bb-local-toolkit

Execute a bug bounty pipeline for reconnaissance, vulnerability research, and automated security testing.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill bb-local-toolkit-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-local-toolkit
Source: https://github.com/pdparchitect/rook/tree/main/skills/bb-local-toolkit
Command: npx skills add https://github.com/pdparchitect/rook --skill bb-local-toolkit-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the fragmentation of the bug bounty workflow by providing a unified, systematic pipeline for reconnaissance, vulnerability research, and reporting, ensuring hunters focus on high-impact findings rather than theoretical bugs.

Core Features & Use Cases

  • Systematic Hunting: Implements a 5-phase non-linear workflow covering everything from initial recon to final report generation.
  • Advanced Methodology: Provides expert-level frameworks for cluster hunting, A->B bug chaining, and developer-empathy-based threat modeling.
  • Use Case: Use this skill to conduct a full-stack security audit on a new target, systematically mapping the attack surface, identifying potential IDOR or SSRF chains, and validating findings against the 7-Question Gate before submission.

Quick Start

Use the bb-local-toolkit skill to perform a full reconnaissance and vulnerability scan on the target domain example.com.

Frequently Asked Questions about bb-local-toolkit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a systematic bug bounty hunt on a new target?

A systematic bug bounty hunt requires a non-linear workflow covering initial reconnaissance, vulnerability research, and automated security testing. This skill executes a 5-phase pipeline to map the attack surface and identify high-impact findings rather than theoretical bugs.

What is A->B bug chaining and how does it work during vulnerability research?

A->B bug chaining is an advanced methodology that combines multiple lower-severity vulnerabilities into a critical exploit chain. This skill provides expert-level frameworks to validate cluster hunting findings and systematically chain exploitation paths.

Can I use this skill for API auditing and cloud infrastructure review?

Yes, API auditing and cloud infrastructure review are supported use cases. The skill applies systematic bug discovery and automated security testing to web application security assessments across these full-stack environments.

What's the best way to validate IDOR and SSRF findings before reporting?

Validating IDOR and SSRF findings requires passing a 7-Question Gate to ensure developer empathy and accurate threat modeling. This skill systematically maps the attack surface and validates potential chains against this gate before submission.

Does this skill generate professional-grade vulnerability reports automatically?

Yes, professional-grade vulnerability reporting is part of the comprehensive pipeline. The final phase of the systematic workflow generates reports focused on high-impact findings and chain exploitation details.