hackerone-recon

Enumerate HackerOne program scope and generate prioritized target inventories.

11|1|Updated May 4, 2026
One-click install
npx skills add https://github.com/dreadnode/capabilities --skill hackerone-recon
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hackerone-recon
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/web-security/skills/hackerone-recon
Command: npx skills add https://github.com/dreadnode/capabilities --skill hackerone-recon

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates the common inefficiencies and errors in HackerOne bug bounty pre-engagement work, including wasted effort on out-of-scope assets, duplicate vulnerability submissions, and poorly formatted reports that get rejected during triage.

Core Features & Use Cases

  • Program Scope Intelligence: Enumerate in-scope assets, check bounty eligibility, and identify accepted vulnerability types for any HackerOne program.
  • Prior Art Analysis: Review disclosed hacktivity reports and personal submission history to avoid testing already patched or known vulnerable surfaces.
  • Structured Target Selection: Build a prioritized asset inventory with required scope and weakness IDs to streamline active testing and report submission.
  • Use Case: A bug bounty researcher starting work on a new HackerOne program can use this Skill to quickly map all in-scope assets, identify high-value targets that haven't been heavily tested, and ensure all reports include the required metadata for fast triage.

Quick Start

Use the hackerone-recon skill to run a full pre-engagement reconnaissance workflow for the HackerOne program with handle 'target-program' and generate a prioritized target inventory with all required scope and weakness IDs.

Frequently Asked Questions about hackerone-recon

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enumerate in-scope assets for a HackerOne bug bounty program?

To enumerate in-scope assets for a HackerOne bug bounty program, use this Skill to map program scope intelligence, check bounty eligibility, and identify accepted vulnerability types for your target program handle.

What is the best way to avoid duplicate findings on HackerOne?

The best way to avoid duplicate findings on HackerOne is to perform prior art analysis using this Skill to review disclosed hacktivity reports and personal submission history before testing.

How do I structure a HackerOne vulnerability report for fast triage?

To structure a HackerOne vulnerability report for fast triage, use this Skill to generate a prioritized target inventory that includes all required scope and weakness IDs for submission.

Can I use this to check bounty eligibility and accepted vulnerability types for any HackerOne program?

Yes, you can check bounty eligibility and identify accepted vulnerability types for any HackerOne program by applying this Skill's program scope intelligence to enumerate target assets.

Why should I do pre-engagement reconnaissance before active bug bounty testing?

Pre-engagement reconnaissance is necessary before active bug bounty testing to eliminate wasted effort on out-of-scope assets, prevent duplicate vulnerability submissions, and avoid rejected reports during triage.

How do I build a prioritized asset inventory for HackerOne testing?

To build a prioritized asset inventory for HackerOne testing, use this Skill to map in-scope assets, analyze prior disclosures, and select high-value targets that have not been heavily tested.