bb-methodology

Orchestrate bug-hunting sessions with a five-phase non-linear workflow.

3.3k|507|Updated May 5, 2026
One-click install
npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bb-methodology-elementalsouls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bb-methodology-elementalsouls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Master orchestrator for bug-hunting sessions, combining a five-phase non-linear workflow with a critical-thinking mindset to ensure consistent, efficient engagements and clear handoffs between phases and skills.

Core Features & Use Cases

  • Five-phase non-linear workflow (Recon, Mapping & Analysis, Vulnerability Discovery, Prove & Escalate, Validate & Report) with dynamic routing to related bb-* skills based on current phase.
  • Mindset and discipline guidance (critical thinking, what-if experiments, and escalation rules) to improve triage quality and outcomes.
  • Seamless orchestration across the Claude BugHunter toolkit, enabling rapid start-to-finish engagements without rigid linear progression.

Quick Start

Issue a session with your target scope and allow bb-methodology to orchestrate recon, mapping, discovery, proving, and reporting.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a phase-based bug bounty workflow and how does it structure vulnerability discovery?

A phase-based bug bounty workflow structures vulnerability discovery into five non-linear phases: recon, mapping and analysis, vulnerability discovery, proving and escalation, and validation and reporting. This methodology enforces critical thinking and discipline through gates like the 7-Question Gate to ensure consistent triage quality and clear phase handoffs.

How do I orchestrate a bug hunting session from recon to reporting?

You orchestrate a bug hunting session by initiating a session with your target scope, then navigating dynamically across five phases from recon to reporting. The methodology provides non-linear routing between phases, enforcing evidence hygiene and marker discipline while dynamically routing to specialized skills based on your current phase.

Can I use this methodology for red-team engagements and security assessments?

Yes, this methodology is applicable to bug bounty, red-team, and assessment engagements. It provides a complete five-phase workflow with mindset and discipline guidance, including escalation rules and critical-thinking frameworks, ensuring efficient engagements across different security testing contexts.

What's the best way to maintain discipline during vulnerability discovery and triage?

The best way to maintain discipline during vulnerability discovery is applying enforced frameworks like the 7-Question Gate, marker discipline, and evidence hygiene. These mechanisms ensure consistent critical thinking, structured what-if experiments, and clear handoffs between phases to improve triage quality and outcomes.

Does the bug hunting workflow require rigid linear progression through all phases?

No, the workflow uses non-linear navigation across its five phases. You can transition dynamically between phases based on findings, with specified entry points, phase transitions, and escalation rules enabling rapid start-to-finish engagements without forcing rigid linear progression.