What problem does it solve?
This Skill helps you plan and execute bug bounty work end-to-end by focusing on real, impact-producing vulnerabilities and reducing wasted time on theoretical or non-exploitable findings.
Core Features & Use Cases
- Impact-first triage (7-Question Gate): prevents writing up weak or non-actionable “could theoretically” issues and enforces “proves harm” testing.
- Recon → Learn → Hunt → Validate → Report workflow: provides structured phase guidance, including scope verification, recon pipelines, and validation steps before reporting.
- Cluster hunting and A-to-B chaining: teaches how to expand from a first confirmed bug signal into adjacent vulnerabilities for higher payout chains.
- Vuln-class methodology support: includes checklists and bypass ideas for common web/security classes (IDOR, SSRF, XSS, OAuth/OIDC, GraphQL, SQLi, file upload, race conditions, cache poisoning, and more).
- Source-code audit & language-specific grep patterns: helps audit repositories for dangerous sinks/patterns across multiple languages.
- LLM/AI security testing guidance: covers prompt/indirect injection, chat history IDOR, system prompt extraction risks, and agentic AI attack classes.
- Reporting guidance: supports human-tone writeups, templates by vulnerability class, validation gates, PoC expectations, and structured submission checklists.
Quick Start
Use the bug-bounty skill for a new target to run a full Recon → Learn → Hunt → Validate → Report flow with scope checks, impact confirmation, and chain hunting.