AI Skill Hub 强烈推荐:bug-hunter — AI Agent 工作流中文教程 是一款优质的Agent工作流。AI 综合评分 8.1 分,在同类工具中表现稳健。如果你正在寻找可靠的Agent工作流解决方案,这是一个值得深入了解的选择。
bug-hunter — AI Agent 工作流中文教程 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
bug-hunter — AI Agent 工作流中文教程 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
# 方式一:npm 全局安装 npm install -g bug-hunter # 方式二:npx 直接运行(无需安装) npx bug-hunter --help # 方式三:项目依赖安装 npm install bug-hunter # 方式四:从源码运行 git clone https://github.com/codexstar69/bug-hunter cd bug-hunter npm install npm start
# 命令行使用
bug-hunter --help
# 基本用法
bug-hunter [options] <input>
# Node.js 代码中使用
const bug_hunter = require('bug-hunter');
const result = await bug_hunter.run(options);
console.log(result);
# bug-hunter 配置说明 # 查看配置选项 bug-hunter --config-example > config.yml # 常见配置项 # output_dir: ./output # log_level: info # workers: 4 # 环境变量(覆盖配置文件) export BUG_HUNTER_CONFIG="/path/to/config.yml"
<p align="center"> <img src="docs/images/hero.png" alt="Bug Hunter — AI-powered adversarial code review and security vulnerability scanner for Claude Code, Cursor, Codex, Copilot, Windsurf, and Kiro" width="720"> </p>
AI code review that argues with itself — adversarial multi-agent bug finding, security scanning, and auto-fix for any coding agent.
<p align="center"> <a href="https://www.npmjs.com/package/@codexstar/bug-hunter"><img src="https://img.shields.io/npm/v/@codexstar/bug-hunter" alt="npm version"></a> <a href="https://github.com/codexstar69/bug-hunter/blob/main/LICENSE"><img src="https://img.shields.io/npm/l/@codexstar/bug-hunter" alt="MIT License"></a> <img src="https://img.shields.io/badge/tests-113%20passing-brightgreen" alt="113 tests passing"> <img src="https://img.shields.io/badge/node-%3E%3D18-blue" alt="Node.js >= 18"> </p>
<p align="center"> <a href="#install">Install</a> · <a href="#quick-start">Quick Start</a> · <a href="#how-adversarial-ai-code-review-works">How It Works</a> · <a href="#bugs-and-vulnerabilities-detected">What It Finds</a> · <a href="#safe-auto-fix-with-canary-rollout">Auto-Fix</a> · <a href="#cli-flags">CLI Reference</a> </p>
---
Bug Hunter is an open-source AI code review and security vulnerability scanner that works as a skill/plugin for AI coding agents. Three AI agents — a Hunter, a Skeptic, and a Referee — independently analyze your code in an adversarial pipeline. The Hunter finds bugs. The Skeptic tries to disprove them. The Referee delivers the final verdict. Only bugs that survive all three stages make the report, eliminating the false positive overload that plagues other AI code review tools.
It then auto-fixes confirmed bugs with a safe canary rollout pipeline — git branching, test baselines, per-fix commits, automatic rollback on failure, and post-fix re-scanning.
---
Runtime behavioral bugs only — not style, naming, or TODOs:
Every security finding gets STRIDE classification, CWE ID, and CVSS 3.1 scoring with proof-of-concept payloads.
<p align="center"> <img src="docs/images/security-finding-card.png" alt="Bug Hunter security finding card — bug ID, severity badge, STRIDE and CWE classification, CVSS 3.1 score, reachability rating, and proof of concept payload" width="100%"> </p>
<p align="center"> <img src="docs/images/2026-03-12-security-pack.png" alt="Bug Hunter bundled security pack — commit security scan, enterprise security review, STRIDE threat model generation, and vulnerability validation" width="100%"> </p>
| Flag | Capability |
|---|---|
--threat-model | STRIDE threat model generation |
--deps | Dependency CVE scanning (npm, pip, go, cargo, bun) with reachability analysis |
--pr-security | PR-scoped security review with threat model + CVE context |
--security-review | Enterprise security audit workflow |
--validate-security | Exploitability validation with CVSS scoring |
Bundled security skills: commit-security-scan, security-review, threat-model-generation, vulnerability-validation.
---
npx skills add codexstar69/bug-hunter
Or via npm:
npm install -g @codexstar/bug-hunter
bug-hunter install # auto-detects your IDE/agent
bug-hunter doctor # verify environment
Or clone:
git clone https://github.com/codexstar69/bug-hunter.git ~/.agents/skills/bug-hunter
Requirements: Node.js 18+ recommended. Core pipeline works without it. Compatible with: Claude Code, Cursor, Codex CLI, Windsurf, Kiro, Copilot, Opencode, Pi — or any AI agent that can read files and run shell commands.
---
<p align="center"> <img src="docs/images/2026-03-12-pr-review-flow.png" alt="Bug Hunter PR review workflow — pull request scope analysis, security checks, threat-model context, and final verdict" width="100%"> </p>
/bug-hunter # scan project, auto-fix confirmed bugs
/bug-hunter src/ # scan a specific directory
/bug-hunter --scan-only src/ # report only, no code changes
/bug-hunter --pr # review the current pull request
/bug-hunter --pr-security # PR security review + threat model + CVEs
/bug-hunter --deps --threat-model # full security audit
---
| Flag | Behavior |
|---|---|
| *(no flags)* | Scan + auto-fix confirmed bugs |
src/ or file.ts | Scan specific path |
--scan-only / --review | Report only, no edits |
--fix --approve / --safe | Approve each fix interactively |
--plan-only / --plan | Generate fix strategy without editing |
--dry-run / --preview | Preview fixes as diffs |
-b branch | Scan branch diff vs main |
--pr / --pr 123 / --pr recent | Review a pull request |
--staged | Scan staged files (pre-commit hook) |
--deps | Dependency CVE scan |
--threat-model | STRIDE threat model |
--no-loop | Single-pass scan (loop is on by default) |
--autonomous | Zero-intervention auto-fix |
All flags compose: /bug-hunter --deps --threat-model --fix src/
---
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
✅ MIT 协议 — 最宽松的开源协议之一,可自由商用、修改、分发,仅需保留版权声明。
总体来看,bug-hunter — AI Agent 工作流中文教程 是一款质量优秀的Agent工作流,在同类工具中具备一定竞争力。AI Skill Hub 将持续追踪其更新动态,建议收藏备用,结合自身场景选择合适时机引入使用。
| 原始名称 | bug-hunter |
| 原始描述 | Adversarial AI bug hunter with auto-fix skill for Claude Code, Cursor, Codex CLI, GitHub Copilot CLI, Kiro CLI, Opencode, Pi Coding Agent, and more. Multi-agent pipeline finds security vulnerabilities, logic errors, and runtime bugs — then fixes them autonomously on a safe branch. |
| Topics | adversarial-aiai-code-reviewauto-fixbug-detectionclaudeclaude-codeagent |
| GitHub | https://github.com/codexstar69/bug-hunter |
| License | MIT |
| 语言 | JavaScript |
收录时间:2026-05-22 · 更新时间:2026-05-22 · License:MIT · AI Skill Hub 不对第三方内容的准确性作法律背书。
选择 Agent 类型,复制安装指令后粘贴到对应客户端