bb-methodology

Guide bug bounty hunters through reconnaissance, vulnerability discovery, and reporting workflows.

4|Updated Mar 12, 2026
One-click install
npx skills add https://github.com/Bsh13lder/Lazy-Claw --skill bb-methodology-bsh13lder
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/Bsh13lder/Lazy-Claw/tree/main/claude-bug-bounty/skills/bb-methodology
Command: npx skills add https://github.com/Bsh13lder/Lazy-Claw --skill bb-methodology-bsh13lder

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill guides bug bounty hunters through a comprehensive, non-linear workflow and mindset framework, enhancing their efficiency and effectiveness in discovering security vulnerabilities.

Core Features & Use Cases

  • Workflow Guidance: Provides detailed steps for reconnaissance, mapping, vulnerability discovery, proof, and reporting.
  • Mindset & Critical Thinking: Offers mental models and analytical techniques tailored for security testing.
  • Use Case: A security researcher utilizes this Skill to structure and optimize their bug hunting efforts, ensuring thorough coverage and prioritized impact.

Quick Start

Ask the AI to explain the bug bounty workflow or request tips on critical thinking during security testing.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the standard workflow for bug bounty hunting?

The bug bounty hunting workflow covers phases from reconnaissance to mapping, vulnerability discovery, proof creation, and final reporting. It provides a non-linear structure to systematically identify security vulnerabilities.

How do I improve my critical thinking for security testing?

Critical thinking for security testing is enhanced by applying specific mental models and analytical techniques during vulnerability discovery. This approach maintains thorough discipline and strategic insight while assessing targets.

How do I structure a vulnerability report for bug bounty programs?

Vulnerability reporting is structured by following the workflow's final phase, ensuring thorough coverage and prioritized impact. This helps security researchers document findings systematically to optimize bug hunting efforts.

What mindset should I adopt for penetration testing?

The penetration testing mindset requires mental models tailored for security testing to systematically identify and exploit vulnerabilities. It emphasizes maintaining thorough discipline and strategic insight throughout the non-linear workflow.

Can I use this methodology for non-linear vulnerability discovery?

Yes, this methodology specifically guides users through a comprehensive, non-linear workflow for vulnerability discovery. It helps security researchers adapt their bug hunting efforts dynamically rather than following rigid sequential steps.