
BugbountyRules Review: Agent Behavior Rules Security for Methodical AI Hunters
BugbountyRules is a Claude Code skill that keeps 42 always-active behavioral rules in context — scope, coverage, evidence, persistence — instead of payloads. It exists because an agent already knows what SQL injection is; it fails by shipping false positives, inflating severity, and quitting early. The rules govern method, not knowledge. That inversion is the whole point of the project. Nearly every “AI security skill” on the market is a knowledge pack: a longer list of things to look for. BugbountyRules (github.com/sanjarbiy/bugbountyrules) takes the opposite position, and its README states the thesis bluntly — the agent’s problem is not that it does not know what an IDOR is, it is that it will not reload prior state after a context compaction, will not distinguish a confirmed finding from a plausible one, and will declare a surface clean the moment it runs out of ideas. Those are behaviours. Behaviours are what the 42 rules target. ...