What problem does it solve? Security researchers waste time figuring out where tools, wordlists, and clones are installed locally, and often submit theoretical findings that get rejected. This Skill provides the complete bug bounty workflow — recon, learning, hunting, validation, and reporting — while also resolving local install paths for tools like ffuf, dalfox, ghauri, trufflehog, and SecLists wordlists. ## Core Features & Use Cases - Full Hunt Pipeline: Covers recon (subdomain enumeration, fingerprinting, HackerOne scope retrieval), pre-hunt intelligence (disclosed reports, threat modeling), vulnerability hunting across 20+ classes (IDOR, SSRF, XSS, SQLi, OAuth, race conditions, LLM/AI security), and report writing with validation gates. - Local Tool Resolution: Locates installed binaries, wordlists, and cloned repositories on the local machine so commands run without path guessing. - Bug Chaining Methodology: Provides A-to-B chain tables (IDOR to auth bypass, SSRF to cloud metadata, XSS to account takeover) and bypass tables for SSRF, open redirect, and file upload. - Use Case: A hunter targeting a HackerOne program asks for the recon pipeline; the Skill runs subfinder, httpx, and nuclei using locally installed paths, then guides IDOR testing with two-account methodology and drafts a report passing the 7-Question Gate. ## Quick Start Ask the assistant to run the bug bounty recon pipeline against an in-scope target using the locally installed tools and wordlists.