bug-bounty-workflow

Orchestrate bug bounty hunts from reconnaissance to HackerOne report submission.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/overtimepog/greyhatcc --skill bug-bounty-workflow
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bug-bounty-workflow
Source: https://github.com/overtimepog/greyhatcc/tree/main/skills/bug-bounty-workflow
Command: npx skills add https://github.com/overtimepog/greyhatcc --skill bug-bounty-workflow

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the entire bug bounty hunting process, from initial program research and reconnaissance to vulnerability discovery, chaining, and HackerOne report submission.

Core Features & Use Cases

  • End-to-End Workflow: Manages all phases of a bug bounty hunt.
  • Automated Reconnaissance: Leverages multiple agents for comprehensive asset discovery.
  • Intelligent Vulnerability Hunting: Prioritizes business logic flaws and identifies chaining opportunities.
  • HackerOne Integration: Automates report generation and submission.
  • Use Case: A security researcher can initiate a hunt for a new bug bounty program with a single command, and the skill will handle asset discovery, vulnerability testing, and report preparation, significantly accelerating the bug hunting lifecycle.

Quick Start

Use the bug-bounty-workflow skill to start a hunt for the program 'example.com'.

Frequently Asked Questions about bug-bounty-workflow

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty reconnaissance and HackerOne report submission?

Automate bug bounty reconnaissance and HackerOne report submission by orchestrating an end-to-end hunting workflow that handles asset discovery, vulnerability testing, and automated report generation through the HackerOne API.

What is an end-to-end bug bounty hunting workflow?

An end-to-end bug bounty workflow manages program research, reconnaissance, vulnerability discovery, gadget chaining, and HackerOne report submission to maximize bug bounty ROI.

Do I need a HackerOne API integration to automate vulnerability research?

Yes, you need a HackerOne API integration to automate vulnerability research workflows, enabling automated scope loading, hunt state persistence, and direct report submission.

Can I chain gadget vulnerabilities for maximizing bug bounty ROI?

Yes, you can chain gadget vulnerabilities for maximizing bug bounty ROI through intelligent vulnerability hunting that prioritizes business logic flaws and identifies chaining opportunities.

What's the best way to load bug bounty program scope automatically?

The best way to load bug bounty program scope automatically is by initiating a hunt with a single command, which triggers automated scope loading and comprehensive asset discovery.

Does automated vulnerability hunting work without maintaining hunt state?

No, automated vulnerability hunting requires hunt state persistence to maintain context across reconnaissance and discovery phases, ensuring continuous workflow management.