bb-local-toolkit

Automate bug bounty workflows for reconnaissance, hunting, validation, and reporting.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill bb-local-toolkit-kisilev13
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-local-toolkit
Source: https://github.com/Kisilev13/Hermes-Agent-Workspace/tree/main/skills/bb-local-toolkit
Command: npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill bb-local-toolkit-kisilev13

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires subfinder, assetfinder, nuclei, ffuf, kiterunner, cloudenum, trufflehog, gitleaks, xssstrike, secretfinder, sqlmap, subzy, arjun, paramspider, kiterunner, semgrep, gau, dalfox, interactsh-client, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a comprehensive bug bounty workflow, addressing the challenges of reconnaissance, learning, hunting, validation, and reporting in bug bounty programs.

Core Features & Use Cases

  • Reconnaissance Automation: Automates the process of discovering subdomains, live hosts, URLs, and identifying common security issues.
  • Pre-Hunt Learning: Facilitates the learning process by reading disclosed reports and identifying potential vulnerabilities.
  • Vulnerability Hunting: Offers various strategies for identifying vulnerabilities such as IDOR, SSRF, XSS, and more.
  • Validation: Provides guidelines for validating findings and writing detailed reports.
  • Use Case: Ideal for bug bounty hunters and security professionals looking to streamline their workflow and increase the efficiency of their bug hunting process.

Quick Start

Start the bug bounty workflow using the bb-local-toolkit skill by executing the command: bb-local-toolkit start.

Frequently Asked Questions about bb-local-toolkit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty reconnaissance and vulnerability hunting?

Bug bounty reconnaissance and vulnerability hunting can be automated by executing a workflow that discovers subdomains, identifies live hosts, and runs vulnerability scanners. This skill orchestrates the entire process from initial recon to detailed reporting.

What is the best way to streamline a bug bounty workflow end-to-end?

Streamlining a bug bounty workflow requires automating reconnaissance, pre-hunt learning from disclosed reports, vulnerability hunting, validation, and reporting. This toolkit integrates these phases to increase the efficiency of your security assessment process.

Can I use nuclei and sqlmap for automated vulnerability detection in a single workflow?

Yes, you can use nuclei and sqlmap together within an automated vulnerability detection workflow. This skill coordinates multiple security tools including subfinder, ffuf, and sqlmap to discover and validate common security issues.

Does this bug bounty toolkit support finding IDOR, SSRF, and XSS vulnerabilities?

Yes, this bug bounty toolkit supports finding IDOR, SSRF, and XSS vulnerabilities. It offers various hunting strategies for these specific security flaws and integrates tools like dalfox and sqlmap to assist in identifying them.

How do I validate bug bounty findings and generate detailed security reports?

To validate bug bounty findings and generate detailed security reports, this skill provides built-in guidelines for confirming vulnerabilities and automates the creation of comprehensive reports for your security assessment results.

Do I need to install external security tools before using this bug bounty automation toolkit?

Yes, you need to install external security tools before using this bug bounty automation toolkit. It requires dependencies like subfinder, nuclei, ffuf, sqlmap, and semgrep to execute its comprehensive vulnerability hunting and reconnaissance workflow.