One-click install
npx skills add https://github.com/infantesromeroadrian/arca-agent --skill bb-methodology-infantesromeroadrian
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/infantesromeroadrian/arca-agent/tree/main/template/skills/bb-methodology
Command: npx skills add https://github.com/infantesromeroadrian/arca-agent --skill bb-methodology-infantesromeroadrian

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

The Skill addresses the challenge of navigating the complex process of bug bounty hunting, providing a structured approach to streamline the workflow and enhance the effectiveness of security researchers.

Core Features & Use Cases

  • 5-Phase Workflow: A structured, non-linear workflow for bug bounty hunting, guiding researchers through reconnaissance, mapping, discovery, exploitation, and validation.
  • Critical Thinking Framework: A mindset guide for security research, including principles for thinking like an attacker, understanding developer psychology, and applying multiple perspectives.
  • Use Case: For security researchers or bug bounty hunters looking to improve their efficiency and effectiveness by adopting a systematic approach to identifying and reporting vulnerabilities.

Quick Start

Execute the bb-methodology skill with the command 'bb-methodology'.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured bug bounty hunting workflow for web application security testing?

A structured bug bounty hunting workflow guides security researchers through reconnaissance, mapping, discovery, exploitation, and validation phases to systematically identify and report vulnerabilities.

How do I improve my critical thinking framework for security testing and vulnerability assessment?

Improve your critical thinking framework for security testing by adopting an attacker mindset, understanding developer psychology, and applying multiple perspectives to uncover vulnerabilities that automated scanners miss.

Can I use a non-linear workflow for vulnerability assessment on web applications?

Yes, you can use a non-linear workflow for vulnerability assessment that allows you to pivot between reconnaissance, mapping, and exploitation phases dynamically as new attack surfaces are discovered during web application testing.

What's the best way to approach manual security testing and exploitation during bug bounty hunting?

The best way to approach manual security testing is to combine a structured 5-phase hunting workflow with critical thinking principles, ensuring thorough reconnaissance and validation before reporting vulnerabilities.

Do I need prior security research experience to use a 5-phase bug bounty methodology?

While prior experience helps, a 5-phase bug bounty methodology is designed to streamline the complex hunting process, providing a structured framework that enhances efficiency for both new and experienced security researchers.