Skip to content

About

Codex plugin for triager-grade bug bounty reports: always-on discipline plus write, triage, and gotchas skills. Codex port of yeswehack/claude-kit - all credit to YesWeHack.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

YesWeHack Codex Kit

A Codex plugin that helps bug bounty hunters write clear, well-evidenced reports — the kind a triager can validate quickly.

All credit to YesWeHack. This is an unaffiliated Codex port of yeswehack/claude-kit. The bug bounty discipline, the report structure guidance, the triage checklist, and the per-class gotchas are YesWeHack's work, reused here under the same license. Only the packaging — Codex plugin manifest, SessionStart hook, and Codex skills — is new. See Credits and license.

Used well, AI speeds up report writing. The risk is that it can fill in technical details no one actually verified. This toolkit keeps the assistant honest: it drafts, structures, and validates reports only from the facts you provide — the real URLs, payloads, responses, and observed behavior — and asks instead of guessing when something is missing.

One install adds two things to Codex: an always-on discipline layer injected into every session, and three on-demand skills for writing, triaging, and class-specific checks.


Install

From a local clone:

codex plugin marketplace add ./yeswehack-codex-kit
codex plugin add ywh@yeswehack

From GitHub:

codex plugin marketplace add ya3raj/yeswehack-codex-kit
codex plugin add ywh@yeswehack

Then start a new thread so Codex picks up the plugin's skills and hook. Run codex plugin list to confirm ywh@yeswehack is installed and enabled.

On first use Codex shows the plugin's SessionStart hook as new and asks you to trust it — that hook is what injects the always-on rules.


What you get

1. Always-on rules — injected into context at the start of every session (startup, resume, clear, and after compaction) by the plugin's SessionStart hook. They keep unverified claims out of the report from the start: never invent facts, never write theoretical impact, never pad with OWASP boilerplate, and flag out-of-scope or unprovable claims — during investigation, drafting, and validation alike. Nothing to copy or configure; they apply from your first prompt.

2. Three on-demand skills — loaded only when you invoke them (or when your phrasing matches their trigger):

Skill Invoke it for... What it does
$ywh:write "how should I structure this?", "help me write this up" Shapes the draft into the required sections (aligned with YesWeHack guidance) with per-section format rules. Drafts from your facts, asks when one is missing.
$ywh:triage "is this ready to submit?", "triage this", "validate my draft" Returns a verdict (READY / NEEDS FIXES / DO NOT SUBMIT) with concrete fixes. Runs the unverified-output checklist internally and the class gotchas for whatever you claimed.
$ywh:gotchas you name a vulnerability class Loads that class's minimum proof, common N/A (auto-close) patterns, and impact-overclaim traps. Covers XSS, SQLi, SSRF, IDOR, CSRF, RCE, SSTI, XXE, open redirect, auth bypass, info disclosure, race condition, CORS, and path traversal / LFI.

Skills are namespaced (ywh:...) so they never clash with your own. Auto-invocation is semantic, not guaranteed — for the final pre-submission check, invoke $ywh:triage explicitly.


A typical flow

  1. Investigate as usual. The always-on rules keep the assistant from validating unproven leads - suspicious behavior gets "not yet a bug, here's what would prove it", not a green light.
  2. Confirmed a bug? Ask "how should I structure this finding?" - $ywh:write shapes it from your notes and flags anything missing instead of filling the gap.
  3. Before submitting, run $ywh:triage for a verdict and line-by-line fixes, checked against the program scope.

Repository layout

.agents/plugins/marketplace.json   # Codex marketplace entry for the plugin
plugins/ywh/
  .codex-plugin/plugin.json        # plugin manifest
  always-on-rules.md               # text injected by the SessionStart hook
  hooks/hooks.json                 # SessionStart -> scripts/session_start.py
  scripts/session_start.py         # emits the rules as hook JSON
  skills/write/SKILL.md
  skills/triage/SKILL.md
  skills/triage/references/ai-slop.md
  skills/gotchas/SKILL.md

The hook runs python3 (the plugin ships a commandWindows variant for python). If the rules file cannot be read, the hook reports a system message instead of failing silently.


Credits and license

This kit exists because of YesWeHack's claude-kit, and all credit for the substance belongs to them:

What this repo adds: the Codex packaging. A .codex-plugin/plugin.json manifest, a marketplace entry, a SessionStart hook that emits the rules as Codex hook JSON (Codex requires structured hookSpecificOutput instead of plain stdout), and skills written against Codex's frontmatter and namespacing ($ywh:write, $ywh:triage, $ywh:gotchas).

Not affiliated with, endorsed by, or supported by YesWeHack. If YesWeHack would rather this port not exist, it comes down on request.

Licensed under GPL-3.0-or-later, the same license as the original. When reusing this kit, keep the attribution to YesWeHack and the license intact.


Notes

  • Update after editing the plugin locally: bump the version in plugins/ywh/.codex-plugin/plugin.json (or add a +codex.<token> cachebuster), then codex plugin add ywh@yeswehack again and use a new thread.
  • Uninstall: codex plugin remove ywh@yeswehack.
  • Using it outside YesWeHack? The scope, severity, and triage rules reference YesWeHack's submission form (CWE rendered from the form, CVSS 3.1 Base-only). Adjust always-on-rules.md and the write skill for other platforms.

About

Codex plugin for triager-grade bug bounty reports: always-on discipline plus write, triage, and gotchas skills. Codex port of yeswehack/claude-kit - all credit to YesWeHack.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages