What problem does it solve?
This Skill eliminates the wasted effort of chasing low-signal, non-bounty-eligible security findings, focusing exclusively on exploitable vulnerabilities that qualify for real responsible disclosure rewards instead of theoretical issues that bounty platforms routinely reject.
Core Features & Use Cases
- Bounty-Focused Triage: Automatically filters out low-value, out-of-scope findings like local-only issues, test code, and demo vulnerabilities to prioritize only remotely reachable, user-controlled attack paths.
- CWE-Aligned Pattern Matching: Targets high-impact, bounty-relevant vulnerability classes including SSRF, authentication bypass, remote code execution, SQL injection, command injection, and path traversal that consistently qualify for rewards.
- Structured Bounty Reports: Generates submission-ready reports with clear sections for description, vulnerable code, proof of concept, impact, and affected version to streamline submissions to HackerOne, Huntr, and similar platforms.
Use case example: When auditing a new web application's API, use this Skill to identify SSRF vulnerabilities in user-controlled URL endpoints that could enable cloud metadata theft, instead of wasting time on generic missing security header issues that most programs consider out of scope.
Quick Start
Use the security-bounty-hunter skill to triage the target repository and identify only exploitable, bounty-eligible vulnerabilities with clear proof-of-concept paths for responsible disclosure.