What problem does it solve?
This Skill provides a comprehensive toolkit for professional bug bounty hunters using Claude Code, enabling them to efficiently find, validate, and report vulnerabilities in web applications.
Core Features & Use Cases
- Full Workflow: From recon to report, covering all stages of bug bounty hunting.
- Recon: Subdomain enumeration, live host discovery, URL crawling, nuclei scanning, and more.
- Hunting: IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI, LLM/AI security testing.
- Validation: 7-Question Gate, 4 validation gates, always-rejected list, conditional chain table, submission checklist.
- Reporting: Templates for H1, Bugcrowd, Intigriti, Immunefi, CVSS 3.1, PoC generation.
- Use Case: Imagine you have a new target and need to quickly identify and report vulnerabilities. Use this Skill to automate the entire process.
Quick Start
Use the bug-bounty skill to start a new target and perform a full recon and hunt.