bb-methodology

Organize bug bounty hunting across five non-linear workflow phases.

1|Updated Jun 15, 2026
One-click install
npx skills add https://github.com/venkatas/vikramaditya --skill bb-methodology-venkatas
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/venkatas/vikramaditya/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/venkatas/vikramaditya --skill bb-methodology-venkatas

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Helps security researchers organize complex bug bounty hunts by providing a unified, non-linear workflow and a strategic mindset that keeps you aligned with goals across multiple phases.

Core Features & Use Cases

  • 5-phase non-linear workflow (RECON → MAPPING & ANALYSIS → VULNERABILITY DISCOVERY → PROVE & ESCALATE → VALIDATE & REPORT) that allows free movement between phases based on findings.
  • Routes to all other skills based on the current hunting phase to guide decision making and task routing.
  • Use-case scenarios include starting a new bug bounty program, switching targets mid-hunt, or asking "what should I do next?" to get next-step guidance.

Quick Start

Activate the workflow by telling me your current hunting phase and target so I can route steps accordingly.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a non-linear workflow for bug bounty hunting?

A non-linear bug bounty workflow allows free movement between phases like RECON, VULNERABILITY DISCOVERY, and VALIDATE & REPORT based on findings, rather than enforcing a strict sequential process. It keeps your hunting strategy aligned with goals across multiple phases.

How do I organize a bug bounty hunt across multiple phases?

You organize a bug bounty hunt by routing guidance through a 5-phase workflow orchestrator covering RECON, MAPPING & ANALYSIS, VULNERABILITY DISCOVERY, PROVE & ESCALATE, and VALIDATE & REPORT. Tell the orchestrator your current phase and target to get next-step guidance accordingly.

Can I switch targets mid-hunt and still maintain my workflow mindset?

Yes, you can switch targets mid-hunt while maintaining your workflow mindset. The orchestrator allows free movement between phases based on new findings and provides structured activation instructions to realign your strategy with the new target.

What's the best way to decide what to do next during security research?

The best way to decide what to do next during security research is to ask the workflow orchestrator for next-step guidance. It evaluates your current hunting phase and routes decision-making tasks to the appropriate skill for actionable steps.

Does the bug bounty methodology workflow require any specific dependencies?

No, the bug bounty methodology workflow requires no specific dependencies or components to function. It relies on frontmatter-defined names, descriptions, and safety checks to provide structured activation instructions independently.

When should I move from vulnerability discovery to proving and escalating?

You should move from vulnerability discovery to proving and escalating when you have identified a potential security flaw and need to validate its impact. The non-linear workflow allows you to transition phases freely based on your findings.