bug-bounty

Automate end-to-end bug bounty workflows across recon, hunting, validation, and reporting.

Updated Jun 23, 2024
One-click install
npx skills add https://github.com/n4igme/randscript --skill bug-bounty-n4igme
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/n4igme/randscript/tree/main/llm/skills/claude-hunter/skills/bug-bounty
Command: npx skills add https://github.com/n4igme/randscript --skill bug-bounty-n4igme

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty programs involve a multi-phase workflow that is often manual, error-prone, and hard to scale. This skill provides an end-to-end framework to orchestrate recon, learning, hunting, validation, and reporting, reducing cognitive load and increasing the reliability of findings.

Core Features & Use Cases

  • End-to-end lifecycle: Recon, Learn, Hunt, Validate, and Report stages with guardrails.
  • Evidence-driven reporting: Templates and checklists aligned with disclosure standards.
  • Threat-model-informed hunting: Structured intelligence, risk framing, and target prioritization.
  • Reporting automation: Consistent, publish-ready reports for internal records or external disclosures.

Quick Start

Begin by loading the bug bounty skill and initiating Recon, Learn, Hunt, Validate, and Report for a target program.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate vulnerability reporting and evidence collection for bug bounty programs?

Bug bounty automation streamlines vulnerability reporting and evidence collection by enforcing structured frontmatter-driven workflows, ensuring consistent, publish-ready reports aligned with disclosure standards.

What is the best way to structure recon and threat-modeling for security testing?

Threat-modeling and recon are structured through dedicated lifecycle stages that prioritize targets, frame risk, and gather intelligence before vulnerability hunting begins.

How do I validate security findings before submitting a bug bounty report?

Validate security findings by applying the 7-Question Gate guardrail during the validation stage, which ensures findings are safe, auditable, and properly verified before disclosure.

Does this bug bounty workflow support external disclosure and internal records?

Yes, reporting automation generates consistent, publish-ready reports designed for both external program disclosures and internal security engagement records.

Can I use optional scripts and references during the vulnerability hunting phase?

Yes, the bug bounty workflow supports optional scripts, references, and assets during vulnerability hunting to enhance recon, learning, and validation stages.