bug-bounty

Automate end-to-end bug bounty workflows from reconnaissance to reporting.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/chatbotkit/rook --skill bug-bounty-chatbotkit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/chatbotkit/rook/tree/main/skills/bug-bounty
Command: npx skills add https://github.com/chatbotkit/rook --skill bug-bounty-chatbotkit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty programs require coordination across reconnaissance, learning from disclosed reports, active hunting, validation, and reporting. This skill provides an end-to-end workflow that guides researchers through scope definition, asset discovery, vulnerability pattern hunting, and structured, presentation-ready reporting.

Core Features & Use Cases

  • Full pipeline: Recon -> Learn -> Hunt -> Validate -> Report with built-in guardrails and templates.
  • Learn from disclosed reports, threat modeling notes, and technique catalogs to identify common vulnerability classes and attack chains.
  • Apply A->B/B->C chaining to extend findings into higher-impact disclosures, backed by evidence collection, reproducible steps, and risk scoring.

Quick Start

Start a bug bounty session by loading a target and kicking off reconnaissance to enumerate assets and potential vulnerabilities.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty workflows from reconnaissance to vulnerability reporting?

You can automate end-to-end bug bounty workflows by running structured phases for recon, learning, hunting, validation, and reporting. This enforces a rigorous methodology with threat modeling and the 7-Question Gate to standardize findings across web, API, and cloud targets.

What is the best way to structure vulnerability reports for bug bounty programs?

The best way to structure vulnerability reports is using standardized templates that include evidence collection, reproducible steps, and risk scoring. This approach ensures your findings are presentation-ready and backed by rigorous validation.

How do I chain vulnerabilities to increase bug bounty impact?

You can chain vulnerabilities by applying A->B and B->C chaining techniques to extend initial findings into higher-impact disclosures. This process is supported by learning from disclosed reports and threat modeling notes to identify common attack chains.

Can I use automated threat modeling for web, API, and cloud pentesting?

Yes, you can use automated threat modeling for web, API, and cloud pentesting. The workflow guides researchers through scoped reconnaissance and asset discovery, applying threat modeling to identify vulnerability patterns across these target types.

How does the 7-Question Gate work in vulnerability validation?

The 7-Question Gate works as a built-in guardrail during vulnerability validation to enforce a rigorous methodology. It ensures that findings are properly verified through evidence collection and reproducible steps before moving to the reporting phase.

Do I need to manually enumerate assets before starting a bug bounty hunt?

No, you do not need to manually enumerate assets before starting a bug bounty hunt. You can load a target and kick off reconnaissance to automatically enumerate assets and identify potential vulnerabilities across the defined scope.