What problem does it solve?
This Skill eliminates the wasted effort of sifting through low-signal, non-bounty eligible security findings during repository reviews, focusing exclusively on exploitable vulnerabilities that qualify for real responsible disclosure or monetary bounty rewards.
Core Features & Use Cases
- Scope Filtering: Automatically excludes out-of-scope, low-value patterns like local-only code, test-only issues, and generic missing security headers that bounty platforms routinely reject.
- High-Impact Prioritization: Focuses on remotely reachable, user-controlled attack paths including SSRF, auth bypass, RCE, SQL injection, and XSS flaws that deliver meaningful impact for bounty submissions.
- Structured Reporting: Provides a standardized report template and pre-submission quality gate to ensure submissions meet program requirements and avoid duplicate tickets.
- Use Case: A bug bounty hunter scanning a public open-source repository for HackerOne submissions can use this Skill to cut through hundreds of irrelevant static analysis alerts and surface only 2-3 high-impact, reportable vulnerabilities.
Quick Start
Use the security-bounty-hunter skill to review the target open-source repository and generate a triage report of only exploitable, bounty-worthy security vulnerabilities eligible for responsible disclosure or bounty submission.