bb-local-toolkit

Coordinate end-to-end bug bounty workflows across recon, learning, hunting, validation, and reporting.

3.3k|507|Updated May 5, 2026
One-click install
npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bb-local-toolkit-elementalsouls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-local-toolkit
Source: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/bb-local-toolkit
Command: npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bb-local-toolkit-elementalsouls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Recon, learn, hunt, validate, and report for bug bounty engagements are unified into a repeatable, end-to-end workflow that reduces wasted effort and accelerates findings.

Core Features & Use Cases

  • Comprehensive bug bounty lifecycle coverage: from reconnaissance and learning through to hunting, validation, and reporting.
  • Template-driven reporting and threat modeling to standardize findings across targets and programs.
  • Reusable playbooks for chain hunting, evidence hygiene, and CVSS-aligned disclosures.

Quick Start

Run the bb-local-toolkit with your target and follow the Recon → Learn → Hunt → Validate → Report workflow to begin bug hunting.

Frequently Asked Questions about bb-local-toolkit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate a complete bug bounty workflow from recon to reporting?

To coordinate a complete bug bounty workflow, you can use an end-to-end orchestration toolkit that unifies reconnaissance, learning, hunting, validation, and reporting into a single repeatable process with built-in guardrails and evidence hygiene.

Can I generate CVSS-aligned bug bounty reports for web apps, APIs, and cloud targets?

Yes, you can generate CVSS-aligned bug bounty reports for web apps, APIs, and cloud targets using template-driven reporting features that standardize findings and disclosures across different programs and target types.

What is the best way to structure threat modeling and chain hunting for bug bounties?

The best way to structure threat modeling and chain hunting is by using reusable playbooks that provide standardized patterns for identifying complex vulnerabilities and maintaining evidence hygiene throughout the validation process.

Does this bug bounty toolkit require external dependencies or components to run?

No, this bug bounty toolkit does not require external dependencies or components to run, allowing you to execute the full reconnaissance, hunting, validation, and reporting workflow directly within your local environment.

How do I start hunting for vulnerabilities using a template-driven bug bounty process?

To start hunting with a template-driven bug bounty process, provide your target and follow the sequential Recon, Learn, Hunt, Validate, and Report workflow to systematically identify and document vulnerabilities.