hackerone

Parse scope CSVs, deploy parallel pentest agents, and generate HackerOne-ready reports.

1|1|Updated Mar 24, 2026
One-click install
npx skills add https://github.com/guib1/red-team-docker --skill hackerone-guib1
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hackerone
Source: https://github.com/guib1/red-team-docker/tree/main/pentest-lab/.agents/skills/hackerone
Command: npx skills add https://github.com/guib1/red-team-docker --skill hackerone-guib1

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

HackerOne bug bounty automation streamlines scope parsing, asset triage, PoC validation, and report generation so security teams can scale bug bounty programs without manual overhead.

Core Features & Use Cases

  • Programmatic scope CSV parsing and asset categorization to speed up triage across large programs.
  • Parallel agent orchestration that deploys per-asset pentest tasks and aggregates findings for rapid reporting.
  • PoC validation and HackerOne-ready report generation to accelerate professional submissions and reduce manual rework.

Quick Start

Provide a HackerOne program URL or a scope CSV path to automatically parse scope, deploy parallel agents per asset, validate PoCs, and produce submission-ready reports.

Frequently Asked Questions about hackerone

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate HackerOne bug bounty workflows across multiple assets?

Automate HackerOne bug bounty workflows by parsing scope CSVs, deploying parallel pentest agents per asset, and generating submission-ready reports with automated PoC validation to scale programs without manual overhead.

What format does the scope CSV need to be in for automated bug bounty triage?

Automated bug bounty triage requires a scope CSV format compatible with the parsing tool to correctly categorize assets and deploy parallel per-asset pentest tasks for rapid reporting.

How do I validate proof of concept artifacts for vulnerability submissions?

Validate proof of concept artifacts for vulnerability submissions by providing the required poc.py and poc_output.txt files, which integrate with existing pentest tooling to confirm PoC validity before report generation.

Can I deploy parallel pentest agents for each asset in a bug bounty program?

Deploy parallel pentest agents for each asset in a bug bounty program through automated orchestration, which executes per-asset pentest tasks and aggregates findings for rapid submission-ready reporting.

Do I need existing pentest tooling to generate HackerOne-ready reports?

Generating HackerOne-ready reports requires integration with existing pentest tooling and reporting pipelines, alongside valid PoC artifacts, to automate professional vulnerability submissions and reduce manual rework.