exploit-agent

Validate suspected web vulnerabilities and generate structured exploit reports.

54|5|Updated May 9, 2026
One-click install
npx skills add https://github.com/jinyimeng01/mastermind-bug-bounty --skill exploit-agent
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: exploit-agent
Source: https://github.com/jinyimeng01/mastermind-bug-bounty/tree/main/agents/exploit
Command: npx skills add https://github.com/jinyimeng01/mastermind-bug-bounty --skill exploit-agent

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security testers transform suspected vulnerabilities into validated exploit findings with evidence, impact analysis, and structured reports while avoiding false positives.

Core Features & Use Cases

  • Exploit Validation Workflow: Guides testing for vulnerability classes including XSS, SQLi, SSRF, IDOR, SSTI, RCE, race conditions, and business logic flaws with confirmation gates.
  • Triage and Reporting: Applies FOUND versus CONFIRMED rules, impact checks, evidence requirements, and generates Chinese HackerOne/SRC-style vulnerability reports.
  • Use Case: A bug bounty researcher can use this Skill after reconnaissance and fuzzing phases to verify exploitability, capture proof, and prepare a submission-ready report.

Quick Start

Use the exploit agent skill to analyze the collected vulnerability findings, validate impact, and prepare a compliant vulnerability report.

Frequently Asked Questions about exploit-agent

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate suspected security vulnerabilities before submitting a bug bounty report?

Bug bounty vulnerability reporting requires structured evidence, confirmed impact analysis, and proof-of-concept generation to transform validated findings into professional security submissions compliant with HackerOne or SRC standards.

Can I use this to generate HackerOne-style vulnerability reports for web application flaws?

Bug bounty vulnerability reporting requires structured evidence, confirmed impact analysis, and proof-of-concept generation to transform validated findings into professional security submissions compliant with HackerOne or SRC standards.

What is the best way to turn fuzzing findings into structured exploit evidence?

Bug bounty vulnerability reporting requires structured evidence, confirmed impact analysis, and proof-of-concept generation to transform validated findings into professional security submissions compliant with HackerOne or SRC standards.

Does this support triage for business logic flaws and race conditions?

Bug bounty vulnerability reporting requires structured evidence, confirmed impact analysis, and proof-of-concept generation to transform validated findings into professional security submissions compliant with HackerOne or SRC standards.

How to avoid false positives when testing for access control issues and IDOR?

Bug bounty vulnerability reporting requires structured evidence, confirmed impact analysis, and proof-of-concept generation to transform validated findings into professional security submissions compliant with HackerOne or SRC standards.

When should I not use automated exploit validation for security testing?

Bug bounty vulnerability reporting requires structured evidence, confirmed impact analysis, and proof-of-concept generation to transform validated findings into professional security submissions compliant with HackerOne or SRC standards.