bug-bounty

Automate end-to-end bug bounty operations from recon to reporting.

3.3k|507|Updated May 5, 2026
One-click install
npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bug-bounty-elementalsouls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/bug-bounty
Command: npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bug-bounty-elementalsouls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Complete bug bounty programs by automating recon, learning, hunting, validation, and reporting, reducing manual toil and ensuring thorough coverage.

Core Features & Use Cases

  • Full pipeline: Recon -> Learn -> Hunt -> Validate -> Report, enabling end-to-end engagement management.
  • A->B bug hunting technique guidance, chain formation, and standardized reporting templates.
  • Pre-hunt intelligence, threat modeling, and role-based gatekeeping to improve quality and efficiency.

Quick Start

Describe your target in plain English to trigger the Bug Bounty Master workflow and start recon, learning, hunting, and reporting.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty recon and vulnerability reporting workflows?

Automate bug bounty operations by orchestrating structured phases from recon to standardized reporting, covering vulnerability discovery, risk assessment, and chain-based exploitation. Describe your target in plain English to trigger the full pipeline.

What is chain-based exploitation in security testing and how does it work?

Chain-based exploitation in security testing links multiple vulnerabilities together to maximize impact. This workflow provides A->B bug hunting technique guidance and chain formation, supported by threat modeling and 7-Question Gate checks for validation.

Can I use this for bug bounty hunting on cloud services and web apps?

Yes, this bug bounty workflow supports engagements on both web apps and cloud services. It automates proactive reconnaissance, vulnerability discovery, and standardized reporting templates across these environments.

How to validate vulnerabilities and maintain evidence hygiene during security testing?

Validate vulnerabilities during security testing by applying role-based gatekeeping and 7-Question Gate checks. The workflow enforces threat modeling and evidence hygiene throughout the validation phase to ensure accurate risk assessment.

What's the best way to structure bug bounty reports from proactive reconnaissance?

Structure bug bounty reports using standardized reporting templates generated after the recon, learn, hunt, and validate phases. This ensures complete coverage of threat modeling, CVE seed patterns, and chain-based exploitation evidence.

Do I need prior CVE seed patterns to start vulnerability discovery?

No, prior CVE seed patterns are not required to start. The workflow integrates CVE seed patterns internally during the learning and hunting phases to guide vulnerability discovery and chain formation automatically.