bb-methodology

Guide bug bounty hunting through a five-phase non-linear workflow.

3|Updated Jul 6, 2026
One-click install
npx skills add https://github.com/hataiit9x/Bbkit-AI --skill bb-methodology-hataiit9x
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/hataiit9x/Bbkit-AI/tree/main/ref/claude-bug-bounty/skills/bb-methodology
Command: npx skills add https://github.com/hataiit9x/Bbkit-AI --skill bb-methodology-hataiit9x

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive framework for bug bounty hunters, guiding them through a structured, non-linear workflow and fostering critical thinking to identify and exploit vulnerabilities effectively.

Core Features & Use Cases

  • Structured Workflow: A 5-phase, non-linear approach to bug bounty hunting, encompassing Recon, Mapping, Vulnerability Discovery, Prove & Escalate, and Validate & Report.
  • Critical Thinking Framework: Combines developer psychology, anomaly detection, and What-If experiments to separate top hunters from the rest.
  • AI-Assisted Thinking: Integrates AI to expand hypotheses and provide fast adversarial planning, while the user handles proof and verification.

Quick Start

Use the bb-methodology skill to start your bug bounty hunting session by answering the 'Define' and 'Select' questions at the beginning of each session.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a non-linear workflow for bug bounty hunting?

A structured bug bounty workflow guides you through five non-linear phases: Recon, Mapping, Vulnerability Discovery, Prove & Escalate, and Validate & Report, ensuring comprehensive coverage of web application security vulnerabilities.

How do I start my bug bounty hunting session with AI-assisted analysis?

Start your bug bounty session by defining your scope and answering the 'Define' and 'Select' questions at the beginning, integrating AI to expand hypotheses while you handle proof and verification.

Does bug bounty hunting require a deep understanding of web application security?

Yes, effective bug bounty hunting requires a deep understanding of web application security and the ability to think like an attacker to successfully identify and exploit software vulnerabilities.

What is the best way to identify and exploit vulnerabilities in software applications?

The best way to identify and exploit vulnerabilities is by applying a critical thinking framework that combines developer psychology, anomaly detection, and What-If experiments alongside AI-assisted analysis.

How does critical thinking separate top bug bounty hunters from the rest?

Critical thinking separates top bug bounty hunters by combining developer psychology, anomaly detection, and What-If experiments to uncover hidden vulnerabilities, enhanced by AI for fast adversarial planning.

Can AI-assisted analysis handle proof and verification during bug bounty hunting?

No, AI-assisted analysis expands hypotheses and provides fast adversarial planning, but the user must handle proof and verification to validate discovered vulnerabilities during bug bounty hunting.