking-agents/web-api-agent.md — local tool integration instructions and expanded tests
references/hacking-agents/shared-rules.md — canonical bug classes extended
Changelog
- Added: Deepseek Pro environment variables and
deepseek export usage for temporary project binding.
- Added:
references/local-tooling.md and integrated into agent bundle creation.
- Updated: Web/API vectors and agent rules to cover more payload classes and local-tool usage.
- Updated: README with clear steps to enable Claude Code execution and improved structure.
- Fixed: Duplicate/stray sections and cleaned repo structure listing.
Upgrade / Usage Notes
- If you run Claude locally, start it from the shell that has your project env vars loaded (see
references/setup.md).
- To use Deepseek Pro temporarily in a repo:
export ANTHROPIC_AUTH_TOKEN="your-deepseek-pro-token"
deepseek export --project . --key "$ANTHROPIC_AUTH_TOKEN" --mode pro
- Ensure local tools are installed and on
PATH if you expect agent-driven scans (e.g., nmap, ffuf, sqlmap, gobuster, curl, httpx, wfuzz, zap, burpsuite).
Breaking changes
- None expected. Agents now include additional reference files in their bundles; no API changes.
Contributors
- @Gabson0x and contributors updates, docs, and orchestration improvements.