bug-bounty

Coordinate recon, hunting, validation, and reporting for bug bounty programs.

1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/mlvpatel/sentinel-ai-offensive --skill bug-bounty-mlvpatel
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/mlvpatel/sentinel-ai-offensive/tree/main
Command: npx skills add https://github.com/mlvpatel/sentinel-ai-offensive --skill bug-bounty-mlvpatel

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

Automates and standardizes the full bug bounty lifecycle from reconnaissance to reporting, enabling teams to consistently surface high-impact vulnerabilities with a repeatable workflow.

Core Features & Use Cases

  • End-to-end orchestration: Recon, learning, hunting, validation, and report generation within a single workflow.
  • Memory-enabled analysis: Persistent memory of targets and findings to accelerate future hunts.
  • Compliance-minded: Built-in gates, schema validation, and audit trails to demonstrate regulatory alignment.

Quick Start

Install the skill and run /recon on a target to begin the end-to-end bug bounty workflow.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty hunting workflows from reconnaissance to reporting?

To automate bug bounty hunting, you orchestrate end-to-end workflows from recon to report generation. This skill coordinates recon, learning, hunting, validation, and reporting to surface vulnerabilities using a repeatable methodology.

Can I run bug bounty recon on enterprise web apps and smart contracts?

Yes, you can run bug bounty recon on enterprise web apps and smart contracts. The workflow applies to targets ranging from web applications to smart contracts within enterprise and open-source bug bounty programs.

How do I validate vulnerabilities found during a bug bounty hunt?

You validate vulnerabilities found during a bug bounty hunt using built-in 7-Question Gate validation and a 4-gate review. The workflow enforces safe-method validation to ensure findings are accurate before reporting.

Does this bug bounty workflow maintain persistent memory of targets and findings?

Yes, this bug bounty workflow maintains persistent hunt memory of targets and findings. This memory-enabled analysis accelerates future hunts by retaining target data and findings across sessions.

How do I generate compliance audit logs for a bug bounty program?

You generate compliance audit logs for a bug bounty program using immutable logging and versioned schemas. This workflow provides built-in gates, schema validation, and audit trails to demonstrate regulatory alignment.

What is the best way to standardize threat modeling for bug bounty hunting?

The best way to standardize threat modeling for bug bounty hunting is applying a repeatable methodology with enforced gates. This workflow satisfies threat modeling, safe-method enforcement, and 4-gate review for consistent results.