Skip to content
Good for Bots

Crowdsourced bug bounty platform connecting security researchers with companies

Click badge to copy

Changed your site? Run a new scan.

Claim to rescan

Claiming is free. Verify ownership to request a rescan after deploying your changes.

Unclaimed listings are checked automatically every 90 days.

Good for Bots report

HuntBug scores 64 of 100: 39 of the 50 base points, half of the agent layer, no penalties.

Earned

39 of the 50 base points above the line, half of the agent layer below it.

64

3 prompts away

Copy them below ↓

29

Still open

Behind the checks below, with prompts in Pro.

7
Penalties0
How scoring works · current methodology →

Through a bot’s eyes

“HuntBug is a crowdsourced bug bounty platform that connects security researchers with companies running vulnerability and security testing programs.”

Simulated from the response GoodForBotsBot received on , not a live answer from any AI assistant.

What it can read, and what stays hidden →

What a bot can read

A language model reading this input learns about HuntBug's value propositions for both security researchers and corporate security teams. The homepage and markdown twin provide platform statistics, live bug submission feeds, feature lists for both user types, a sample program directory with asset counts and triage SLAs, and community leaderboards. The provided llms.txt file adds concrete details about the platform's reputation scoring system (such as points awarded for different severity levels), links to legal and policy pages, and contact email addresses for sales, support, and security. The JSON-LD schema confirms organizational details. While the text outlines features, workflows, and payout methods, specific pricing numbers for corporate plans are omitted from the main page text.

What stays hidden

The exact pricing tiers and fees for companies wanting to list a program are not visible on the homepage, although the llms.txt file references a pricing page URL. Specific terms of service, detailed compliance documentation, and full program rules for individual listings require visiting subpages.

What is HuntBug?

HuntBug is a crowdsourced bug bounty platform designed to connect security researchers with companies that run vulnerability disclosure and bounty programs. It serves two distinct audiences: researchers who want to hunt for bugs, track personal reputation, and earn payouts via wire, Wise, or USDC; and companies that need to run public or private bounty programs, manage live asset scopes, handle duplicate checks, and process tax forms and escrow payouts.

Read more →

The platform provides a live submission feed, triage workflows, directory listings of active programs, leaderboards, and daily security quests.

3 prompts, 29 points

For Claude Code, Cursor or Codex. The score moves after the next scan.

+12.5score from 64 to 77

Serve Markdown at its own URL

Markdown is served on request, but not at any URL a crawler would find on its own.

Read prompt

+10.7score from 77 to 88

Mark up content so a reader can find it

None of the 4 pages read pass. The homepage is barely structured: No <main> element and nothing carrying role="main".

Read prompt

+5score from 88 to 93

State a position on AI crawlers

robots.txt names no AI crawlers, so every operator has to guess.

Read prompt

Pro

13 more prompts in Pro

Pro shows a prompt for every fix and drafts your llms.txt and robots.txt. It never changes the score.

$9 once, per listingSee Pro

Deployed your fixes? Rescan to update your score →

Ready-made files

Pro drafts these for this site.

Pro

A ready-made llms.txt and robots.txt

Pro drafts both files for HuntBug from its scan, keeps only links and rules our parsers can verify, and hands them over ready to review and publish. It never changes the score.

See Pro

Select a check to see what we found and how it is graded.

Readable base

39.3 / 50

Passes.

3.6 of 3.6 points.

robots.txt is valid, with 1 user-agent group.

Passes.

8.9 of 8.9 points.

Sitemap declared in robots.txt, listing 18 URLs.

Passes.

8.9 of 8.9 points.

All 4 pages read pass. The homepage describes itself to machines as Organization in valid schema.org JSON-LD.

Fails.

0 of 10.7 points.

None of the 4 pages read pass. The homepage is barely structured: No <main> element and nothing carrying role="main".

Passes.

8.9 of 8.9 points.

7 of 7 assessed homepage navigation links expose usable destinations.

Passes.

4.5 of 4.5 points.

66 of 66 assessed homepage links and buttons have a nonempty accessible name.

Not applicable.

0 of 0 points.

No applicable form fields were observed in the homepage HTML.

Passes.

