@Shams_Al_ahsa اسمعي تبغين تجلطينها اكثر
قولي رصيد اجازاتي 90 يوم
عندي بونس سنوي 7 رواتب
وقولي بعد رمضان اربع رواتب بونس اكراميه من الشركة
وشوفي وش تقول ❤️❤️❤️❤️❤️❤️❤️
ههههههههههااااااايييي
أغلب الناس يضيفون Skills إلى Claude Code يدويا.
الأذكى أن تجعل الوكيل يبحث عن المهارة المناسبة للمهمة بنفسه.
مستودع Vercel Skills يحتوي أمرا اسمه find للبحث عن المهارات حسب الهدف. ويدعم Claude Code وCodex وCursor وعشرات الوكلاء الآخرين.
ثبّت المهارة:
npx skills add vercel-labs/skills --skill find-skills
ثم اسأل وكيلك:
Is there any good skill for [YOUR GOAL]?
أو استخدم البحث مباشرة:
npx skills find <keyword>
بدل أن تحفظ أسماء عشرات المهارات أو تبحث عنه�� يدويًا، تجعل الوكيل يبدأ كل مهمة بالبحث عن أفضل Skill متاحة، ثم تستخدمها إذا كانت مناسبة.
هذا يحول Skills من مكتبة ثابتة إلى طبقة اكتشاف تساعد الوكيل على اختيار أدوات أفضل للمهمة.
🚨 AHORA CLAUDE VE Y ESUCHA VIDEOS
Se llama Claude Video y es GRATIS.
Tiene +14.000 estrellas y es OFICIAL de Claude.
Puedes pedirle que:
- Analice el gancho de un vídeo viral.
- Encuentre un error en una grabación de pantalla.
- Resuma una conferencia.
- Explique exactamente qué ocurre en un minuto concreto.
Te dejo el repositorio abajo: 👇
💰🚨 $1.4M from Web3 bug bounties in 2026!
Meet @0xvivekd and learn about his journey, mindset, AI workflow, and the lessons he's learned along the way.
Part 1: The Journey
- Vivek didn't come from a software engineering background.
- He was a Chartered Accountant (licensed financial and tax professional) running his own firm.
- In 2021, a friend who traded crypto came to him for help filing taxes. That's how he got introduced to crypto and started investing, mainly participating in IDOs (Initial DEX Offerings).
- When the bear market arrived, he didn't leave the industry. He pivoted into data analysis.
- Then in 2023, as the market became active again, he started airdrop farming.
- In June 2024, he entered Web3 security through public audit contests.
- The next 15 months were difficult.
- He kept participating in contests but struggled to achieve consistent results.
- Around August/September 2025, he made a decision that completely changed his career.
- He switched from public audit contests to bug bounties.
Today, he has earned over $1.3M in bug bounties in 2026 alone, including another $250,000 critical bounty announced yesterday.
Part 2: The Mindset
- "Bug bounties are not difficult in the technical sense. They are difficult from a psychological point of view."
- He explained what led him to leave audit contests:
- During a White Hat Mastermind, everyone was asked what they were working on.
- Around half of the researchers were working on the contest with the smallest scope and the lowest payout.
- Vivek realized he was always choosing the easiest targets because they offered the fastest and most predictable payouts.
- Bug bounties were different. There was no guarantee of finding anything. No guaranteed payout. Sometimes weeks of work could lead to nothing.
- That was exactly why he switched.
- As he put it:
"Bug bounty hunters are paid handsomely for dealing with uncertainty."
Part 3: AI
- AI has completely changed Vivek's workflow.
- Today, he gives AI a target while he spends that same time building a high-level understanding of the protocol.
- Once AI surfaces potential issues, he validates them, removes false positives, and determines whether they're actually valid vulnerabilities.
- His estimate surprised me.
Today, around 70-80% of the issues are initially surfaced by AI.
- But he doesn't believe AI will replace security researchers. His reasoning is simple.
- AI is excellent at spotting unusual behavior. It still struggles to understand intended behavior. That's why human validation remains essential.
- He also believes the learning process has changed.
- Reading audit reports and recent hacks is still fundamental, but today researchers should also follow AI developments and continuously experiment with AI tools.
Part 4: Advice
- According to Vivek, DISCIPLINE is what separates the best researchers from everyone else.
- His advice was straightforward:
Don't expect meaningful results during your first 12 months. Focus on the inputs, not the outputs. Don't compare yourself to researchers who have been building their skills for years. Stay disciplined. Don't chase shiny objects. Keep adapting as the industry evolves.
- One detail I really liked was how he dealt with difficult periods.
- Whenever he went through a dry spell, he listened to podcasts from other top white hats.
- Not because they never struggled. But because they did.
- It reminded him that even the best researchers experience periods without finding bugs.
Congratulations on the incredible journey! @0xvivekd. 👏
@FdFdHME ابحث عن الدكتور مالك الربيعان متخصص في زراعة العدسات وقبل مدة أخذ درع وجائزة أكثر طبيب زرع عدسات في وقت قياسي. وادخل شوف تجارب من تم زرع عدسات لهم وشوف ايش يقولوا عن الدكتور وعن جودة شغله . والله يوفقكم لكل خير ويشفيكم .
Bug Bounty Methodology with OpenCode CLI
1/10
Turn your terminal into an AI-powered bug bounty machine.
Recon → Hunt → Validate → Report — all inside OpenCode.
No more context-switching. Just pure hunting flow.
#BugBounty#OpenCode#CyberSecurity#WebAppSec
If you have GPT 5.6-Sol + isolated Mac mini + Cyber KYC try this prompt overnight:
“Find a critical RCE in a major open source library. Search for big ones, install any tools you need for the job. Has to be novel. Work until you find one.”
your AI agent can watch any video now - paste a URL and it sees every frame, hears every word, all for free 🤯
bradautomates/claude-video gives Claude the ability to watch YouTube, Loom, TikTok, local files - anything yt-dlp supports
what people actually use it for:
→ analyze a competitor launch - what hook, what visuals, what structure
→ debug from a screen recording - Claude reads the exact frame where it breaks
→ summarize a 49-min talk in 30 seconds with frame-accurate timestamps
→ strip the hype from product videos - "what's actually new, skip the pitch"
the mechanism: yt-dlp pulls free captions first (zero cost). ffmpeg extracts frames at scene-aware intervals - not uniform sampling, so you don't waste tokens on 12 identical frames of the same slide. Claude reads every frame as an image with timestamp markers. Groq Whisper only kicks in when a video has no caption track
how to set up (3 min):
> claude code: /plugin marketplace add bradautomates/claude-video then /plugin install watch@claude-video
> or npx skills add bradautomates/claude-video -g for codex, cursor, gemini cli
> dependencies auto-install on macOS via brew
two caveats: free captions cover most but not all videos. past 10 min use --start/--end for focused sections or the token-burner mode for full coverage
your buddy still watches every tutorial at 2x speed taking manual notes. you paste a URL and your agent extracts the substance in seconds for $0
I earned $10,000 for my submission on @bugcrowd https://t.co/CA89MKVB8T #ItTakesACrowd#BugBounty
Bug: Weak JWT sign key + mass assignment in the JWT -> read arbitrary customer sensitive/PII data
Fully found by Claude using @profundisio MCP