What problem does it solve?
Miscellaneous vulnerabilities including access control failures, information disclosure, authentication logic bugs, and misconfigurations consistently deliver the highest bug bounty payouts, but are often overlooked due to lack of systematic hunting methodology. This Skill solves that gap by providing field-validated techniques derived from 225 public bug bounty reports across diverse targets.
Core Features & Use Cases
- Comprehensive Hunting Methodology: 12-step structured workflow covering role boundary testing, invitation flow bypasses, token scope fuzzing, cross-tenant access checks, SAML/SSO logic audits, and CRLF/header injection testing.
- Real-World Attack Chains: Multi-step engagement patterns that combine low-severity primitives into high-impact findings, with concrete examples from disclosed bug bounty reports.
- Validation & Triage Tools: Gate 0 validation checks, body-diff rules, and marker discipline guidelines to avoid false positives and produce report-ready, platform-accepted findings.
- Use Case: Ideal for bug bounty hunters and penetration testers targeting SaaS platforms, enterprise auth systems, and multi-tenant applications to find high-severity, high-payout vulnerabilities.
Quick Start
Use the hunt-misc skill to systematically test for privilege escalation and access control flaws on your current authorized bug bounty target, following the provided step-by-step methodology and validation gates to produce report-ready findings.