bug-bounty

Orchestrate reconnaissance, vulnerability research, and exploit chain development for authorized bug bounty programs.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill bug-bounty-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/bug-bounty
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill bug-bounty-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) components.

What problem does it solve?

This skill addresses the inefficiency of fragmented bug bounty hunting by providing a unified, impact-driven workflow that guides operators from initial reconnaissance to high-value exploit chaining and professional reporting.

Core Features & Use Cases

  • Impact-Driven Hunting: Prioritizes crown-jewel assets and business logic flaws over theoretical vulnerabilities.
  • Cluster Hunting: Implements the A-to-B signal method to identify and chain related vulnerabilities for higher payouts.
  • Professional Reporting: Includes a 7-question gate and CVSS 3.1 templates to ensure reports meet the standards of top-tier bug bounty programs.

Quick Start

Use the bug bounty skill to initiate a crown-jewel hunt for the target domain example.com.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a bug bounty hunt to prioritize high-value vulnerabilities?

Bug bounty hunting workflows can prioritize high-value vulnerabilities by targeting crown-jewel assets and business logic flaws over theoretical issues. This approach uses an A-to-B signal method to identify and chain related vulnerabilities, maximizing impact and payout potential.

What is the A-to-B signal method for exploit chaining in vulnerability research?

The A-to-B signal method is a cluster hunting technique in vulnerability research that identifies and chains related vulnerabilities. By mapping connections between individual flaws, it builds comprehensive exploit chains that demonstrate real business impact.

How do I create professional vulnerability reports for bug bounty programs?

Professional vulnerability reporting requires passing a 7-question gate and utilizing CVSS 3.1 templates. This ensures reports demonstrate clear business impact and meet the strict submission standards of top-tier bug bounty programs.

Does this offensive security workflow support API and cloud application pentesting?

Yes, the offensive security pipeline supports web, API, cloud, and mobile application security testing. It orchestrates reconnaissance, vulnerability research, and exploit development across these environments within authorized bug bounty programs.

What is the best way to map attack surfaces during reconnaissance for bug bounty?

The best way to map attack surfaces is through systematic target mapping during reconnaissance. This process identifies crown-jewel assets and business logic entry points, enabling a structured pipeline from initial reconnaissance to exploit chain development.

Why focus on business logic analysis instead of theoretical vulnerabilities in pentesting?

Focusing on business logic analysis during pentesting uncovers impact-driven flaws that theoretical vulnerability scanning misses. This cluster hunting approach chains related exploits to demonstrate actual business impact, leading to higher bug bounty payouts.