Skip to main content

Bug bounty automation: vulnerability fix patterns for Python and Solidity with SARIF export

Project description

Bounty Hunter Toolkit

PyPI Tests Patterns License Python

Production-ready security fix patterns for GitHub bounty issues. 15 patterns across Python, Solidity, and TypeScript. Zero dependencies.

Install

pip install bounty-hunter-toolkit

What Is This?

Bug bounty programs on GitHub post issues like "Fix SQL injection in user.py" with bounties ranging from $5 to $500. This toolkit contains the proven fix patterns that resolve these issues, so you can apply a correct fix in minutes instead of researching from scratch.

15 patterns. 52 tests. Real vulnerabilities found and fixed on repositories like ClankerNation, ai-research, TentOfTrials, and Nexussyn.

Pattern Categories

Python Security Fixes (10 patterns)

Vulnerability Fix Pattern
SQL Injection Parameterized queries cursor.execute("SELECT * WHERE id = ?", (id,))
JWT None Algorithm Explicit algorithms list jwt.decode(token, key, algorithms=["HS256"])
XXE defusedxml / entity removal Disable DTD external entities
SSTI Jinja2 autoescape Use render_template() not render_template_string()
NoSQL Injection Type validation if not isinstance(id, int): reject
CSRF Per-session tokens session['csrf_token'] = secrets.token_hex()
Open Redirect urlparse validation Check urlparse(target).netloc == ''
Log4j JNDI Input sanitization Remove ${jndi:ldap:} patterns
Unsafe YAML safe_load yaml.safe_load(data) not yaml.load()
Unsafe Pickle Restricted unpickler pickle.Unpickler().find_class = restricted
Docker Escape seccomp profile Drop CAP_SYS_ADMIN, add --security-opt
Path Traversal Path.resolve check if not path.resolve().is_relative_to(base)
SSRF IP range validation Block 169.254.0.0/16, 10.0.0.0/8
Command Injection subprocess list form subprocess.run(["ls", arg]) not os.system()
XXE SOAP Disable DTD parser.feature_external_ges = False
Insecure Deserialization JSON instead of pickle json.loads() for untrusted data
Race Condition File locking fcntl.flock(f, fcntl.LOCK_EX)
Information Disclosure Remove debug mode app.debug = False
Weak Crypto Use hashlib hashlib.sha256() not hashlib.md5()
Insecure File Upload Validate extension + magic Check file header bytes
Mass Assignment Explicit field whitelist Model(**allowed_fields_only)
Timing Attack Constant-time compare hmac.compare_digest(a, b)
Session Fixation Regenerate on login session.regenerate() after auth
Insecure CORS Explicit origins CORS(app, origins=["https://app.com"])
Clickjacking X-Frame-Options response.headers['X-Frame-Options'] = 'DENY'
MIME Sniffing X-Content-Type-Options response.headers['X-Content-Type-Options'] = 'nosniff'
Insecure Cookie Secure + HttpOnly flags set_cookie(..., secure=True, httponly=True)

Solidity Security Fixes (15 patterns)

Contract Vulnerability Fix
AgentRegistry Unchecked batch Loop bounds + revert on failure
GovernorAlpha Missing quorum Require quorumVotes <= totalVotes
Timelock Queue bypass Enforce delay >= MINIMUM_DELAY
PaymentEscrow Zero-amount drain require(msg.value > 0)
MultiTokenStaking emergencyWithdraw drain Check staked balance before withdrawal
InterestRateModel Missing events Emit event on state change
AMMPool Unindexed events Add indexed to key parameters
CompoundVault Reentrancy Add nonReentrant modifier
RandomLottery No refund mechanism Allow refund if winner not claimed
PrizeSplit Zero-share division require(share > 0)
GasSponsorRelay ERC2771 mismatch Validate trustedForwarder
TokenBridge Unvalidated address Check isContract(target)
AgentToken Permit replay Include chainId in domain separator
SafeERC20 Transfer return value Use SafeERC20.safeTransfer()
Permit2Adapter Gasless approval drain Limit allowance + expiry

