What problem does it solve?
This skill consolidates recon, learning, hunting, and reporting into an end-to-end bug bounty workflow, reducing fragmentation and accelerating engagements.
Core Features & Use Cases
- Recon workflows: subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit
- Pre-hunt learning: disclosed reports, tech stack research, mind maps, threat modeling
- Vulnerability hunting: IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI
- LLM/AI security testing: chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10
- A-to-B bug chaining: IDOR → auth bypass, SSRF → cloud metadata, XSS → ATO
- Reporting: templates and validation gates to structure findings and reports
Quick Start
Start by mapping recon data, then apply learn, hunt, validate, and report steps to close a target with a formal submission.