bug-bounty

Execute structured bug bounty reconnaissance, vulnerability testing, and report generation.

4|Updated Mar 12, 2026
One-click install
npx skills add https://github.com/Bsh13lder/Lazy-Claw --skill bug-bounty-bsh13lder
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/Bsh13lder/Lazy-Claw/tree/main/claude-bug-bounty/skills/bug-bounty
Command: npx skills add https://github.com/Bsh13lder/Lazy-Claw --skill bug-bounty-bsh13lder

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive framework for conducting bug bounty assessments, from reconnaissance to reporting, streamlining the process of identifying and verifying vulnerabilities.

Core Features & Use Cases

  • Reconnaissance: Automates subdomain enumeration, URL collection, and reconnaissance of target assets.
  • Vulnerability Hunting: Guides systematic testing for IDOR, SSRF, XSS, SQLi, and more, based on industry best practices.
  • Reporting & Validation: Assists in compiling detailed, impact-focused vulnerability reports with evidence and verification steps.
  • Use Case: A security researcher uses this Skill to perform a full bug bounty engagement, from target initial mapping to crafting validated disclosure reports.

Quick Start

Input the target domain and accept the default scanning parameters to start reconnaissance, then review the findings for potential bug points.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate subdomain enumeration and reconnaissance for bug bounty testing?

Bug bounty reconnaissance automates subdomain enumeration and target asset mapping by executing structured scripts. You input a target domain to collect URLs and discover potential attack surfaces efficiently.

What is the best way to test for IDOR, SSRF, and XSS vulnerabilities during a pentest?

Vulnerability hunting for IDOR, SSRF, XSS, and SQLi is guided by systematic testing procedures based on industry best practices. This ensures thorough verification of bugs on target systems.

How do I compile a vulnerability report with impact analysis and verification steps?

Vulnerability reporting compiles detailed, impact-focused reports by validating discovered bugs and structuring evidence. This assists security professionals in crafting validated disclosure documentation.

Can I execute a full bug bounty engagement from initial mapping to disclosure without external dependencies?

Yes, this complete bug bounty workflow executes structured reconnaissance, vulnerability testing, and report generation procedures. It operates without external dependencies to assist in discovering and verifying bugs.

Does this security testing framework require manual parameter configuration for target scanning?

No, you input the target domain and accept default scanning parameters to start reconnaissance. The structured workflow then guides you through automated target asset discovery and testing.

How do I validate discovered vulnerabilities before submitting a bug bounty report?

Vulnerability validation confirms discovered bugs by executing verification steps and compiling evidence. This structured reporting process ensures impact-focused disclosure documentation for security professionals.