What problem does it solve?
This Skill unit provides a comprehensive and systematic bug bounty workflow to help researchers effectively hunt, report, and validate security vulnerabilities.
Core Features & Use Cases
- Full Workflow: Integrates reconnaissance, pre-hunt intelligence, vulnerability hunting, validation, and reporting into a single streamlined process.
- Advanced Hunting Methods: Implements advanced bug hunting techniques, such as A-to-B bug chaining, cluster hunting, and strategic data collection.
- Technical Specializations: Delivers focused vulnerability identification, with deep dives into areas like IDOR, SSRF, XSS, auth bypass, and OAuth.
- AI-Driven Security Testing: Employs AI-powered tools for prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, and system prompt extraction.
- Reporting and Hygiene: Offers comprehensive reporting features, including the 7-Question Gate, severity validation, PII redaction, and AI-generated PoCs.
Quick Start
Use the bug-bounty skill to initiate a comprehensive bug bounty workflow by entering 'bug-hunting' in Claude Code.