TypeScript/SDK Fixes (9 patterns)

File Vulnerability Fix
session.ts 401 no refresh Auto-refresh on 401 response
wallet.ts Wrong EIP-712 Typed data structure validation
rpc.ts Batch injection Validate JSON-RPC batch items
websocket.ts Duplicate reconnect Dedup by connection ID
crypto.ts Wrong recovery secp256k1 recovery flag handling
retry.ts Infinite retry Conditional retry with backoff cap
deploy.py Missing gas estimate web3.eth.estimate_gas() before send
events.py Event loss Resubscribe on disconnect
encoding.py Nested decode error Recursive struct decoder

Usage

from bounty_hunter_toolkit import PatternMatcher

matcher = PatternMatcher()

# Find patterns matching a vulnerability description
patterns = matcher.find("sql injection")
for p in patterns:
    print(f"{p.name}: {p.description}")
    print(f"  Vulnerable: {p.vulnerable_code[:80]}")
    print(f"  Fixed: {p.fixed_code[:80]}")

# Apply a pattern to a file
matcher.apply("sql_injection", "app.py")
# CLI usage
python -m bounty_hunter_toolkit --list
python -m bounty_hunter_toolkit --find "jwt"
python -m bounty_hunter_toolkit --apply sql_injection --file app.py

Testing

python -m pytest tests/ -v --tb=short

52 tests. Each pattern has:

  • Test that vulnerable code triggers the detector
  • Test that fixed code passes
  • Test that the fix does not break functionality

Real Results

Target Issues Fixed Bounty
ClankerNation/OpenAgents 41 patterns PR submitted
ai-research 27 security fixes Posted
TentOfTrials 14 bounties 3 emails
Nexussyn 4 fixes $40 USDC

License

MIT

Links

Freelance portfolio: https://ameobius-space.github.io/kwork-portfolio/

Hire on LaborX: https://laborx.com/gigs/python-automation-telegram-bots-cdp-api-integrations-105867

Real-World Use Cases

  • LaborX batch apply: 270+ applications via JWT Bearer + SOCKS5
  • Kwork dialog monitoring: CDP9224 conversation tracking at scale
  • Gmail API: OAuth2 automation for inbox monitoring
  • Freelance pipeline: Automated bid → apply → track → report
  • Bug bounty recon: Subdomain enumeration + evidence collection

Articles

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

bounty_hunter_toolkit-1.4.1.tar.gz (15.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

bounty_hunter_toolkit-1.4.1-py3-none-any.whl (12.6 kB view details)

Uploaded Python 3

File details

Details for the file bounty_hunter_toolkit-1.4.1.tar.gz.

File metadata

  • Download URL: bounty_hunter_toolkit-1.4.1.tar.gz
  • Upload date:
  • Size: 15.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.10.12

File hashes

Hashes for bounty_hunter_toolkit-1.4.1.tar.gz
Algorithm Hash digest
SHA256 f88c1ccefb619896c3fb00a501865608ee5f80a7326ed863a36a6ccdc30d81cf
MD5 20710b53b6152663b05bd7b59d9a3b1a
BLAKE2b-256 d1da7c2dc34f2a73a1f777a0a70ec0500d4912233c8c0da877649efc63969913

See more details on using hashes here.

File details

Details for the file bounty_hunter_toolkit-1.4.1-py3-none-any.whl.

File metadata

File hashes

Hashes for bounty_hunter_toolkit-1.4.1-py3-none-any.whl
Algorithm Hash digest
SHA256 4b4c00e0710c53901559af7586655767aa65a97ea245c7b7e08cf1e11b7172c8
MD5 5291c73ca7b7ef28bc32d2df66802a2d
BLAKE2b-256 0e6bac73d60e20d3451ee07ea46b2759057d9f5a99e6bf3aaf40803d29d10a55

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page