security-bounty-hunter

Automate bug bounty reconnaissance, triage, and reporting with CVSS scoring.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill security-bounty-hunter-brucesongs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-bounty-hunter
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/security-bounty-hunter
Command: npx skills add https://github.com/brucesongs/kali-claw --skill security-bounty-hunter-brucesongs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Hunt for exploitable, bounty-worthy security issues systematically by orchestrating a repeatable workflow that flows from reconnaissance through reporting, reducing manual toil and increasing high-value findings.

Core Features & Use Cases

  • Structured reconnaissance pipeline covering passive and active surface discovery, technology fingerprinting, and hidden-endpoint discovery.
  • Automated triage, evidence collection, CVSS mapping, deduplication, and chainable attack-story development for compelling reports.
  • Platform-agnostic orchestration with templates, artifacts, and cross-session knowledge sharing to accelerate repeatable success across bug bounty programs.

Quick Start

Run the automated bug bounty reconnaissance pipeline on a target within scope and generate a prioritized findings list.

Frequently Asked Questions about security-bounty-hunter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty reconnaissance and reporting?

Automate bug bounty reconnaissance and reporting by running a structured pipeline that handles surface discovery, technology fingerprinting, and hidden-endpoint discovery. The pipeline flows from reconnaissance through triage and reporting to reduce manual toil and accelerate high-value findings.

What's the best way to triage vulnerabilities and calculate CVSS scores?

Triage vulnerabilities and calculate CVSS scores using automated evidence collection, CVSS mapping, and deduplication. The pipeline enforces scope compliance and develops chainable attack stories for compelling, evidence-driven reports.

Does this bug bounty automation work with responsible disclosure workflows?

Yes, this bug bounty automation applies to both open bug bounty programs and responsible disclosure workflows. It automates reconnaissance, triage, and reporting across these contexts using platform-agnostic orchestration with templates and artifacts.

How do I develop PoC and build chainable attack stories for reports?

Develop PoC and build chainable attack stories using the pipeline's automated triage, evidence collection, and chainable attack-story development features. These combine to create compelling, evidence-driven reports for bounty submissions.

Can I use this for passive and active surface discovery across bug bounty programs?

Yes, you can use this for passive and active surface discovery across bug bounty programs. The structured reconnaissance pipeline covers technology fingerprinting and hidden-endpoint discovery with platform-agnostic orchestration, templates, and cross-session knowledge sharing.