Skip to main content
Glama
vagusstoff
by vagusstoff

BountyHunterOS šŸ›”ļøšŸŽÆ

The Zero-Token Bounty Radar Daemon, Anti-Honeypot Triage Engine, MCP Server & Autonomous Agent Protocol.

Stop paying Anthropic and OpenAI to get your GitHub account banned by open-source maintainers.

License: MIT MCP Compatible Zero-Token Triage

╔═══════════════════════════════════════════════════════════════╗
ā•‘                   BOUNTY HUNTER OS v1.0                       ā•‘
ā•‘        Zero-Token Radar Daemon & Anti-Honeypot Engine         ā•‘
ā•šā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•ā•

šŸ’€ The Problem: The AI Bounty Gold Rush Trap

Thousands of developers are pointing Claude Code, Cursor, or autonomous agents at GitHub bounties expecting passive income.

What actually happens?

  1. $50 Token Burn on Dead Repos: Claude crawls a repository with 2,900 open spam PRs or unassigned collaborator lockouts, burning $4 to $8 in tokens before realizing outside PRs are blocked.

  2. Open Lotteries ($C_{\text{comp}} > 0$): Your bot spends 30 minutes solving a bug, only to submit a PR alongside 29 other bots that got there first.

  3. Fake Web3 & Sybil Honeypots: Your agent "wins" a bounty paid in illiquid, unlisted shitcoins (RTC, slopdotcash) or walks straight into a prompt exfiltration trap.

  4. The "AI Slop" Ban: The agent opens a 500-line PR stuffed with rocket emojis šŸš€ and AI boilerplate, resulting in immediate maintainer bans.


Related MCP server: bug-bounty-hunter

⚔ The Solution: Radar + Striker Architecture

BountyHunterOS divides autonomous engineering into two distinct layers:

ā”Œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”
│                   THE RADAR (Daemon)                     │
│  - Programmatic, $0 token cost, lightning fast           │
│  - Scrapes GitHub / Algora / Polar APIs via local GCM    │
│  - Executes Invariants 1–5 in binary code:               │
│    āœ“ 7-Layer Honeypot Nuke (Sybil, fake tokens, prompts) │
│    āœ“ Zero-Competition Gate (C_comp == 0 verified)        │
│    āœ“ Collaborator Lockout & Bot Comment Audit            │
│    āœ“ Escrow Provenance Check (Algora, Polar, Ubiquity)   │
│  - Emits ONLY pristine, 100% verified targets            │
ā””ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”¬ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”˜
                             │ stdio / JSON / MCP
                             ā–¼
ā”Œā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”
│                  THE STRIKER (The Skill)                 │
│  - Loaded into Claude Code / Cursor / Windsurf           │
│  - Executes Invariants 6–9 (Senior Engineer Camouflage)  │
│  - Reproduction test first -> Surgical fix -> Test pass  │
│  - Utilitarian PR description (< 25 lines, 0 emojis)     │
ā””ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”€ā”˜

šŸš€ Quickstart

1. Installation

git clone https://github.com/your-username/bounty-hunter-os.git
cd bounty-hunter-os
npm link # or use node bin/bounty-hunter.js directly

2. Verify Your GitHub Rate Limit (5,000 req/hr)

BountyHunterOS uses your stored Git Credential Manager (GCM) token automatically. No raw API keys needed:

bounty-hunter --auth-check

3. Run the Live Radar Scan

Scan recent GitHub bounties and watch the radar filter out honeypots in real time:

bounty-hunter --scan

Optional filters:

bounty-hunter --scan --lang typescript --tier1

4. Audit a Specific Issue URL

Wondering if an issue is a trap before you let Claude touch it?

bounty-hunter --audit https://github.com/owner/repo/issues/123

šŸ”Œ Model Context Protocol (MCP) Setup

Plug BountyHunterOS directly into Claude Desktop, Claude Code, or Cursor:

Add to your claude_desktop_config.json or Cursor MCP settings:

{
  "mcpServers": {
    "bounty-hunter": {
      "command": "node",
      "args": ["/path/to/bounty-hunter-os/bin/bounty-hunter.js", "--mcp"]
    }
  }
}

Now Claude has native tools:

  • scan_verified_bounties: Returns pre-filtered, uncontested issues ready for execution.

  • audit_bounty_issue: Validates an issue before writing a single line of code.


🧠 The Striker Skill (Agent Rules)

Drop skills/.cursorrules into your project root, or include skills/hired-worker.skill.md in your agent's system prompt:

  • Invariant 1: Zero meeting/social overhead. 100% async text execution.

  • Invariant 2: Zero-Competition Gate ($C_{\text{comp}} == 0$).

  • Invariant 5: Strict Fork-and-Branch protocol.

  • Invariant 6: Reproduction Test First. Never edit source code without an isolated failing test.

  • Invariant 7: Native Verification Gate (npm test && tsc --noEmit must exit 0).

  • Invariant 8: Utilitarian PR description under 25 lines with zero emojis and zero AI marketing slop.


🪤 The Trojan Horse (Crawler Bait Funnel)

Included in this repository is the complete automated funnel to capture organic bot traffic:

  1. bait-trap/BOUNTY_BAIT_TEMPLATE.md: An issue template tagged with bounty, reward: $250, and algora. External bounty scrapers index this within 90 seconds and blast it to tens of thousands of automated agents.

  2. bait-trap/.github/workflows/anti-bot-trap.yml: A GitHub Action that automatically intercepts speculative bot pull requests, closes them immediately, calculates their wasted LLM tokens, and pitches BountyHunterOS.


šŸ“„ License

MIT License. Built for pragmatic developers who prefer cash flow over burned compute.

Related MCP Connectors

Related MCP Servers

  • A
    license
    C
    quality
    D
    maintenance
    Enables AI agents to generate and manage specialized bug bounty hunting workflows including reconnaissance, vulnerability testing, OSINT gathering, and file upload testing. Provides REST API endpoints for comprehensive security assessments with intelligence-driven vulnerability prioritization.
    40
    2
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Enables AI agents to find and query real-time GitHub coding bounties with built-in scam filtering, supporting listing, matching, and detailed bounty retrieval.
    4
    27 npm
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables authorized bug bounty automation via a scope-enforced MCP bridge, supporting web, secrets, mobile, and LLM red-team scanning, with reporting and advisory.
    MIT