bug-bounty

Automate bug bounty workflows from reconnaissance to vulnerability reporting.

3|Updated Jul 6, 2026
One-click install
npx skills add https://github.com/hataiit9x/Bbkit-AI --skill bug-bounty-hataiit9x
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/hataiit9x/Bbkit-AI/tree/main/ref/claude-bug-bounty
Command: npx skills add https://github.com/hataiit9x/Bbkit-AI --skill bug-bounty-hataiit9x

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires subfinder, httpx, nuclei, pdf2image, pdfplumber, pypdf, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill automates the entire bug bounty workflow, from reconnaissance to testing, validation, and reporting, saving time and reducing errors.

Core Features & Use Cases

  • Reconnaissance: Subdomain enumeration, live host discovery, URL crawling, and nuclei scanning.
  • Vulnerability Testing: Identifies vulnerabilities like SSRF, XSS, SQLi, and others.
  • Validation: Uses a 7-Question Gate to ensure findings are actionable.
  • Reporting: Generates submission-ready reports for bug bounty platforms.

Quick Start

Use the bug-bounty skill to start hunting for vulnerabilities in the target domain 'example.com'.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty reconnaissance and vulnerability testing?

You can automate bug bounty workflows by running scripts that handle subdomain enumeration, live host discovery, URL crawling, and nuclei scanning to identify vulnerabilities like SSRF, XSS, and SQLi.

What is the 7-Question Gate for vulnerability validation?

The 7-Question Gate is a validation process in vulnerability testing that ensures findings are actionable and reduces false positives before generating submission-ready bug bounty reports.

Do I need Python tools to automate subdomain enumeration and nuclei scanning?

Yes, automating reconnaissance and vulnerability testing requires Python tools and AI integration to intelligently test domains and analyze security findings during the bug bounty workflow.

How do I generate submission-ready reports for bug bounty platforms?

You can generate submission-ready reports for bug bounty platforms by running an automated workflow that validates findings through a 7-Question Gate and compiles actionable vulnerabilities into a final document.

Can I use this automated workflow for vulnerability testing on any target domain?

Automated vulnerability testing workflows are suitable for security researchers targeting specific domains like 'example.com', provided proper authorization for bug bounty programs is obtained.