Agent skill

Bug Bounty Hunting Methodology

by awarexone in awarexone/Agentic-Bug-Hunter

Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

MITAuto-check passedSecurity

Install Bug Bounty Hunting Methodology

skills CLI
$ npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awarexone/Agentic-Bug-Hunter bb-methodology --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bb-methodology .claude/skills/bb-methodology && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bb-methodology
GitHub stars
5.3k
Used in
2 other repos
Token cost
~4.7k tokens
SKILL.md length
1,881 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

  • Works in 5 steps: Critical Thinking (deep analysis) → Multi-Perspective (multiple angles) → Tactical Thinking (pattern detection) → …
  • Starting a new bug bounty hunting session
  • SKILL.md covers PART 1: MINDSET (How to Think), PART 2: WORKFLOW (What to Do) and PART 3: NAVIGATION & TIMING
  • Calls python3, bash and curl

What it does

The skill is a master orchestrator meant to start any hunting session, resume one after switching targets, or answer 'what should I do next' when the hunter feels lost; it routes to other skills based on the current phase. Its mindset section reframes hunting as proving a specific attack scenario rather than scanning for patterns, with a daily discipline of defining a target feature and CIA impact, selecting one or two vulnerability classes such as IDOR or race conditions, and executing only those without wandering, picking one of five goals per session: confidentiality, integrity, availability, account takeover or RCE.

Four thinking domains structure the approach: critical thinking that questions trust boundaries and reverse-engineers developer psychology (a new feature probably skipped the auth checks an older one has), multi-perspective checks across horizontal and vertical roles, data flow and timing, tactical pattern detection such as naming anomalies that hint at a different, less careful developer, and What-If experiments like hitting a checkout-success URL directly or replaying a request many times at once to probe for a race condition.

When your agent uses it

  • Starting a new bug bounty hunting session
  • Switching to a new target and needing a fresh plan
  • Feeling unsure what to do next in an ongoing hunt
  • Deciding which vulnerability class to focus a session on

Example prompts

  • “I'm starting a new bug bounty session on this target. What should I focus on first?”
  • “Where am I in the hunting process for this app?”
  • “This feature has no auth check on a newly added endpoint. Walk me through exploiting it.”
  • “Set up a race-condition test for this coupon redemption endpoint.”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Critical Thinking (deep analysis)
  2. Multi-Perspective (multiple angles)
  3. Tactical Thinking (pattern detection)
  4. Strategic Thinking (big picture)
  5. AI-Assisted Thinking (model as a second analyst)

What it can do on your machine

Read from SKILL.md and the folder at commit cd58a40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • bash
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Bounty Hunting Methodology loads about 4.7k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 1,881 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from awarexone/Agentic-Bug-Hunter at commit cd58a40, republished under its MIT licence (© awarexone). 1,881 words, ~4,727 tokens.

Download SKILL.mdSave it as .claude/skills/bb-methodology/SKILL.md (or your agent's skills folder).
name
bb-methodology
description
Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other skills based on current hunting phase. Also use when asking "what should I do next" or "where am I in the process."

Bug Bounty Methodology: Workflow + Mindset

Master orchestrator for hunting sessions. Combines the 5-phase non-linear workflow with the critical thinking framework that separates top 1% hunters from the rest.


PART 1: MINDSET (How to Think)

Core Principle

Hunting is not "find a bug" -- it is "prove an attack scenario." Think like an attacker with a specific goal, not a scanner looking for patterns.

