bug-bounty-hunting

Orchestrates an end-to-end bug bounty workflow from recon to validated, ready-to-submit reports.

1|Updated May 25, 2026
One-click install
npx skills add https://github.com/ctahok/hermes-bug-bounty-skills --skill bug-bounty-hunting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty-hunting
Source: https://github.com/ctahok/hermes-bug-bounty-skills/tree/main/bug-bounty-hunting
Command: npx skills add https://github.com/ctahok/hermes-bug-bounty-skills --skill bug-bounty-hunting

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

It helps you avoid aimless probing and consistently produce valid, impact-backed bug bounty results by guiding each stage from recon through validation and reporting.

Core Features & Use Cases

  • 5-phase, non-linear methodology: Mode confirmation, mindset, reconnaissance, active hunting, and validation/triage.
  • Chain-oriented exploitation planning: Systematically escalate from a signal bug (A) to compounding impact (B/C) instead of treating findings as isolated issues.
  • Hard gates for proof quality: A “7-Question Gate” and pre-submission checks that kill low-confidence or out-of-scope claims before writing reports.
  • Target selection framework: Crown-jewel targeting (auth, financials, upload/import, APIs, cloud metadata surfaces) to maximize payout probability.

Quick Start

Use the command: "Start bug bounty hunting for this target by confirming engagement type, running recon, selecting 1-2 vuln classes, and then applying the 7-question gate before drafting any report."

Frequently Asked Questions about bug-bounty-hunting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a bug bounty exploit chain from a single vulnerability signal?

To build a bug bounty exploit chain, you systematically escalate from an initial signal bug (A) to compounding impact (B/C) instead of treating findings as isolated issues. This approach ensures your vulnerability triage demonstrates maximum severity for higher payouts.

What is the best way to run reconnaissance for web and API bug bounty hunting?

The best way to run reconnaissance for bug bounty hunting is using a 5-phase, non-linear methodology that applies crown-jewel targeting. This focuses active testing on high-value surfaces like authentication, financials, APIs, and cloud metadata to maximize payout probability.

How do you validate vulnerability evidence before submitting a bug bounty report?

You validate vulnerability evidence by applying a strict 7-Question Gate and performing dedup checks before drafting reports. This evidence hygiene process kills low-confidence or out-of-scope claims early, ensuring your final report chains are impact-backed and credible.

Can I use a structured methodology for cloud-facing and authentication bug bounty tasks?

Yes, you can use a structured methodology for cloud-facing and authentication bug bounty tasks. The workflow applies stepwise execution discipline, confirming engagement modes and selected vulnerability classes before active testing to ensure disciplined, targeted hunting.

Why does my bug bounty hunting lack consistent, valid results?

Your bug bounty hunting lacks consistent results because of aimless probing without impact validation. By guiding each stage from reconnaissance through targeted testing and evidence-driven triage, you avoid wasted effort and consistently produce valid, impact-backed findings.

When should I not use an automated approach for vulnerability triage?

You should not use a purely automated approach for vulnerability triage when you need hard gates for proof quality. Complex exploit chains require manual A→B clustering and evidence validation to decide what findings to keep or kill before submission.