bug-bounter

Define scope, enumerate web assets, and assess vulnerabilities for bug bounty reporting.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill bug-bounter
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounter
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/bug-bounter
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill bug-bounter

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Skill provides a structured, repeatable methodology for conducting authorized bug bounty investigations, helping teams scope targets, enumerate assets, and plan responsible disclosure.

Core Features & Use Cases

  • Define scope and enumerate web assets for bug bounty testing
  • Systematically assess vulnerabilities and prepare responsible disclosure reports
  • Use Case: Apply the workflow to a scoped web target and generate actionable findings

Quick Start

Begin the engagement by outlining scope and collecting required assets to start the assessment.

Frequently Asked Questions about bug-bounter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the best way to structure a bug bounty methodology for authorized web targets?

A structured bug bounty methodology defines target scope, performs reconnaissance, enumerates web assets, assesses vulnerabilities, and prepares responsible disclosure reports. This systematic approach ensures repeatable testing and compliant vulnerability identification across authorized targets.

How do I start reconnaissance and asset enumeration for a scoped bug bounty engagement?

Start bug bounty reconnaissance by outlining the engagement scope and collecting required web assets. Systematically enumerate the target's exposed assets using recommended tools to map the attack surface before conducting active vulnerability assessment.

How does responsible disclosure workflow integrate with web vulnerability assessment?

Responsible disclosure workflow integrates with web vulnerability assessment by systematizing the reporting phase. After identifying vulnerabilities during authorized testing, you prepare structured disclosure reports to communicate actionable findings safely to the target owners.

Can I use this bug bounty playbook for OSINT challenges requiring thorough enumeration?

Yes, you can apply this bug bounty playbook to OSINT challenges that require thorough enumeration. The methodology supports open-source intelligence gathering and structured asset mapping to uncover vulnerabilities within authorized, scoped testing boundaries.

What guardrails are needed to ensure safe and compliant bug bounty testing?

Safe and compliant bug bounty testing requires strict scope definition and adherence to responsible disclosure guidelines. Guardrails include staying within authorized target boundaries, following step-by-step guidance, and using recommended tools to prevent unintended impact during vulnerability assessment.