program-research

Extract bug bounty scope, bounties, exclusions, and policy details from HackerOne.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/overtimepog/greyhatcc --skill program-research
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: program-research
Source: https://github.com/overtimepog/greyhatcc/tree/main/skills/program-research
Command: npx skills add https://github.com/overtimepog/greyhatcc --skill program-research

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the time-consuming process of researching bug bounty programs, extracting all necessary details like scope, bounties, and rules, so you can start hunting faster.

Core Features & Use Cases

  • Comprehensive Data Extraction: Gathers scope, bounties, exclusions, and policy details from HackerOne, Bugcrowd, and Intigriti.
  • Multi-Source Approach: Leverages Playwright, HackerOne API, and AI search (Perplexity) for complete and accurate information.
  • Use Case: Before starting a new bug bounty engagement, run this Skill with a program URL to get a structured scope.md and attack_plan.md file, ready for immediate use.

Quick Start

Research the HackerOne program at https://hackerone.com/examplecorp.

Frequently Asked Questions about program-research

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty program research on HackerOne?

Automate bug bounty program research by extracting scope, bounties, exclusions, and policy details from HackerOne using Playwright, APIs, and AI search. Provide a program URL to generate structured markdown files for immediate attack planning and scope management.

Can I extract bug bounty scope and exclusions from Bugcrowd and Intigriti?

Yes, you can extract scope, bounties, exclusions, and policy details from Bugcrowd and Intigriti. The Skill uses a multi-source approach leveraging Playwright, APIs, and AI search to gather complete program information across these platforms.

What is the best way to prepare for a new bug bounty engagement?

The best way to prepare is to run automated program research with a target program URL. This generates a structured scope.md and attack_plan.md file, consolidating all necessary rules and details to help you start hunting faster.

Do I need Playwright to extract bug bounty policy details?

Playwright is required for comprehensive data extraction. The Skill leverages Playwright alongside the HackerOne API and Perplexity AI search to ensure complete and accurate information is gathered from bug bounty program pages.

Does automated program research work with private bug bounty programs?

The Skill extracts policy details and scope from platforms like HackerOne. While it uses APIs and Playwright for data extraction, accessing private program details requires appropriate authentication and permissions within your HackerOne account.

What format does the bug bounty program research output use?

The bug bounty program research outputs structured markdown files, specifically generating a scope.md and an attack_plan.md. These files document the extracted bounties, exclusions, and scope details for efficient engagement preparation.