What problem does it solve?
Bug bounty hunters and penetration testers often waste time on low-impact work, produce findings that get rejected for not matching platform rules, and struggle to chain small bugs into high-severity reports. This Skill eliminates that inefficiency by providing a standardized, field-validated workflow and critical thinking framework used by top 1% hunters to maximize high-impact findings per hour of effort.
Core Features & Use Cases
- 5-Phase Non-Linear Workflow: Structured recon, mapping, vulnerability discovery, proof, and reporting phases that adapt when you get stuck, so you never waste time on dead ends.
- Engagement Type Validation Gate: Hard rules to distinguish bug bounty, red team, pentest, and audit scopes upfront, eliminating rejected findings caused by misaligned report criteria.
- Critical Thinking Framework: Developer psychology reverse-engineering, anomaly detection, and What-If experiment techniques to find unique bugs that automated scanners miss.
- False Positive Prevention Discipline: Marker discipline, body-diff rules, and statistical sampling requirements to ensure every finding you report holds up to triage review.
- Use Case: A hunter starting a new SaaS bug bounty target can use this Skill to avoid wasting 2 days on recon for out-of-scope assets, chain a low-impact IDOR to a full account takeover, and format their report to meet H1 triage standards on the first submission.
Quick Start
Use the bb-methodology skill at the start of your next authorized bug bounty or penetration testing session to confirm your engagement type, set a daily hunting goal, and follow the structured workflow to find and report valid high-impact bugs.