One-click install
npx skills add https://github.com/uphiago/recon-skills --skill bb-methodology-uphiago
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/bb-methodology
Command: npx skills add https://github.com/uphiago/recon-skills --skill bb-methodology-uphiago

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty hunters and penetration testers often waste time on low-impact work, produce findings that get rejected for not matching platform rules, and struggle to chain small bugs into high-severity reports. This Skill eliminates that inefficiency by providing a standardized, field-validated workflow and critical thinking framework used by top 1% hunters to maximize high-impact findings per hour of effort.

Core Features & Use Cases

  • 5-Phase Non-Linear Workflow: Structured recon, mapping, vulnerability discovery, proof, and reporting phases that adapt when you get stuck, so you never waste time on dead ends.
  • Engagement Type Validation Gate: Hard rules to distinguish bug bounty, red team, pentest, and audit scopes upfront, eliminating rejected findings caused by misaligned report criteria.
  • Critical Thinking Framework: Developer psychology reverse-engineering, anomaly detection, and What-If experiment techniques to find unique bugs that automated scanners miss.
  • False Positive Prevention Discipline: Marker discipline, body-diff rules, and statistical sampling requirements to ensure every finding you report holds up to triage review.
  • Use Case: A hunter starting a new SaaS bug bounty target can use this Skill to avoid wasting 2 days on recon for out-of-scope assets, chain a low-impact IDOR to a full account takeover, and format their report to meet H1 triage standards on the first submission.

Quick Start

Use the bb-methodology skill at the start of your next authorized bug bounty or penetration testing session to confirm your engagement type, set a daily hunting goal, and follow the structured workflow to find and report valid high-impact bugs.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure bug bounty hunting sessions to avoid wasting time on dead ends?

Bug bounty hunting sessions require a 5-phase non-linear workflow covering recon, mapping, vulnerability discovery, proof, and reporting to adapt dynamically and eliminate low-yield testing dead ends.

Why do my bug bounty findings get rejected during triage review?

Bug bounty findings get rejected when misaligned with platform rules or failing false positive prevention discipline, requiring engagement type validation gates and marker discipline to meet triage standards.

How do I chain low-impact vulnerabilities into high-severity bug bounty reports?

Vulnerability escalation chaining combines low-impact bugs like IDOR into full account takeovers using critical thinking frameworks, developer psychology reverse-engineering, and What-If experiment techniques.

What is the best way to prevent false positives in penetration testing engagements?

False positive prevention in penetration testing requires marker discipline, body-diff rules, and statistical sampling to ensure every reported finding holds up to strict triage review.

Does this workflow apply to red team and audit engagements or just bug bounty platforms?

This workflow applies to authorized bug bounty, red team, and penetration testing engagements, using hard validation gates to distinguish scope types and align report criteria upfront.

How do I find unique vulnerabilities that automated scanners miss during recon?

Finding unique vulnerabilities that automated scanners miss requires critical thinking frameworks including anomaly detection, developer psychology reverse-engineering, and structured What-If experiment techniques.