hunt-misc

Identify miscellaneous vulnerabilities like access control failures and misconfigurations in SaaS platforms.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill hunt-misc-uphiago
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-misc
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/hunt-misc
Command: npx skills add https://github.com/uphiago/recon-skills --skill hunt-misc-uphiago

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Miscellaneous vulnerabilities including access control failures, information disclosure, authentication logic bugs, and misconfigurations consistently deliver the highest bug bounty payouts, but are often overlooked due to lack of systematic hunting methodology. This Skill solves that gap by providing field-validated techniques derived from 225 public bug bounty reports across diverse targets.

Core Features & Use Cases

  • Comprehensive Hunting Methodology: 12-step structured workflow covering role boundary testing, invitation flow bypasses, token scope fuzzing, cross-tenant access checks, SAML/SSO logic audits, and CRLF/header injection testing.
  • Real-World Attack Chains: Multi-step engagement patterns that combine low-severity primitives into high-impact findings, with concrete examples from disclosed bug bounty reports.
  • Validation & Triage Tools: Gate 0 validation checks, body-diff rules, and marker discipline guidelines to avoid false positives and produce report-ready, platform-accepted findings.
  • Use Case: Ideal for bug bounty hunters and penetration testers targeting SaaS platforms, enterprise auth systems, and multi-tenant applications to find high-severity, high-payout vulnerabilities.

Quick Start

Use the hunt-misc skill to systematically test for privilege escalation and access control flaws on your current authorized bug bounty target, following the provided step-by-step methodology and validation gates to produce report-ready findings.

Frequently Asked Questions about hunt-misc

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find high-payout access control and privilege escalation vulnerabilities in SaaS platforms?

This Skill provides field-validated hunting steps and payload patterns for identifying access control failures, authentication logic bugs, and misconfigurations by applying a 12-step workflow derived from 225 public bug bounty reports.

What is the best way to hunt for SAML bypass and SSO logic bugs?

The best way to hunt for SAML bypass and SSO logic bugs is to follow a systematic methodology that audits enterprise identity and authentication flows, using multi-step attack chains and validation gates to ensure reproducible findings.

How do I systematically test multi-tenant applications for cross-tenant access flaws?

You can systematically test multi-tenant applications for cross-tenant access flaws by executing field-validated hunting steps that include token scope fuzzing and role boundary testing, ensuring vulnerabilities map directly to business impact.

Can I use this methodology to validate bug bounty findings and avoid false positives?

Yes, you can validate bug bounty findings and avoid false positives by applying Gate 0 validation checks, body-diff rules, and marker discipline guidelines to produce report-ready, platform-accepted high-severity findings.

Does this hunting approach work for internal API endpoints and enterprise auth systems?

Yes, this hunting approach works for internal API endpoints and enterprise auth systems, providing real-world attack chains and root cause analysis specifically targeting these environments for high-impact miscellaneous vulnerabilities.