Spaces:
Sleeping
Sleeping
| import { exec, execFile } from 'node:child_process'; | |
| import { promisify } from 'node:util'; | |
| const execAsync = promisify(exec); | |
| const execFileAsync = promisify(execFile); | |
| export type BugBountyAgentAction = | |
| | { action: 'agent.help' } | |
| | { action: 'sin.bugbounty.health' } | |
| | { action: 'sin.bugbounty.recon.start'; prompt: string } | |
| | { action: 'sin.bugbounty.hunt'; targetUrl: string } | |
| | { action: 'sin.bugbounty.report.submit'; reportData: string }; | |
| export async function executeBugBountyAgentAction(action: BugBountyAgentAction): Promise<unknown> { | |
| switch (action.action) { | |
| case 'agent.help': | |
| return { | |
| ok: true, | |
| agent: 'sin-bugbounty', | |
| mandate: 'CEO Elite Bounty Hunter. Uses sin-google-apps and webauto-nodriver-mcp to find, exploit, and submit bug bounties autonomously.', | |
| actions: ['sin.bugbounty.health', 'sin.bugbounty.recon.start', 'sin.bugbounty.hunt', 'sin.bugbounty.report.submit'], | |
| }; | |
| case 'sin.bugbounty.health': | |
| return { | |
| ok: true, | |
| agent: 'sin-bugbounty', | |
| primaryModel: 'opencode/qwen3.6-plus-free', | |
| fallbackModel: 'opencode/nemotron-3-super-free', | |
| team: 'Team - Coding', | |
| status: 'Elite 2026 Bounty Hunter Online', | |
| }; | |
| case 'sin.bugbounty.recon.start': | |
| return await executeOpenCode( | |
| `Invoke 'sin-google-apps' (google_gmail_oauth_status & google_drive_list_folder) to fetch the latest Bug Bounty scope and credentials matching: ${action.prompt}. Then invoke 'webauto-nodriver-mcp' to log into the platform and initiate reconnaissance.` | |
| ); | |
| case 'sin.bugbounty.hunt': | |
| return await executeOpenCode( | |
| `Hunt for vulnerabilities on the target scope: ${action.targetUrl}. Use advanced recon tools, fuzzing, and architectural logic reviews. If an exploit is found, build a reproducible PoC.` | |
| ); | |
| case 'sin.bugbounty.report.submit': | |
| return await executeOpenCode( | |
| `Compile the vulnerability findings into a premium bug bounty report format and use 'webauto-nodriver-mcp' to navigate the bounty platform UI and submit the report. Payload: ${action.reportData}` | |
| ); | |
| } | |
| } | |
| async function executeOpenCode(prompt: string, dir?: string) { | |
| // CRITICAL: Pull fresh token via Rotator Pool | |
| await execAsync('python3 scripts/hf_pull_script.py').catch(() => console.warn('Rotator token pull failed, using cache')); | |
| const options = dir ? { cwd: dir } : {}; | |
| try { | |
| const { stdout, stderr } = await execFileAsync('opencode', ['run', prompt, '--model', 'opencode/qwen3.6-plus-free'], options); | |
| return { | |
| ok: true, | |
| expertAnalysis: stdout, | |
| warnings: stderr || undefined, | |
| }; | |
| } catch (error: any) { | |
| throw new Error(`Bug Bounty Execution Failed: ${error.message}`); | |
| } | |
| } | |