bug-bounty

Execute reconnaissance, vulnerability analysis, and reporting for web applications and APIs.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill bug-bounty-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/pdparchitect/rook/tree/main/skills/bug-bounty
Command: npx skills add https://github.com/pdparchitect/rook --skill bug-bounty-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the fragmentation of the bug bounty workflow by providing a unified, systematic pipeline for reconnaissance, vulnerability research, and professional reporting.

Core Features & Use Cases

  • Full-Cycle Workflow: Orchestrates the entire process from initial asset discovery and subdomain enumeration to deep-dive vulnerability hunting and PoC generation.
  • Advanced Hunting Methodologies: Implements specialized techniques for A-to-B bug chaining, cluster hunting, and identifying complex vulnerabilities like IDOR, SSRF, and race conditions.
  • Professional Reporting: Provides structured gates and templates to ensure findings are validated, impactful, and written with a professional tone suitable for submission.

Quick Start

Use the bug bounty skill to perform a full reconnaissance and vulnerability scan on the target domain example.com.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate reconnaissance and vulnerability scanning for bug bounty targets?

You can automate bug bounty reconnaissance and vulnerability scanning by orchestrating a unified pipeline that handles asset discovery, subdomain enumeration, and deep-dive vulnerability hunting across web applications and APIs.

What is the best way to find complex vulnerabilities like IDOR and SSRF during a security audit?

Finding complex vulnerabilities like IDOR and SSRF requires advanced hunting methodologies such as A-to-B bug chaining and cluster hunting, which validate exploitable security flaws by integrating automated tool orchestration with manual testing.

How do I chain multiple vulnerabilities to demonstrate higher impact in bug bounty reports?

You can chain vulnerabilities to demonstrate higher impact by applying specialized A-to-B bug chaining techniques and cluster hunting methodologies, systematically linking individual security flaws to show compound exploit scenarios.

Can I use this security audit workflow for cloud infrastructure and APIs?

Yes, this security audit workflow targets web applications, APIs, and cloud infrastructure, systematically identifying exploitable security flaws and validating findings across these diverse environments.

How do I generate professional vulnerability reports suitable for bug bounty submission?

You generate professional vulnerability reports by using structured gates and templates that ensure findings are validated, impactful, and written with a professional tone suitable for bug bounty submission.

Does this bug bounty workflow validate findings before reporting?

Yes, the bug bounty workflow validates findings by integrating automated tool orchestration with manual methodology, ensuring that identified vulnerabilities are confirmed exploitable before generating the final report.