bug-bounty

Automate web application bug bounty workflows from recon to reporting.

1|Updated Jun 22, 2026
One-click install
npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill bug-bounty-0xhaaz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/0xhaaz/bug-bounty-toolkit/tree/main
Command: npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill bug-bounty-0xhaaz

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires subfinder, httpx, nuclei, katana, waybackurls, gau, dalfox, ffuf, anew, qsreplace, assetfinder, gf, interactsh-client, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive toolkit for professional bug bounty hunters using Claude Code, enabling them to efficiently find, validate, and report vulnerabilities in web applications.

Core Features & Use Cases

  • Full Workflow: From recon to report, covering all stages of bug bounty hunting.
  • Recon: Subdomain enumeration, live host discovery, URL crawling, nuclei scanning, and more.
  • Hunting: IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI, LLM/AI security testing.
  • Validation: 7-Question Gate, 4 validation gates, always-rejected list, conditional chain table, submission checklist.
  • Reporting: Templates for H1, Bugcrowd, Intigriti, Immunefi, CVSS 3.1, PoC generation.
  • Use Case: Imagine you have a new target and need to quickly identify and report vulnerabilities. Use this Skill to automate the entire process.

Quick Start

Use the bug-bounty skill to start a new target and perform a full recon and hunt.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate the web application security testing workflow end to end?

You can automate the web application security testing workflow from recon to report by utilizing a comprehensive bug bounty hunting toolkit that handles subdomain enumeration, vulnerability hunting, validation, and report generation.

Can I use Nuclei and Katana for vulnerability hunting within Claude Code?

Yes, you can use Nuclei and Katana for vulnerability hunting within Claude Code, as the bug bounty hunting workflow integrates external tools for recon, live host discovery, URL crawling, and automated scanning.

What is the best way to validate and report web vulnerabilities like XSS and SSRF?

The best way to validate and report web vulnerabilities like XSS and SSRF is to use a 7-Question Gate and submission checklist, ensuring findings pass validation gates before generating reports for platforms like HackerOne or Bugcrowd.

Do I need external tools like subfinder and ffuf to perform subdomain enumeration?

Yes, you need external tools like subfinder and ffuf to perform subdomain enumeration and vulnerability scanning, as the bug bounty hunting workflow requires these dependencies to automate recon and hunting stages.

How do I generate Proof of Concept and CVSS 3.1 reports for bug bounty submissions?

To generate Proof of Concept and CVSS 3.1 reports for bug bounty submissions, use the reporting templates provided by the bug bounty hunting toolkit, which support output formats for H1, Bugcrowd, Intigriti, and Immunefi.