bb-methodology

Guide bug bounty and red-team operations through a structured five-phase workflow.

Updated Jul 1, 2026
One-click install
npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill bb-methodology-bpnrockstar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/bpnrockstar/UnifiedBugHunter/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill bb-methodology-bpnrockstar

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the challenges of bug bounty and red-team operations by providing a structured methodology framework to guide and optimize the entire hunting process.

Core Features & Use Cases

  • Comprehensive Methodology: Offers a 5-phase non-linear workflow that combines critical thinking with a structured approach to hunting.
  • Critical Thinking Framework: Includes domains like critical thinking, multi-perspective analysis, tactical thinking, strategic thinking, and AI-assisted analysis.
  • Vulnerability Discovery and Escalation: Provides guidelines and tools for discovering vulnerabilities and escalating them based on their impact.
  • Reporting and Validation: Assists in crafting precise and impactful security reports for submission.
  • Recon and Mapping: Offers techniques for maximizing attack surface and understanding the application's structure.

Quick Start

Use the bb-methodology skill to kick off a new hunting session by running bb-methodology start.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured bug bounty methodology and why do I need one?

A structured bug bounty methodology provides a non-linear workflow combining critical thinking with tactical analysis to guide vulnerability discovery. You need it to optimize hunting sessions, maximize attack surface coverage, and systematically escalate discovered vulnerabilities based on impact.

How do I start a bug bounty hunting session using a methodology framework?

To start a bug bounty hunting session, initiate the framework to access a 5-phase non-linear workflow. This guides you through initial recon, application mapping, vulnerability discovery, impact escalation, and precise security report generation for submission.

Can I use this methodology for red teaming operations and security assessments?

Yes, you can use this methodology for red teaming operations and in-depth security assessments. It is specifically tailored for security professionals performing comprehensive security audits, providing frameworks for multi-perspective analysis and strategic thinking during operations.

Does this bug bounty framework assist with vulnerability validation and report generation?

Yes, this bug bounty framework assists with vulnerability validation and report generation by providing structured tools. It helps you craft precise and impactful security reports that accurately communicate the discovered vulnerabilities and their escalated impact for submission.

What is the best way to maximize attack surface coverage during security audits?

The best way to maximize attack surface coverage during security audits is using dedicated recon and mapping techniques. This methodology framework provides specific techniques to thoroughly map and understand the target application's structure before active exploitation.

When should I not use a non-linear workflow for vulnerability discovery?

You should not use a non-linear workflow for vulnerability discovery when conducting strictly compliance-driven audits requiring rigid, sequential test execution. This framework emphasizes critical thinking and tactical flexibility, which may not align with highly standardized, checklist-based assessment requirements.