What problem does it solve?
This Skill addresses the complex and multifaceted problem of bug bounty hunting, providing a comprehensive workflow for reconnaissance, learning, hunting, validation, and reporting vulnerabilities.
Core Features & Use Cases
- Comprehensive Reconnaissance: Subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit.
- Pre-Hunt Learning: Disclosed reports, tech stack research, mind maps, threat modeling.
- Vulnerability Hunting: IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI.
- A-to-B Bug Chaining: IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth.
- Language-Specific Grep: JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap.
- Reporting: 7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, submission checklist.
- Use Case: Ideal for bug bounty hunters looking to streamline their workflow and improve their chances of discovering and reporting high-quality vulnerabilities.
Quick Start
Start the bug bounty workflow by running the 'bug-bounty' skill and follow the full pipeline: Recon -> Learn -> Hunt -> Validate -> Report.