What problem does it solve?
This Skill eliminates the common inefficiencies and errors in HackerOne bug bounty pre-engagement work, including wasted effort on out-of-scope assets, duplicate vulnerability submissions, and poorly formatted reports that get rejected during triage.
Core Features & Use Cases
- Program Scope Intelligence: Enumerate in-scope assets, check bounty eligibility, and identify accepted vulnerability types for any HackerOne program.
- Prior Art Analysis: Review disclosed hacktivity reports and personal submission history to avoid testing already patched or known vulnerable surfaces.
- Structured Target Selection: Build a prioritized asset inventory with required scope and weakness IDs to streamline active testing and report submission.
- Use Case: A bug bounty researcher starting work on a new HackerOne program can use this Skill to quickly map all in-scope assets, identify high-value targets that haven't been heavily tested, and ensure all reports include the required metadata for fast triage.
Quick Start
Use the hackerone-recon skill to run a full pre-engagement reconnaissance workflow for the HackerOne program with handle 'target-program' and generate a prioritized target inventory with all required scope and weakness IDs.