bb-methodology

Orchestrates bug bounty hunting with a non-linear 5-phase workflow and critical-thinking framework.

2|Updated Apr 11, 2025
One-click install
npx skills add https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda --skill bb-methodology-carlos-reyes-utp
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda/tree/main/.agent/skills/bb-methodology
Command: npx skills add https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda --skill bb-methodology-carlos-reyes-utp

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It solves the problem of getting stuck, wandering, or reporting incorrectly during a bug bounty hunting session by providing a structured, non-linear workflow plus a critical-thinking mindset to decide what to do next.

Core Features & Use Cases

  • Engagement Mode Confirmation (Phase 0 gate): Ensures you align your definition of “finding” to bug bounty vs red team vs pentest vs internal audit before you begin, reducing wasted effort and mis-scoped reports.
  • Non-Linear 5-Phase Hunting Workflow: Recons, maps, finds, proves/escalates, then validates/reports while allowing you to move backward when stuck or when new information appears.
  • Mindset & Decision Framework: Guides critical thinking across trust boundaries, anomaly detection, multi-perspective review, and what-if experiments to differentiate real attack paths from noise.
  • False-Positive Prevention Rules: Enforces quality gates like marker discipline, body-diff confirmation, sample-size requirements for timing claims, and stronger reproduction expectations for higher severities.

Quick Start

Use bb-methodology at the START of a new hunt and whenever you ask “what should I do next” by first confirming the engagement mode, then selecting the phase targets based on what you’ve found so far.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I decide what to do next during a bug bounty hunt?

To decide your next move in bug bounty hunting, apply a non-linear 5-phase workflow that routes between recon, mapping, finding, proving, and validating, allowing backward phase movement when new information appears or exploitation gets blocked.

What is engagement mode gating in vulnerability research?

Engagement mode gating is a Phase 0 confirmation step that aligns your finding definition to bug bounty, red team, pentest, or internal audit before you begin, reducing wasted effort and mis-scoped security reports.

How do I prevent false positives when testing for security vulnerabilities?

Prevent false positives in vulnerability testing by enforcing quality gates like marker discipline, body-diff confirmation, sample-size requirements for timing claims, and stronger reproduction expectations for higher severity reports.

Can I use a critical thinking framework to differentiate real attack paths from noise?

Yes, you can differentiate real attack paths from noise by applying a critical thinking framework that guides analysis across trust boundaries, anomaly detection, multi-perspective review, and what-if experiments during your hunting workflow.

What should I do when I get stuck or blocked during a bug bounty exploitation attempt?

When blocked during bug bounty exploitation, move backward through the non-linear 5-phase workflow to recon or mapping phases to gather new information, then apply the critical-thinking framework to identify alternative testing paths.

Does this bug bounty workflow methodology work for internal security audits?

Yes, the methodology supports internal audits through its engagement mode confirmation gate, which explicitly aligns your finding criteria and workflow behavior to internal audit standards before recon and validation phases begin.