bug-bounty

Automate bug bounty workflows for scope, evidence, and reporting.

7|Updated Feb 11, 2026
One-click install
npx skills add https://github.com/valITino/blhackbox --skill bug-bounty-valitino
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/valITino/blhackbox/tree/main/.claude/skills/bug-bounty
Command: npx skills add https://github.com/valITino/blhackbox --skill bug-bounty-valitino

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps authorized security researchers manage bug bounty workflows from scope definition through reporting, reducing manual coordination and ensuring findings are well-documented.

Core Features & Use Cases

  • Scope management: define in-scope targets, exclusions, and program rules to keep testing within permitted boundaries.
  • Evidence capture: organize proof, screenshots, and artifacts for each finding to support PoCs and remediation.
  • Structured reporting: generate bounty-ready vulnerability reports with clear remediation steps and references.
  • Use Case: Run a full engagement for a program, capturing scope, testing results, and a compliant report suitable for submission.

Quick Start

Provide a target domain within the authorized scope and follow the prompts to begin the bug bounty workflow.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage authorized scope boundaries during a bug bounty engagement?

Manage authorized scope by defining in-scope targets, exclusions, and program rules to keep vulnerability testing within permitted boundaries. This ensures security research remains fully compliant with engagement limits.

What is the best way to document proof of concept artifacts for vulnerability reporting?

The best way to document proof of concept artifacts for vulnerability reporting is to systematically organize proof, screenshots, and artifacts. Capturing evidence for each finding directly supports PoCs and facilitates remediation.

How do I generate bounty-ready vulnerability reports with clear remediation steps?

Generate bounty-ready vulnerability reports through structured reporting automation that includes clear remediation steps and references. This ensures findings are well-documented and suitable for direct program submission.

Can I run a full bug bounty workflow from scope definition through final submission?

Yes, you can run a full bug bounty workflow from scope definition through final submission. The automated workflow manages scope, captures testing results and evidence, and produces a compliant vulnerability report.

Do I need to provide a specific target domain to start authorized security testing?

Yes, you need to provide a target domain within the authorized scope to start authorized security testing. Following the initial domain prompt initiates the structured bug bounty workflow for that specific engagement.