2.7 of 2.7 points.

66 of 66 assessed homepage controls and role declarations meet the static role, state and relationship checks.

Passes.

1.8 of 1.8 points.

3 of 4 pages read pass. The homepage declares no canonical URL, in a Link header or a <link> element.

Agent layer

25 / 50

Passes.

11.3 of 11.3 points.

/llms.txt is well formed: 16 links across 3 sections.

Half passes.

3.8 of 7.5 points.

/llms.txt is partly descriptive: it has no summary blockquote under the title.

Prompt in Pro →
Fails.

0 of 12.5 points.

Markdown is served on request, but not at any URL a crawler would find on its own.

Passes.

10 of 10 points.

All 4 pages read pass. The homepage serves markdown on `Accept: text/markdown`.

Fails.

0 of 5 points.

robots.txt names no AI crawlers, so every operator has to guess.

Fails.

0 of 2.5 points.

No usage declaration found in robots.txt or the final successful homepage response header.

Prompt in Pro →

Penalties

− 0

Passes.

Penalty: 0 of 15 points.

Our crawler reaches the page without being challenged.

Passes.

Penalty: 0 of 20 points.

Nothing on the homepage tells a crawler to skip it or to withhold its snippet.

Passes.

Penalty: 0 of 25 points.

The captured homepage HTML contains 788 content words; completeness is not assessed.

Passes.

Penalty: 0 of 25 points.

robots.txt allows every known search and user-fetch crawler to reach the homepage.

Passes.

Penalty: 0 of 10 points.

The homepage is served over HTTPS and returns HTTP 200.

Passes.

Penalty: 0 of 3 points.

The homepage provides both a non-empty title and meta description.

Passes.

Penalty: 0 of 3 points.

The homepage is reached in 0 redirects.

Passes.

Penalty: 0 of 3 points.

The homepage reached a plain crawler in 680 ms.

Agent capabilities

0 of 10 · no points

Each one found adds +1 to the badge.

Not applicable.

Adds +1 to the badge when found.

No API catalog published.

Not applicable.

Adds +1 to the badge when found.

No /auth.md published.

Not applicable.

Adds +1 to the badge when found.

No AI Catalog published, so no MCP server card can be discovered.

Not applicable.

Adds +1 to the badge when found.

No A2A Agent Card at /.well-known/agent-card.json, and none listed in an AI Catalog.

Not applicable.

Adds +1 to the badge when found.

No usable Agent Skills index was found at either well-known path or in the AI Catalog.

Not applicable.

Adds +1 to the badge when found.

No WebMCP declarations were found in the collected HTML or inline scripts. External scripts were not inspected.

Not applicable.

Adds +1 to the badge when found.

No Web Bot Auth key directory at /.well-known/http-message-signatures-directory.

Not applicable.

Adds +1 to the badge when found.

No HTTP 402 payment challenge on the homepage or robots.txt, and no manifest at /.well-known/x402.

Not applicable.

Adds +1 to the badge when found.

No ACP discovery declaration established at /.well-known/acp.json.

Not applicable.

Adds +1 to the badge when found.

No UCP discovery declaration established at /.well-known/ucp.

Access & usage policy

Who can read this page, and for what purpose?

GoodForBotsBot received HTTP 200 via a direct request. No indexing restriction was observed in the supported homepage directives.

Sampled URL: https://huntbug.com/

Declared crawling rules

No matching refusal for this URL was found for the listed identities.

Sources and scope: declared crawling rules
  • Declared allow · Scan admission

    • GoodForBotsBot/1.0 (+https://goodforbots.com/bot)

    The recorded robots admission decision allowed our crawler to proceed.

