bb-methodology

Guide bug bounty hunting through a structured 5-phase workflow.

1|Updated Jun 22, 2026
One-click install
npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill bb-methodology-0xhaaz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/0xhaaz/bug-bounty-toolkit/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill bb-methodology-0xhaaz

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill unit provides a comprehensive methodology for bug bounty hunting, guiding users through a structured 5-phase workflow and a critical thinking framework to identify and validate vulnerabilities.

Core Features & Use Cases

  • 5-Phase Workflow: A non-linear, 5-phase approach to bug bounty hunting, including Recon, Mapping & Analysis, Vulnerability Discovery, Prove & Escalate, and Validate & Report.
  • Critical Thinking Framework: Combines developer psychology, anomaly detection, and What-If experiments to separate top hunters from the rest.
  • Navigation & Timing: Quick reference for non-linear navigation and a 20-minute rotation clock to stay productive.

Quick Start

Start a new bug bounty hunting session by running the bb-methodology skill with the target domain.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured bug bounty hunting methodology?

A structured bug bounty hunting methodology provides a 5-phase workflow covering Recon, Mapping & Analysis, Vulnerability Discovery, Prove & Escalate, and Validate & Report to systematically identify web application vulnerabilities.

How do I start bug bounty hunting with a critical thinking framework?

Start bug bounty hunting by applying critical thinking through developer psychology, anomaly detection, and What-If experiments, running a target domain through the 5-phase workflow to guide vulnerability discovery and validation.

What's the best way to stay productive during security testing sessions?

Stay productive during security testing by utilizing a 20-minute rotation clock and non-linear navigation approach, allowing you to systematically pivot across targets without losing focus during the vulnerability assessment process.

Can I use this vulnerability assessment workflow for any web application target?

Yes, the vulnerability assessment workflow supports web application targets, but it requires a deep understanding of web application vulnerabilities and security testing to effectively execute the 5-phase hunting process.

How does developer psychology improve vulnerability discovery?

Developer psychology improves vulnerability discovery by analyzing how developers think and code, enabling hunters to predict anomalies and design targeted What-If experiments that uncover hidden security flaws.

Why should I use a non-linear workflow for bug bounty hunting?

A non-linear workflow allows dynamic navigation across the five phases, enabling hunters to pivot between Recon, Vulnerability Discovery, and Validation based on real-time findings rather than being locked into a rigid sequence.