bb-methodology

Guide bug bounty hunting through a five-phase workflow with critical thinking frameworks.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill bb-methodology-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill bb-methodology-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps you navigate and execute the complex 5-phase non-linear workflow of bug bounty hunting, ensuring a systematic approach to finding and reporting vulnerabilities.

Core Features & Use Cases

  • 5-Phase Workflow: Guidance through Recon, Mapping, Vulnerability Discovery, Proof & Escalation, and Validation & Reporting.
  • Critical Thinking Framework: Incorporates developer psychology, anomaly detection, and What-If experiments to think like an attacker.
  • Multi-Perspective Analysis: Encourages from various angles, including horizontal, vertical, data flow, time/state, and client environment.
  • Tactical and Strategic Thinking: Teaches to identify patterns, anomalies, and understand the big picture in security testing.
  • 7-Phase Comparison: Distinguishes between amateur and professional approaches to hunting.
  • Anti-Patterns: Lists common mistakes to avoid in the hunting process.

Quick Start

Start the bug bounty hunting session with the bb-methodology skill to begin the systematic approach to vulnerability assessment.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the best way to structure a bug bounty hunting workflow?

A professional bug bounty workflow uses a 5-phase non-linear approach: Recon, Mapping, Vulnerability Discovery, Proof & Escalation, and Validation & Reporting. This methodology ensures systematic vulnerability hunting and higher quality findings.

How do I apply critical thinking during vulnerability hunting?

Apply critical thinking in vulnerability hunting by incorporating developer psychology, anomaly detection, and What-If experiments. This framework helps you think like an attacker and identify hidden security flaws.

How do I perform multi-perspective analysis in security testing?

Multi-perspective analysis in security testing is performed by examining the target from horizontal, vertical, data flow, time/state, and client environment angles. This comprehensive vulnerability hunting approach ensures threats are evaluated from every possible attack vector.

What common mistakes should I avoid in bug bounty hunting?

Avoid common bug bounty hunting mistakes by reviewing documented anti-patterns. The methodology distinguishes between amateur and professional approaches to prevent typical errors in the vulnerability hunting process.

Do I need prior security research experience to use a 5-phase hunting methodology?

While prior security research experience is beneficial, the 5-phase hunting methodology provides tactical and strategic guidance for all levels. It teaches pattern identification and big picture analysis, helping both new and experienced bug bounty hunters optimize their workflow.