bb-methodology

Identify and prove vulnerabilities using a non-linear 5-phase bug bounty workflow.

1|1|Updated Mar 24, 2026
One-click install
npx skills add https://github.com/guib1/red-team-docker --skill bb-methodology
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/guib1/red-team-docker/tree/main/pentest-lab/.agents/skills/bug-bounty/skills/bb-methodology
Command: npx skills add https://github.com/guib1/red-team-docker --skill bb-methodology

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Helps security teams and bug bounty hunters orchestrate a comprehensive, non-linear vulnerability assessment workflow to maximize findings while minimizing waste.

Core Features & Use Cases

  • Mindset-driven workflow guides researchers through critical thinking, anomaly detection, and goal-oriented testing.
  • 5-phase non-linear flow enables flexible navigation across Recon, Mapping, Finding, Proving, and Reporting with fast retreat and pivot options.
  • Escalation & gadget chaining supports rapid triage and crafting impactful reports to maximize payout potential.

Quick Start

Begin by defining targets, mapping the app, and then proceeding through the 5-phase workflow to identify and prove vulnerabilities.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a non-linear bug bounty workflow and how does it help find vulnerabilities?

A non-linear bug bounty workflow enables flexible navigation across five phases: Recon, Mapping, Finding, Proving, and Reporting. It allows rapid retreat and pivot options during vulnerability assessment to maximize findings while minimizing wasted effort on diverse targets like web apps and APIs.

How do I systematically identify and prove vulnerabilities for a bug bounty report?

To identify and prove vulnerabilities systematically, navigate through Mapping, Finding, and Proving phases. This mindset-driven approach guides critical thinking and anomaly detection, ensuring you craft impactful reports with demonstrated impact for maximum payout potential.

Can I use this 5-phase vulnerability assessment workflow for both web apps and APIs?

Yes, the 5-phase vulnerability assessment workflow is applicable to bug bounty hunters across diverse targets, ranging from web apps to APIs. It guides mindset, mapping, testing, proving impact, and reporting for comprehensive security coverage.

What's the best way to structure a pentest report to maximize bug bounty payouts?

To maximize bug bounty payouts, structure your pentest report using the Reporting phase, which emphasizes safe disclosure practices and escalation support. This ensures actionable, high-quality findings that demonstrate proven impact through gadget chaining and robust documentation.

Why does my bug bounty hunting process produce low-quality or unactionable findings?

Bug bounty hunting produces low-quality findings when it lacks disciplined phase navigation and robust documentation. Applying a structured 5-phase workflow ensures safe disclosure practices and comprehensive vulnerability assessment, resulting in actionable, high-quality findings.