$npx skillfedfor your agent

bbot

OSINT automation for hackers.

With conditionsPyPI SecurityReleased Jul 202677.0K downloads / moAGPL-3.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — bbot-3.0.1-py3-none-any.whl
v3.0.1 · released 2026-07-21 · Python <3.15,>=3.10 · 36 runtime deps: ansible-core, ansible-runner, asndb, beautifulsoup4, blastdns, blasthttp, cachetools, cloudcheck

Yes, if you need comprehensive reconnaissance automation for security testing or bug bounties. BBOT is actively maintained, has low install friction, and offers a large module ecosystem. However, verify that AGPL-3.0 licensing aligns with your use case, and be aware that the 36 runtime dependencies add complexity. Not suitable for minimal, lightweight scanning—consider simpler tools if you only need basic subdomain enumeration.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later.
  • DNS resolver performance depends on unfiltered resolvers in /etc/resolv.conf; adding more resolvers significantly speeds up scans.
  • Low friction install via pip or pipx.

License · maintenance · safety

AGPL-3.0 (agpl) — Licensed under AGPL-3.0, which requires that any modifications or derivative works distributed must also be released under AGPL-3.0. Suitable for internal security work and open-source projects, but commercial use or proprietary modifications require careful licensing review.

last release 2026-07-21 (24 days) · last repo commit 2026-08-14 · 10,362 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 77,007 downloads/mo, #14,560 on PyPI

Verify before relying

pip install bbot

from bbot.scanner import Scanner

scan = Scanner("evilcorp.com", presets=["subdomain-enum"])
for event in scan.start():
    print(event)
  • Whether the claimed 20-50% subdomain discovery advantage over other tools holds across different domain sizes and configurations.
  • Performance characteristics and resource requirements for large-scale scans (e.g., scanning entire IP ranges or thousands of targets).
  • Compatibility and stability of the 36 runtime dependencies in production environments.
Same gist for agents: .md · .json

What it is and what it does

BBOT is a modular security scanner designed for reconnaissance, bug bounties, and attack surface management. It combines passive API sources with active techniques like DNS brute-forcing and web crawling to discover subdomains, email addresses, web vulnerabilities, and other reconnaissance data. The tool accepts multiple target types—domains, IPs, IP ranges, URLs, emails, and more—and can run preset scanning profiles (subdomain-enum, spider, email-enum, web, kitchen-sink) or be customized with individual modules.

As a Python library or CLI tool, BBOT outputs findings to multiple formats including Neo4j, databases, messaging platforms, and standard files. It emphasizes automation and scale: recursive DNS mutations, NLP-powered subdomain generation, web screenshots, and integration with Ansible for dependency management. The active maintenance, large dependency footprint, and AGPL license reflect its role as a comprehensive framework rather than a lightweight utility.

Use it for

  • Enumerate subdomains of a target domain using passive APIs and recursive DNS brute-force with target-specific mutations.
  • Crawl a website to extract emails, URLs, and other reconnaissance data while respecting session integrity.
  • Scan an entire IP range or multiple targets in parallel to map an organization's attack surface.
  • Integrate reconnaissance into a security workflow via Python API for synchronous or asynchronous event processing.
  • Output scan results directly to Neo4j, Elasticsearch, or messaging platforms for real-time analysis and alerting.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need comprehensive reconnaissance automation for security testing or bug bounties.

BBOT is actively maintained, has low install friction, and offers a large module ecosystem. However, verify that AGPL-3.0 licensing aligns with your use case, and be aware that the 36 runtime dependencies add complexity. Not suitable for minimal, lightweight scanning—consider simpler tools if you only need basic subdomain enumeration.

Install

bbot on PyPI

Before you install

Low friction install via pip or pipx. Actively maintained with a recent release (24 days old) and strong community signal (10362 GitHub stars). Requires Python 3.10 or later and brings in 36 runtime dependencies including Ansible, DNS tools, and web frameworks—manageable for a comprehensive security scanner.

Requires Python 3.10 or later. DNS resolver performance depends on unfiltered resolvers in /etc/resolv.conf; adding more resolvers significantly speeds up scans.

License in practice

Licensed under AGPL-3.0, which requires that any modifications or derivative works distributed must also be released under AGPL-3.0. Suitable for internal security work and open-source projects, but commercial use or proprietary modifications require careful licensing review.

Quickstart

pip install bbot

from bbot.scanner import Scanner

scan = Scanner("evilcorp.com", presets=["subdomain-enum"])
for event in scan.start():
    print(event)

Verify before relying

  • Whether the claimed 20-50% subdomain discovery advantage over other tools holds across different domain sizes and configurations.
  • Performance characteristics and resource requirements for large-scale scans (e.g., scanning entire IP ranges or thousands of targets).
  • Compatibility and stability of the 36 runtime dependencies in production environments.

Package facts

LicenseAGPL-3.0 agpl
Python supportSupports the current Python release <3.15,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
36 packages
ansible-coreansible-runnerasndbbeautifulsoup4blastdnsblasthttpcachetoolscloudcheckdeepdiffdnspythonidnajinja2lxmlmmh3orjsonpippsutilpuremagicpycryptodomepydanticpyjwtpyyamlpyzmqradixtargetregexsetproctitlesocksiotabulatetldextractunidecode
MaintenanceActively maintained 24 days since the last release
Last repo commit
First released
Downloads77,007 / month, #14,560 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Operating System :: POSIX :: LinuxTopic :: Security

Evidence: bbot-3.0.1-py3-none-any.whl

Tags

Capabilities
subdomain enumeration scannerosint reconnaissance automationbug bounty recon toolattack surface mappingweb vulnerability scannerdns brute force toolsecurity scanning framework
Topics
osint-frameworkattack-surface-mappingsecurity-automation
PyPI keywords
attack-surfaceautomationbugbountyclicommand-line-toolhackingintelligenceneo4josintosint-frameworkosint-toolpentestingpythonpython-libraryreconrecursionscannersecurity-toolssubdomain-enumerationsubdomain-scannersubdomainsthreat-intel

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “subdomain enumeration scanner”

  • bbotBBOT is a multipurpose reconnaissance and vulnerability scanner that…
  • python3-nmapWraps nmap port scanner commands as Python methods, converting…
  • unifi-discoveryDiscovers Unifi devices on a network using async I/O, returning…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also cisco-ai-skill-scanner · cisco-ai-mcp-scanner · scanoss · sherlock-project · kingfisher-bin · bloodhound · zaproxy · semgrep · pysonar · python3-nmap