bb-methodology

Guide bug bounty hunters through a 5-phase non-linear workflow.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill bb-methodology-kisilev13
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/Kisilev13/Hermes-Agent-Workspace/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill bb-methodology-kisilev13

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive methodology for bug bounty hunters, guiding them through the entire hunting process from start to finish, ensuring they cover all bases and maximize their success rate.

Core Features & Use Cases

  • 5-Phase Workflow: A non-linear, 5-phase workflow covering Recon, Mapping & Analysis, Vulnerability Discovery, Prove & Escalate, and Validate & Report.
  • Mindset & Thinking Framework: Tools and techniques for thinking like an attacker, including critical thinking, multi-perspective analysis, and strategic thinking.
  • Navigation & Timing: Quick references for navigating the methodology, including a 20-minute rotation clock and pushback protocol.
  • Methodology Discipline: Discipline rules to prevent false positives and ensure quality findings, including marker discipline, body-diff rule, and statistical-sample rule.
  • Related Skills & Chains: Integration with related skills and chains for a seamless workflow.
  • Operator Notes: Engagement-derived additions and wisdom from real experiences.

Quick Start

Use the bb-methodology skill to initiate a new bug bounty hunting session.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a 5-phase bug bounty hunting workflow?

A 5-phase bug bounty hunting workflow breaks the process into Recon, Mapping & Analysis, Vulnerability Discovery, Prove & Escalate, and Validate & Report. This non-linear methodology helps hunters cover all bases and maximize their success rate efficiently.

How do I prevent false positives during vulnerability discovery?

To prevent false positives during vulnerability discovery, apply methodology discipline rules like marker discipline, the body-diff rule, and the statistical-sample rule. These rules ensure quality findings and prevent inaccurate vulnerability reports.

Do I need prior vulnerability analysis experience to use this bug bounty methodology?

Yes, this bug bounty methodology requires an understanding of basic vulnerability analysis principles. It targets bug bounty hunters looking to improve their efficiency and effectiveness rather than teaching foundational security concepts from scratch.

How do I stay focused and manage time during a bug bounty hunt?

To stay focused during a bug bounty hunt, use a 20-minute rotation clock and a pushback protocol. These navigation and timing tools help hunters pivot effectively and maintain strategic momentum across the non-linear workflow.

What is the best way to think like an attacker during bug bounty hunting?

The best way to think like an attacker during bug bounty hunting is to apply a critical thinking framework that includes multi-perspective analysis and strategic thinking. This mindset framework helps hunters uncover vulnerabilities that automated scanners might miss.

When should I not use a non-linear workflow for bug bounty hunting?

You should not use a non-linear workflow for bug bounty hunting if your engagement requires strict sequential compliance reporting. This methodology prioritizes dynamic critical thinking and rapid pivoting over rigid, linear step-by-step execution.