    GoodForBotsBot admission along the homepage request chain

    https://huntbug.com/

    robots.txt is present and valid

  • Declared allow · robots.txt

    • goodforbotsbot (Site diagnostics)
    • * (Default robots group)
    • oai-searchbot (ai-search)
    • claude-searchbot (ai-search)
    • perplexitybot (ai-search)
    • mistralai-index (ai-search)
    • kimi-searchbot (ai-search)
    • amzn-searchbot (ai-search)
    • meta-webindexer (ai-search)
    • exasearchbot (ai-search)
    • aiwebindex (ai-search)
    • duckassistbot (ai-search)
    • shapbot (ai-search)
    • yandexadditional (ai-search)
    • yandexadditionalbot (ai-search)
    • gptbot (ai-training)
    • claudebot (ai-training)
    • mistralai-training (ai-training)
    • kimibot (ai-training)
    • ai2bot (Unknown)
    • applebot-extended (ai-training)
    • webzio-extended (ai-training)
    • chatgpt-user (user-fetch)
    • claude-user (user-fetch)
    • perplexity-user (user-fetch)
    • mistralai-user (user-fetch)
    • kimi-user (user-fetch)
    • amzn-user (user-fetch)
    • diffbot-user (user-fetch)
    • firecrawlagent (extraction)
    • webzio (extraction)
    • meta-externalfetcher (user-fetch, agent)
    • google-extended (ai-training, grounding)
    • meta-externalagent (ai-training, product-improvement)
    • amazonbot (ai-training, product-improvement)
    • ccbot (open-dataset, ai-training)
    • googlebot (search)
    • bingbot (search)

    No matching refusal for this URL in the applicable robots group. This is a declaration, not an access test.

    Acquisition of https://huntbug.com/

    https://huntbug.com/robots.txt

    User-agent: *
    allow: /

    robots.txt is present and validStates a position on AI crawlersAllows search and user-fetch crawlers

Observed access

GoodForBotsBot received HTTP 200 via a direct request.

Sources and scope: observed access
Coverage and interpretation
  • Crawler coverage includes the registered identities and up to 50 user-agent entries from robots.txt. Source excerpts and detail groups are bounded; omissions are labelled.
  • Observed access describes GoodForBotsBot only. Other crawler entries describe declared rules, not tests of those operators' access.
  • Coverage is the sampled homepage response and collected robots.txt files. No indexing or citation is guaranteed. Usage preferences are declarations, not a legal determination of permission.
  • This explanation adds no points or penalties. Any score effects belong to the linked checks.
  • AIPREF and Content Signals keep their own definitions. AIPREF search can include processing used exclusively for search; training preferences are not a blanket ruling on every search process.

In its category

6th of 24 in Developer Tools & APIs

Whole category →
  1. 1Good for Botsgoodforbots.com
  2. 2Chrome Goldminechromegoldmine.com
  3. 6HuntBug · this reporthuntbug.com

The prompts above would take HuntBug to 93, 3rd in its category.

To the prompts ↑

Category average 56. The percentile appears once the catalogue holds a few hundred sites.

Scanned

Site profile

Login
Detected
A sign-in or sign-up link
API
Not established
Commerce
Not established

It decides which conditional checks apply. “Not established” means no proof in what we read, not proof of absence.

Scan details

Every scan is kept. Pro draws the history as a chart →

Scanned
3 Oct 2026
Rubric
0.9.0
Requests
22
Fetched
153.3 KB
Took
25.7 s
Homepage
680 ms · direct
Pages read
4
robots.txt
allowed
Which pages the scan read

The homepage and up to three pages from the sitemap and homepage links. Structured data, page structure, Markdown negotiation and typed links check each page read and take the median page; other checks read the homepage.

  • Homepagealways read
  • /pricingpricing · linked from the homepage · from the sitemap · read
  • /blogcollection · linked from the homepage · from the sitemap · read
  • /aboutabout · linked from the homepage · from the sitemap · read

More like HuntBug:Developer Tools & APIsSecurity & PrivacyB2BDevelopers

Same category

goodforbots.com

Evaluates website readability for AI crawlers and language models with a scoring rubric

Same category

appbanana.io

Real human testers for Android apps to pass Google Play closed testing requirements

Same category

agentskills.codes

Open registry of installable skills and instruction files for AI coding assistants

Same category

vavahost.com

Fast web hosting with cPanel, LiteSpeed, NVMe storage, and 1-click WordPress

Same category

egmatic.com

No-code 2D game editor with a built-in ship layer for developers

Same category

contacts.wawebplus.com

Chrome extension to export WhatsApp Web group contacts and phone numbers to Excel or CSV