bb-methodology

Orchestrate phase-based bug bounty hunts with critical-thinking decision rules.

1|Updated Apr 18, 2026
One-click install
npx skills add https://github.com/jellaharshith/SWIFT --skill bb-methodology-jellaharshith
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/jellaharshith/SWIFT/tree/main/swift/skills/cbh/skills/bb-methodology
Command: npx skills add https://github.com/jellaharshith/SWIFT --skill bb-methodology-jellaharshith

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It solves getting stuck or taking the wrong approach during a bug bounty hunt by providing a non-linear, phase-based workflow plus a critical-thinking framework to decide what to do next.

Core Features & Use Cases

  • Engagement-mode gating (finding validity discipline): Forces an explicit engagement type decision up front so you only treat appropriate outcomes as deliverables for that program type.
  • Non-linear 5-phase hunting workflow orchestration: Guides you through Recon → Mapping → Find → Prove → Report, with clear rules for jumping backward when stuck.
  • Critical thinking toolkit for higher signal: Applies developer-psychology reasoning, anomaly detection, and What-If experiments to separate top performers from generic scanning.
  • Escalation and validation readiness: Emphasizes proving maximum business impact and running a structured validation gate before writing up.

Quick Start

Tell the AI you are starting (or switching targets in) a bug bounty hunt and ask it to run the bug bounty start workflow by confirming your engagement type first, then walking through the 5 phases to decide your next testing step.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a non-linear bug bounty hunting methodology and how does it work?

A non-linear bug bounty hunting methodology orchestrates movement across Recon, Mapping, Discovery, Prove/Escalate, and Validate/Report phases. It applies decision rules for jumping backward when stuck and uses critical-thinking frameworks to choose the next testing experiment.

How do I structure a bug bounty workflow to avoid taking the wrong testing approach?

Structure a bug bounty workflow by applying engagement-mode gating upfront to confirm target validity, then progress through a 5-phase hunting workflow. Use critical-thinking frameworks like developer-psychology reasoning and anomaly detection to guide next testing steps.

How do I know when to move to the validation and reporting phase of a vulnerability hunt?

Move to the validation and reporting phase after proving maximum business impact during the escalation phase. Run a structured validation gate to ensure finding validity before writing up the deliverable for the specific engagement type.

What is the best way to decide what to test next when I get stuck during a bug bounty engagement?

The best way to decide what to test next when stuck is applying a critical-thinking toolkit using What-If experiments and anomaly detection. The workflow orchestration provides clear rules for jumping backward to earlier phases like Recon or Mapping.

Does this hunting methodology work for different types of bug bounty engagement rules?

Yes, the methodology forces an explicit engagement-type confirmation at the start of a session. This finding validity discipline ensures you only treat appropriate outcomes as deliverables based on the specific program's engagement rules.

When should I start using a phase-based workflow orchestration during my vulnerability hunting?

Start using workflow orchestration at the beginning of a hunt session, when switching targets, or whenever you ask what to do next. It requires explicit goal and selection discipline to route between phases, escalation paths, and validation gates.