Daily Discipline: Define, Select, Execute

Before touching any tool:

  1. Define: "Today I target [feature/domain] to achieve [CIA impact]"
  2. Select: Choose 1-2 vuln classes (IDOR, Race Condition, etc.)
  3. Execute: Focus ONLY on selected techniques. No wandering.
5 Ultimate Goals (Pick One Per Session)
  1. Confidentiality -- steal data the attacker shouldn't see
  2. Integrity -- modify data the attacker shouldn't change
  3. Availability -- disrupt service (app-level DoS only)
  4. Account Takeover -- control another user's account
  5. RCE -- execute commands on the server
4 Thinking Domains
1. Critical Thinking (deep analysis)

Question trust boundaries:

  • Frontend control disabled? Send request directly via proxy
  • user_role=user cookie? Change to admin
  • price=1000 in POST? Change to 1
  • <script> blocked? Try <img onerror=...>

Reverse-engineer developer psychology:

  • Feature A has auth checks -> Similar feature B (newly added) probably doesn't
  • Complex flows (coupon + points + refund) -> Edge cases have bugs
  • /api/v2/user exists -> Does /api/v1/user still work with weaker auth?

What-If experiments:

  • Skip checkout -> hit /checkout/success directly
  • Skip 2FA -> navigate to /dashboard
  • Send coupon request 10x simultaneously -> Race condition?
  • Replace guid=f8a2... with id=100 on sibling endpoint -> IDOR?
2. Multi-Perspective (multiple angles)
PerspectiveWhat to check
Horizontal (same role)User A's token + User B's ID -> IDOR
Vertical (different role)Regular user -> /admin/deleteUser
Data flow (proxy view)Hidden params in JSON: debug=false, discount_rate
Time/StateRace conditions, post-delete session reuse
Client environmentMobile UA -> legacy API with weaker auth
Business impact"What's the $ damage if this breaks?"
3. Tactical Thinking (pattern detection)
  • Naming anomaly: userId everywhere but suddenly user_id -> different dev, weaker security
  • Error diff: Same 403 but different JSON structure -> different backend systems
  • 200 but wrong body length/content: 200 OK with tiny response or "just a moment" text → WAF soft block, not a real response. Run bypass_403.sh to confirm and get baseline diff.
  • Environment diff: Prod vs Dev/Staging -> debug headers, CSP disabled
  • Version diff: JS file before/after update -> new endpoints, removed params
  • Supply chain: Check framework/library versions for known CVEs
  • Third-party integration: Stripe/Auth0/Intercom -> webhook signature missing?
4. Strategic Thinking (big picture)
  • Asymmetry: Defender must patch ALL holes. You only need ONE.
  • Intuition engineering: Log why something "feels wrong." Verify later. Update mental DB.
  • Unknown management: Can't understand something? Add to "investigate later" list. Just-in-Time Learning.
5. AI-Assisted Thinking (model as a second analyst)

Use AI to expand hypotheses, not to declare verdicts. The model is a fast adversarial planner; the browser, proxy, and live requests are the proof layer.

  • Decompose the feature: ask for actors, assets, entry points, state transitions, and trust boundaries.
  • Generate sibling paths: versioned endpoints, mobile routes, legacy APIs, alternate roles, and admin-only variants.
  • Build a role matrix: anonymous, user A, user B, stale session, fresh session, admin, service account.
  • Ask for dev shortcuts: "Where would a tired developer skip a check or reuse a helper?"
  • Ask for chains: "If this bug is real, what bug B and C sit next to it?"
  • Turn ideas into requests: every AI suggestion must become a single reproducible HTTP experiment.
  • Kill weak signals fast: if AI cannot point to a concrete request, response diff, or cross-account delta, the idea stays as a hypothesis.

High-signal prompts:

  • "Given this endpoint and feature, list the 10 most likely trust-boundary mistakes."
  • "What sibling endpoints, methods, or roles should I test next?"
  • "Which bug class would a rushed implementation likely miss here?"
  • "What does the smallest proof request look like?"
  • "What would make this become a real report instead of a scanner hit?"
Amateur vs Pro: 7-Phase Comparison
PhaseAmateurPro
ReconMain domain onlyShadow IT, dev environments, all assets
DiscoveryLook for errorsLook for design contradictions, business logic flaws
ExploitGive up when blockedBuild filter-bypass payloads
EscalationReport the phenomenon onlyChain to real harm (session steal, ATO)
FeasibilityInclude unrealistic conditionsMinimize attack prerequisites
ReportingState facts onlyQuantify business risk
RetestCheck if old PoC failsAnalyze fix method, find incomplete patches
Two Approach Routes
  • Route A (Feature-based): "This feature is complex" -> deep-dive its input handling -> find vuln
  • Route B (Vuln-based): "I want IDOR" -> find endpoints with sequential IDs -> test access control
Anti-Patterns (Stop Doing These)
  • Program hopping: Stick with one target minimum 2 weeks / 30 hours
  • Tool-only hunting: Automation finds duplicates. Manual testing finds unique bugs.
  • Rabbit hole: Max 45 min per parameter. Set a timer. If stuck, sleep on it.
  • No goal: "Just looking around" = wasted time. Always Define first.

