bug-bounty-hunting

Automate bug bounty workflows from target selection to vulnerability report submission.

1|Updated May 13, 2026
One-click install
npx skills add https://github.com/hanifahhanundz/bug-bounty-hunting-agent --skill bug-bounty-hunting-hanifahhanundz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty-hunting
Source: https://github.com/hanifahhanundz/bug-bounty-hunting-agent/tree/main
Command: npx skills add https://github.com/hanifahhanundz/bug-bounty-hunting-agent --skill bug-bounty-hunting-hanifahhanundz

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires hackerone, bugcrowd, intigriti, yeswehack, and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill streamlines the bug bounty hunting process, automating target selection, reconnaissance, vulnerability identification, and report submission, significantly reducing manual effort and time.

Core Features & Use Cases

  • Target Selection: Automate the identification of bounty programs with active monetary rewards.
  • Reconnaissance: Automate the passive reconnaissance of target systems using various tools and techniques.
  • Code Audit: Automate the identification of vulnerabilities in source code using automated scanning and manual analysis.
  • Report Submission: Provide templates and guidelines for submitting detailed vulnerability reports to bounty programs.

Quick Start

Load this skill into your AI agent and ask it to audit the codebase for vulnerabilities in the 'target-repo' repository.

Frequently Asked Questions about bug-bounty-hunting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty hunting workflows for open-source projects?

Automate bug bounty hunting by using AI-assisted target selection, passive reconnaissance, source code analysis, vulnerability identification, and report submission to significantly reduce manual effort and time.

What is AI-assisted vulnerability hunting and how does it work for source code analysis?

AI-assisted vulnerability hunting uses automated scanning and manual analysis techniques to identify vulnerabilities in source code. AI agents audit the codebase, locate security flaws, and generate detailed vulnerability reports for bounty programs.

Can I use this skill to submit vulnerability reports to HackerOne and Bugcrowd?

Yes, you can submit vulnerability reports to HackerOne, Bugcrowd, Intigriti, and YesWeHack. The skill provides templates and guidelines for generating and submitting detailed vulnerability reports to these bounty programs.

How do I start a code audit for vulnerabilities in a specific target repository?

To start a code audit, load this skill into your AI agent and ask it to audit the codebase for vulnerabilities in the target repository. The agent will perform automated scanning and source code analysis to identify security issues.

Does this skill support automated target selection for bounty programs with monetary rewards?

Yes, this skill automates target selection by identifying bounty programs that offer active monetary rewards. It streamlines the initial phase of bug bounty hunting by pinpointing open-source projects with available payouts.

What are the limitations of using AI agents for passive reconnaissance in bug bounty hunting?

AI agents require source code analysis and report generation capabilities to perform passive reconnaissance. While automation reduces manual effort, the quality of vulnerability identification depends heavily on the AI agent's ability to accurately audit code.