What problem does it solve?
This Skill provides an end-to-end bug bounty lifecycle workflow, uniting reconnaissance, learning, hunting, validation, and reporting to speed up findings and improve quality.
Core Features & Use Cases
- Recon: subdomain enumeration, asset discovery, fingerprinting, HackerOne scope awareness.
- Pre-hunt intelligence: disclosed reports review, tech stack research, mind maps, threat modeling.
- Vulnerability hunting: IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, logic flaws, GraphQL, HTTP smuggling, cache poisoning, OAuth/OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI.
- AI-assisted analysis: LLM/AI testing patterns, chatbot IDOR, prompt injection, ASCII smuggling, exfil channels, RCE via code tools.
- A-to-B bug chaining: IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, etc.
- Bypass tables and regex grep patterns: SSRF IP bypass, open redirect bypass, file upload bypass, and language-specific grep.
- Templates & reporting: 7-Question Gate, 4 validation gates, CVSS 3.1, PoC templates, and submission checklists.
Quick Start
Install and begin recon and hunting against a target using the skill's integrated commands.