bb-methodology

Orchestrate a five-phase offensive security workflow for bug bounty engagements.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill bb-methodology-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/bb-methodology
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill bb-methodology-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the problem of aimless, inefficient bug bounty hunting by providing a structured, non-linear framework that prevents rabbit holes and ensures high-impact findings.

Core Features & Use Cases

  • 5-Phase Workflow: Guides you through Recon, Mapping, Discovery, Proof, and Reporting with clear exit criteria.
  • Critical Thinking Framework: Teaches you to reverse-engineer developer psychology and perform What-If experiments to find logic flaws.
  • Quality Gates: Includes strict discipline rules for marker usage, body-diff verification, and statistical sampling to eliminate false positives.

Quick Start

Initiate the bug bounty methodology to define your target goals and select the appropriate hunting phase for your current session.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure bug bounty hunting to avoid rabbit holes and find high-impact vulnerabilities?

A bug bounty methodology prevents rabbit holes by enforcing a structured, non-linear five-phase workflow with strict exit criteria. It guides hunters through Recon, Mapping, Discovery, Proof, and Reporting to consistently identify high-impact vulnerabilities.

What is the best way to eliminate false positives during vulnerability research?

To eliminate false positives during vulnerability research, apply validation discipline using marker usage, body-diff verification, and statistical sampling. These quality gates enforce rigorous reproduction standards across multiple toolsets to verify findings.

How do you reverse-engineer developer psychology to find logic flaws in red teaming?

To find logic flaws during red teaming, apply a critical thinking framework that uses What-If experiments to reverse-engineer developer psychology. This methodology identifies underlying logic flaws by analyzing developer assumptions and predicting edge-case application behaviors.

Can pentesting workflows adapt to non-linear engagement types without strict reproduction standards?

Pentesting workflows using this methodology require structured engagement-type confirmation and rigorous reproduction standards. The non-linear workflow demands validation across multiple toolsets to maintain accuracy and eliminate false positives across different engagement types.

Does this security methodology require specific dependencies or toolsets to function?

This security methodology operates without dependencies and integrates across multiple toolsets. It functions as an orchestrator for existing pentesting and red teaming tools, applying validation discipline rather than requiring specific software installations.