What problem does it solve?
This Skill provides a comprehensive toolkit for bug bounty hunters, addressing the entire workflow from reconnaissance to report generation, ensuring a systematic and efficient approach to identifying and validating vulnerabilities.
Core Features & Use Cases
- Comprehensive Recon: Offers tools for subdomain enumeration, asset discovery, fingerprinting, and source code audit.
- Pre-Hunt Learning: Provides resources for disclosed reports, tech stack research, mind maps, and threat modeling.
- Vulnerability Hunting: Focuses on IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, and agentic AI.
- LLM/AI Security Testing: Incorporates AI features for chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, and ASI01-ASI10.
- A-to-B Bug Chaining: Offers methodologies for chaining vulnerabilities for maximum impact.
- Bypass Tables: Provides tables for SSRF IP bypass, open redirect bypass, and file upload bypass.
- Language-Specific Grep: Includes grep patterns for JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, and Rust unwrap.
- Reporting: Offers guidelines for the 7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, and submission checklist.
Quick Start
Use the bb-local-toolkit skill to initiate a bug bounty engagement on a target.