What problem does it solve? Security researchers waste time on theoretical bugs, shallow recon, and rejected reports. This Skill provides a structured bug bounty methodology covering recon, vulnerability hunting, validation, and report writing so hunters focus on exploitable, payable findings. ## Core Features & Use Cases - Full Recon Pipeline: Subdomain enumeration, live host probing, URL collection, cloud asset discovery, and HackerOne scope retrieval using tools like subfinder, httpx, nuclei, and ffuf. - Vulnerability Hunting Checklists: Detailed testing procedures for IDOR, SSRF, XSS, SQLi, OAuth/OIDC, GraphQL, race conditions, file upload, business logic, and LLM/AI security issues, including bypass tables and A-to-B bug chaining methods. - Validation & Reporting: A 7-Question Gate to kill weak findings, CVSS 3.1 scoring guidance, and report templates by vulnerability class. - Use Case: Starting on a new HackerOne program, use the Skill to pull the program scope, run the standard recon pipeline, hunt IDOR variants across API endpoints with two test accounts, then validate and write a submission-ready report. ## Quick Start Use the bug-bounty skill to start recon and plan a hunting session for the target program example.com on HackerOne.