hunt-mindset

Guide bug bounty hunters through a 5-phase non-linear hunting workflow.

1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/mlvpatel/sentinel-ai-offensive --skill hunt-mindset
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-mindset
Source: https://github.com/mlvpatel/sentinel-ai-offensive/tree/main/skills/hunt-mindset
Command: npx skills add https://github.com/mlvpatel/sentinel-ai-offensive --skill hunt-mindset

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty operators frequently start hunts with inconsistent mindsets and fragmented workflows. This skill provides a master orchestrator that combines a 5-phase non-linear hunting workflow with a rigorous critical thinking framework, helping hunters stay focused and switch between targets seamlessly.

Core Features & Use Cases

  • 5-phase non-linear workflow that allows moving between RECON, MAPPING, VULNERABILITY DISCOVERY, PROVE & ESCALATE, and VALIDATE & REPORT.
  • Critical thinking framework covering developer psychology, anomaly detection, and What-If experiments.
  • Routes to all other skills based on the current hunting phase, and guidance when asking what to do next or where you are in the process.
  • Suitable for starting sessions, switching targets, and maintaining a productive hunting routine across complex targets.

Quick Start

Begin by defining the target and selecting 1–2 vuln classes, then follow the 5-phase workflow to map, discover, prove, and report findings.

Frequently Asked Questions about hunt-mindset

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a non-linear bug bounty hunting workflow?

A non-linear bug bounty workflow structures hunts into five phases: recon, mapping, vulnerability discovery, prove and escalate, and validate and report. This framework allows hunters to transition flexibly between phases while maintaining critical thinking and analysis focus.

What is the best way to maintain a consistent mindset across different bug bounty targets?

Maintaining a consistent mindset across targets requires a deterministic orchestrator that applies critical thinking frameworks covering developer psychology and anomaly detection. This approach ensures structured phase transitions and productive hunting routines even when switching targets frequently.

How do I start a bug bounty hunt when I have a new target?

To start a bug bounty hunt, first define the target and select one or two vulnerability classes. Then follow a structured five-phase workflow to map the attack surface, discover vulnerabilities, prove and escalate findings, and validate reports.

Can I move between reconnaissance and vulnerability discovery phases non-linearly?

Yes, you can move between reconnaissance, mapping, and vulnerability discovery phases non-linearly. The workflow supports flexible phase transitions, allowing hunters to route back to earlier phases like recon when new anomalies or attack surfaces are discovered during validation.

What critical thinking frameworks help with bug bounty anomaly detection?

Critical thinking frameworks for bug bounty anomaly detection involve analyzing developer psychology, identifying anomalies in application behavior, and conducting What-If experiments. These frameworks guide hunters through rigorous analysis during vulnerability discovery and proof phases.

When should I transition to the validate and report phase in a bug bounty hunt?

You should transition to the validate and report phase after proving and escalating a vulnerability. The workflow provides deterministic phase transitions and escalation paths to ensure findings are thoroughly validated and properly documented before reporting.