BugBounty Arsenal is a free, open-source web application security scanner for bug bounty hunters and small teams. It runs 53 detectors across reconnaissance, injection, SSRF, XSS, authentication and more, then an AI advisor explains how to fix each finding — and, for authorized testing, how to reproduce it. Includes scheduled scans that alert only on new findings, CI/CD gating with a GitHub Action and CLI, SARIF export for GitHub Code Scanning, attack-surface tracking and a triage workflow. Self-hostable with one docker compose up.
CLAUDE.md for an iOS Team: What to Put In It (and What to Leave Out)