bug-bounty

Automate bug bounty workflows from recon to reporting across HackerOne, Bugcrowd, and Immunefi.

2|1|Updated Mar 20, 2026
One-click install
npx skills add https://github.com/Mikacr1138/claude-bug-bounty --skill bug-bounty-mikacr1138
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/Mikacr1138/claude-bug-bounty/tree/main
Command: npx skills add https://github.com/Mikacr1138/claude-bug-bounty --skill bug-bounty-mikacr1138

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Streamlines the entire bug bounty lifecycle by orchestrating recon, learning, hunting, validation, and reporting in a single, automated workflow.

Core Features & Use Cases

  • Recon automation: subdomain enumeration, asset discovery, fingerprinting, and scope checks across bug bounty programs.
  • Pre-hunt learning: leverage disclosed reports, tech stack research, mind maps, threat modeling, and intelligence gathering to plan effective hunts.
  • Vulnerability hunting & validation: execute a master workflow that covers multiple vuln classes, apply 7-Question Gate checks, 4 gates, and conditional chaining for robust validation.
  • Reporting templates: generate submission-ready reports with CVSS scoring, templates by vuln class, and human-tone writing.

Quick Start

Load targets, run recon, hunt vulnerabilities, validate findings, and generate submission-ready reports.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate recon and vulnerability reporting for bug bounty programs?

Bug bounty workflow automation orchestrates the entire lifecycle from recon to reporting across platforms like HackerOne and Bugcrowd. It coordinates asset discovery, vulnerability hunting, validation gates, and templated report generation in a single automated process.

What is the best way to validate findings before submitting a bug bounty report?

Validating bug bounty findings requires applying structured checks like 7-Question Gate validation and 4 conditional gates. This process uses A-to-B chains to robustly confirm vulnerabilities across multiple classes before generating submission-ready reports.

Can I generate submission-ready reports with CVSS scoring for HackerOne and Bugcrowd?

Yes, submission-ready reports with CVSS scoring can be generated automatically using templated reports by vulnerability class. The workflow supports major platforms including HackerOne, Bugcrowd, and Immunefi with human-tone writing for final submissions.

How do I plan an effective bug bounty hunt using disclosed reports and threat modeling?

Pre-hunt learning leverages disclosed reports, tech stack research, mind maps, and threat modeling to gather intelligence. This planning phase helps identify target weaknesses and plan effective hunts before executing the master vulnerability workflow.

Does the bug bounty workflow handle subdomain enumeration and scope checks automatically?

Recon automation handles subdomain enumeration, asset discovery, fingerprinting, and scope checks automatically across bug bounty programs. This ensures targets are properly validated against program scopes before proceeding to vulnerability hunting.

What validation gates are applied during bug bounty vulnerability hunting?

The master vulnerability hunting workflow applies 7-Question Gate checks, 4 distinct validation gates, and conditional chaining. These mechanisms ensure robust validation across multiple vulnerability classes before findings proceed to report generation.