opencode-js-bountyOpencode plugin for automated JS bundle bug bounty analysis and UI tracking
3
37
近 7 天 3
28.3
生态多维模型
4 个月前
2026-04-21
快速安装与配置
opencode.json写入当前项目的 opencode.json,只对这个仓库生效。
opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-js-bounty@1.0.2"]
}写入 ~/.config/opencode/opencode.json,对所有项目生效。
~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-js-bounty@1.0.2"]
}若你要在本地改造这个插件,先装到项目里再从本地路径引用。
shell
pnpm add -D opencode-js-bountyopencode 启动时会通过内嵌运行时自动加载 npm 依赖并缓存至本地目录,无需手动在全局环境执行安装。

An official OpenCode plugin that automatically downloads js files, analyzes them for hidden API endpoints and local storage secrets, and spins up a beautiful local Bug Bounty Tracker UI to manage your hunt!
Installation
- Add the plugin to your OpenCode project by editing opencode.json:
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-js-bounty"]
}
- Run
npm install opencode-js-bounty(or whatever your package manager uses to install it locally).
Note: The installation process will automatically register the /js-bounty command into your OpenCode CLI via a post-install hook.
Usage
Simply trigger the analysis inside OpenCode by passing a local file path or a remote URL:
/js-bounty https://example.com/assets/file.js
What happens next?
- OpenCode seamlessly intercepts the command and downloads the file.
- The plugin executes a high-speed extraction script, aggressively pulling out all `/api/`, `/v1/`, and `/jwt/` paths, along with cached `llab-` secrets.
- The data is saved to `tracker-state.json`.
- A stealthy local UI server boots up at http://localhost:49152.
- OpenCode replies with a single link to click. No terminal clutter!
Features
- Zero Configuration: Just pass a URL and get a full dashboard.
- Plannotator-Style UI: A dark-mode, split-pane React application built-in.
- Persistent State: Notes, statuses, and checkboxes are instantly saved to disk locally.
- Auto-Categorization: Automatically separates hidden localStorage keys from standard REST APIs.
Author & Support
Created with ❤️ by Ahmed Yasser
If this tool helped you secure a sweet bounty, consider starring the repo or reaching out on Twitter/X (@spxios)!