bb-methodology

Orchestrate a five-phase bug-bounty workflow across recon, mapping, discovery, proving, and reporting.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/chatbotkit/rook --skill bb-methodology-chatbotkit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/chatbotkit/rook/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/chatbotkit/rook --skill bb-methodology-chatbotkit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

bb-methodology provides a master orchestrator for bug bounty sessions, unifying the 5-phase non-linear hunting workflow with a critical thinking framework to help analysts switch targets, stay on track, and decide what to do next.

Core Features & Use Cases

  • Unified workflow: a non-linear 5-phase model that supports recon, mapping, finding, proving, and reporting.
  • Mindset framework: developer psychology, anomaly detection, and What-If experiments integrated into decision-making.
  • Routing & orchestration: routes to other skills based on the current hunting phase.
  • Use Case: when starting a new bug-bounty engagement or when asking what to do next, use this to orient the investigation.

Quick Start

Start by confirming the engagement type, then follow the five-phase hunting workflow to guide your bug-hunting session.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a bug bounty workflow to stay organized across different phases?

A bug bounty workflow can be structured using a five-phase non-linear model covering recon, mapping, vulnerability discovery, proving impacts, and reporting. This orchestrator routes tasks to the appropriate skill set based on the current hunting phase, keeping assessments organized and compliant.

What is the best way to decide what to do next during a bug bounty hunt?

To decide what to do next during a bug bounty hunt, use a master orchestrator that integrates a critical thinking framework with developer psychology and anomaly detection. It evaluates your current hunting phase and routes you to the appropriate next action or skill set.

How does a mindset framework improve vulnerability discovery and security testing?

A mindset framework improves vulnerability discovery by integrating developer psychology, anomaly detection, and What-If experiments into decision-making. This approach helps analysts identify deviations from expected application behavior and uncover hidden security flaws during the finding phase.

Can I switch targets during an active bug bounty engagement without losing track of progress?

Yes, you can switch targets during an active engagement without losing track. The unified non-linear workflow supports dynamic target switching and phase routing, ensuring you maintain context and can reorient your investigation across recon, mapping, finding, proving, and reporting.

What guardrails and compliance checks are implemented during a bug bounty assessment?

Guardrails implemented during an assessment include role-based checks and escalation patterns. These ensure thorough, compliant security testing by routing to appropriate skill sets based on the current hunting phase and enforcing strict assessment boundaries.

When should I use an orchestrated bug bounty methodology instead of ad-hoc testing?

Use an orchestrated bug bounty methodology when starting a new engagement or when you need to orient a stalled investigation. It replaces ad-hoc testing by providing a repeatable five-phase workflow with critical thinking guardrails to ensure thorough, compliant assessments.