ClaudeBrain
____ _ _ ____ _
/ ___| | __ _ _ _ __| | ___| __ ) _ __ __ _(_)_ __
| | | |/ _` | | | |/ _` |/ _ \ _ \| '__/ _` | | '_ \
| |___| | (_| | |_| | (_| | __/ |_) | | | (_| | | | | |
\____|_|\__,_|\__,_|\__,_|\___|____/|_| \__,_|_|_| |_|
Pentest & bug-bounty knowledge base + AI automation harness
An AI-powered penetration testing and bug-bounty knowledge base and automation harness for Claude Code. It turns an Obsidian vault into an opinionated offensive-security workflow: a searchable wiki of 500+ hacking technique pages, per-vulnerability "hunt" skills, deterministic hooks that fire the right skill at the right moment, and a state-first engagement model that stops you (and the model) from repeating work.
ClaudeBrain is a red-team / bug-bounty second brain built on Andrej Karpathy's LLM Wiki pattern: a persistent, AI-maintained knowledge base the model synthesizes each new source into over time, instead of re-deriving from raw documents on every query. Concretely, an offensive-security wiki, an agentic hunt-skill library, and a Model Context Protocol (MCP) search layer, wired together so Claude Code always checks the knowledge base before it attacks and never repeats a dead end. Think HackTricks or PayloadsAllTheThings, but indexed for semantic search and driven by an autonomous AI agent.
Authorized testing only. Everything here assumes a legal engagement: a signed penetration test, a bug-bounty program in scope, or your own lab / CTF. You are responsible for staying in scope and within the rules of engagement.
If ClaudeBrain saves you time on an engagement, a star helps other pentesters and bug-bounty hunters find it.
Contents