What problem does it solve? Security researchers often lose time to unstructured hunting, false-positive findings, and misaligned engagement expectations. This Skill provides a master orchestrator that combines a five-phase non-linear hunting workflow (Recon, Mapping, Discovery, Escalation, Reporting) with a critical-thinking framework and strict false-positive prevention rules, so every session starts with a defined goal and every finding survives triage. ## Core Features & Use Cases - Engagement Mode Confirmation: Distinguishes bug bounty, red team, pentest, and internal audit engagements before testing begins, so findings match what the platform actually accepts. - Five-Phase Non-Linear Workflow: Routes between Recon, Mapping, Vulnerability Discovery, Prove & Escalate, and Validate & Report phases with explicit navigation rules for when you get stuck. - False-Positive Discipline Gates: Enforces marker discipline, body-diff verification, statistical sampling for timing claims, and a shell-loop ban to kill findings that would be rejected as N/A. - Use Case: Starting a new bug bounty target, you confirm the engagement type, define a session goal (e.g., IDOR leading to account takeover), follow the phase routing and tool tables, then run the 7-question validation gate before writing a platform-formatted report. ## Quick Start Use the bb-methodology skill to plan my bug bounty session on this target and tell me which phase to start in.