bug-bounty-methodology

Guide structured bug bounty workflows from recon to report.

21|1|Updated Apr 12, 2026
One-click install
npx skills add https://github.com/woohyun212/security-skill --skill bug-bounty-methodology
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty-methodology
Source: https://github.com/woohyun212/security-skill/tree/main/bug-bounty-methodology
Command: npx skills add https://github.com/woohyun212/security-skill --skill bug-bounty-methodology

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides a structured cognitive and operational framework to run comprehensive bug bounty hunts from Recon to Report, including escalation routing and developer psychology techniques.

Core Features & Use Cases

  • Five-phase workflow: Recon → Map → Discover → Prove → Report with escalation routing to guide decisions.
  • Reusable decision framework that adapts to target type, scope, and time constraints, improving efficiency and reproducibility.
  • Works for new programs or ongoing engagements to maintain consistency, depth, and quality of findings.

Quick Start

Ask your AI agent to run a complete bug bounty session following the five-phase workflow for your target.

Frequently Asked Questions about bug-bounty-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured bug bounty workflow from recon to report?

A structured bug bounty workflow guides security testing through five phases: Recon, Map, Discover, Prove, and Report. This process enforces repeatable decision frameworks for target analysis, vulnerability discovery, proof-of-concept creation, and final documentation.

How do I run a pentest engagement using a five-phase methodology?

Run a pentest engagement by applying the five-phase methodology: execute reconnaissance, map the attack surface, discover vulnerabilities, prove exploitability, and report findings. This structured workflow ensures consistent depth, quality, and efficient triage throughout the security testing process.

Can I use this bug bounty methodology for private security testing engagements?

Yes, this bug bounty methodology works for private engagements, public programs, and organized testing initiatives. The workflow adapts to target type, scope, and time constraints, maintaining consistency and depth across different security testing environments.

What is the best way to prioritize and route bug bounty escalations?

The best way to route bug bounty escalations is using a structured workflow that integrates cognitive strategies for efficient triage. This framework guides prioritization decisions during the Discover and Prove phases to ensure critical vulnerabilities are documented and escalated properly.

How does developer psychology help in bug bounty vulnerability discovery?

Developer psychology techniques help identify assumptions and common coding patterns that lead to security flaws. Integrating these cognitive strategies into the bug bounty workflow improves vulnerability discovery efficiency during the mapping and discovery phases.

Do I need specific tools to follow this security testing workflow?

No specific dependencies are required to follow this security testing workflow. The methodology provides a cognitive and operational framework that adapts to your existing pentest toolkit, enforcing a repeatable process for reconnaissance, discovery, and reporting.