import { exec, execFile } from 'node:child_process'; import { promisify } from 'node:util'; const execAsync = promisify(exec); const execFileAsync = promisify(execFile); export type BugBountyAgentAction = | { action: 'agent.help' } | { action: 'sin.bugbounty.health' } | { action: 'sin.bugbounty.recon.start'; prompt: string } | { action: 'sin.bugbounty.hunt'; targetUrl: string } | { action: 'sin.bugbounty.report.submit'; reportData: string }; export async function executeBugBountyAgentAction(action: BugBountyAgentAction): Promise { switch (action.action) { case 'agent.help': return { ok: true, agent: 'sin-bugbounty', mandate: 'CEO Elite Bounty Hunter. Uses sin-google-apps and webauto-nodriver-mcp to find, exploit, and submit bug bounties autonomously.', actions: ['sin.bugbounty.health', 'sin.bugbounty.recon.start', 'sin.bugbounty.hunt', 'sin.bugbounty.report.submit'], }; case 'sin.bugbounty.health': return { ok: true, agent: 'sin-bugbounty', primaryModel: 'opencode/qwen3.6-plus-free', fallbackModel: 'opencode/nemotron-3-super-free', team: 'Team - Coding', status: 'Elite 2026 Bounty Hunter Online', }; case 'sin.bugbounty.recon.start': return await executeOpenCode( `Invoke 'sin-google-apps' (google_gmail_oauth_status & google_drive_list_folder) to fetch the latest Bug Bounty scope and credentials matching: ${action.prompt}. Then invoke 'webauto-nodriver-mcp' to log into the platform and initiate reconnaissance.` ); case 'sin.bugbounty.hunt': return await executeOpenCode( `Hunt for vulnerabilities on the target scope: ${action.targetUrl}. Use advanced recon tools, fuzzing, and architectural logic reviews. If an exploit is found, build a reproducible PoC.` ); case 'sin.bugbounty.report.submit': return await executeOpenCode( `Compile the vulnerability findings into a premium bug bounty report format and use 'webauto-nodriver-mcp' to navigate the bounty platform UI and submit the report. Payload: ${action.reportData}` ); } } async function executeOpenCode(prompt: string, dir?: string) { // CRITICAL: Pull fresh token via Rotator Pool await execAsync('python3 scripts/hf_pull_script.py').catch(() => console.warn('Rotator token pull failed, using cache')); const options = dir ? { cwd: dir } : {}; try { const { stdout, stderr } = await execFileAsync('opencode', ['run', prompt, '--model', 'opencode/qwen3.6-plus-free'], options); return { ok: true, expertAnalysis: stdout, warnings: stderr || undefined, }; } catch (error: any) { throw new Error(`Bug Bounty Execution Failed: ${error.message}`); } }