bb-methodology

Structures bug bounty hunting into five phases from recon to reporting.

3|Updated Nov 12, 2025
One-click install
npx skills add https://github.com/cmndcntrlcyber/rtpi --skill bb-methodology-cmndcntrlcyber
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/cmndcntrlcyber/rtpi/tree/main/knowledge_seed/bug_hunter_skills/bb-methodology
Command: npx skills add https://github.com/cmndcntrlcyber/rtpi --skill bb-methodology-cmndcntrlcyber

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the common challenges faced by bug bounty hunters, such as inefficient workflows, lack of a structured approach, and poor identification of critical vulnerabilities.

Core Features & Use Cases

  • 5-Phase Non-Linear Workflow: Guides hunters through the process of recon, mapping, vulnerability discovery, proofing, and reporting.
  • Critical Thinking Framework: Enhances analytical skills by considering developer psychology, anomaly detection, and "What-If" experiments.
  • Use Case: Before beginning a bug bounty session, load this Skill to define the target, choose vuln classes, and focus your hunting efforts effectively.

Quick Start

Load the bb-methodology skill to start your bug bounty hunt with a structured approach.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured methodology for bug bounty hunting?

A structured bug bounty hunting methodology uses a 5-phase non-linear workflow covering recon, mapping, vulnerability discovery, proofing, and reporting. This approach prevents inefficient workflows by guiding hunters through critical thinking techniques to identify and exploit vulnerabilities effectively.

How do I optimize my vulnerability hunting workflow?

Optimize vulnerability hunting workflows by applying critical thinking frameworks that consider developer psychology, anomaly detection, and What-If experiments. Loading this methodology before a session helps define the target, choose vulnerability classes, and focus exploitation efforts effectively.

How does critical thinking improve security research and threat intelligence gathering?

Critical thinking improves security research by analyzing developer psychology and detecting anomalies during target mapping. This framework encourages What-If experiments to uncover edge cases, transforming standard threat intelligence gathering into a structured process for identifying critical vulnerabilities.

Can I use this bug bounty workflow for any target platform?

Yes, this bug bounty workflow is platform-agnostic and applies to any target. The 5-phase non-linear methodology focuses on universal vulnerability discovery and critical thinking techniques rather than relying on specific platform dependencies or tools.

What's the best way to start a bug bounty session?

The best way to start a bug bounty session is to load this methodology and immediately define your target, choose specific vulnerability classes, and structure your hunting efforts. This prevents inefficient workflows and poor identification of critical vulnerabilities.

When should I use a non-linear workflow for vulnerability discovery?

Use a non-linear workflow for vulnerability discovery when standard sequential approaches fail to uncover critical bugs. This methodology allows hunters to cycle between recon, mapping, and discovery phases while applying critical thinking to adapt to target behaviors dynamically.