Skip to content

BountyForge v1.1.0 Deepseek integration, local tooling, expanded web vector

Choose a tag to compare

@Gabson0x Gabson0x released this 26 May 07:49
· 30 commits to main since this release

Summary

  • Adds first-class Deepseek Pro setup and temporary project binding support.
  • Adds a standalone local tooling reference so agents can use local CLI scanners and fuzzers.
  • Expands web/API attack coverage (CSV injection, open redirect, path traversal, parameter pollution, HTTP response splitting).
  • Integrates local-tooling references into agent bundles so agents can act on environment info instead of README-only guidance.
  • Updates SKILL.md banner to display "bountyforge".
  • Cleans and clarifies README.md including an "Enabling Claude Code Execution" section.
  • Misc: tidy up attack vector docs and agent instructions.

Highlights

  • New files:
    • references/setup.md — Deepseek CLI env and export usage
    • references/local-tooling.md — standalone local tooling + vuln coverage guide
  • Key updates:
    • SKILL.md — banner changed to bountyforge; bundles now include setup.md and local-tooling.md
    • README.md — Deepseek Pro environment examples (macOS/Linux + PowerShell), instructions for enabling Claude Code execution
    • references/attack-vectors/web-api-vectors.md — added CSV injection, open redirect, path traversal, parameter pollution
    • references/hacking-agents/web-api-agent.md — local tool integration instructions and expanded tests
    • references/hacking-agents/shared-rules.md — canonical bug classes extended

Changelog

  • Added: Deepseek Pro environment variables and deepseek export usage for temporary project binding.
  • Added: references/local-tooling.md and integrated into agent bundle creation.
  • Updated: Web/API vectors and agent rules to cover more payload classes and local-tool usage.
  • Updated: README with clear steps to enable Claude Code execution and improved structure.
  • Fixed: Duplicate/stray sections and cleaned repo structure listing.

Upgrade / Usage Notes

  • If you run Claude locally, start it from the shell that has your project env vars loaded (see references/setup.md).
  • To use Deepseek Pro temporarily in a repo:
export ANTHROPIC_AUTH_TOKEN="your-deepseek-pro-token"
deepseek export --project . --key "$ANTHROPIC_AUTH_TOKEN" --mode pro
  • Ensure local tools are installed and on PATH if you expect agent-driven scans (e.g., nmap, ffuf, sqlmap, gobuster, curl, httpx, wfuzz, zap, burpsuite).

Breaking changes

  • None expected. Agents now include additional reference files in their bundles; no API changes.

Contributors

  • @Gabson0x and contributors updates, docs, and orchestration improvements.