PART 2: WORKFLOW (What to Do)

The 5-Phase Non-Linear Flow
+-------------------------------------------------+
|                                                 |
|  +----------+    +----------+    +----------+   |
|  | 1. RECON |---+| 2. MAP   |---+| 3. FIND  |  |
|  +----------+    +-----+----+    +-----+-----+  |
|       ^                |               |         |
|       |                v               v         |
|       |          +----------+    +----------+    |
|       +----------| 4. PROVE |---+| 5. REPORT|   |
|                  +----------+    +----------+    |
|                                                  |
|  Non-linear: stuck at any phase -> go back       |
|  New API found at phase 3 -> return to phase 2   |
|  WAF blocks at phase 4 -> origin IP from phase 1 |
+-------------------------------------------------+

THIS IS NOT LINEAR. Move freely between phases. When stuck, return to a previous phase.

Phase 0: SESSION START (Every Time)

Before touching any tool, answer these:

  1. Define: "Today I target [feature/domain] to achieve [C/I/A/ATO/RCE]"
  2. Select: Choose 1-2 vuln classes (IDOR, XSS, SSRF, etc.)
  3. Execute: Focus ONLY on selected techniques
  4. Identity: Anonymous or authenticated? If the bugs you're hunting need a session (IDOR, BOLA, privilege escalation, auth bypass, mass-assignment), load auth once at session start — see docs/auth-sessions.md. Then every downstream tool (httpx, katana, ffuf, nuclei, dalfox, PoC verifiers) sends those headers automatically and audit log entries are stamped with a stable session_id hash.

Route selection -- Wide or Deep?

SignalWide (recon sweep)Deep (focused testing)
New program, first dayX
Wildcard scope *.target.comX
Main webapp, been here >3 daysX
Scope update (new domain added)X
Found interesting subdomainX
Hunting IDOR / BOLA / auth bugsX (auth-aware)
Phase 1: RECON

Goal: Maximize attack surface. Find what others missed.

Wide approach (initial sweep):

Subdomain enum -> DNS resolution -> HTTP probing -> Port scan -> Tech detect

Deep approach (targeted):

Google Dorks -> JS file download -> Hidden param discovery -> API mapping
What you findNext action
Live subdomains with tech stackPhase 2 (Mapping)
Known software (WordPress, Jira)Check CVEs + defaults immediately
Cloud resources (S3, Firebase)Test permissions (read/write/list)
403 or 200 + block page on endpointtools/bypass_403.sh <url> auto-detects soft blocks (200+block-body). Verdict: bypassed/needs_review/blocked. If all blocked after 5 min, skip
Nothing after 5 min on a hostSkip, try next host (5-minute rule)

Command: /recon target.com

After every recon (mandatory):

bash
python3 tools/lead_board.py ingest target.com
python3 tools/lead_board.py show target.com
python3 tools/lead_board.py next target.com
# Route in plain language: "GraphQL endpoint → skills/graphql-audit"
# touch status when you start / kill / report a lead

(hunt.py runs ingest + EOL automatically unless --skip-leads.)

Phase 2: MAPPING & ANALYSIS

Goal: Understand the app like its developer does.

Checklist:

  • Map all endpoints (Burp/Caido sitemap + JS analysis)
  • Identify auth model (cookie, JWT, OAuth, SAML?)
  • Find business-critical flows (payment, registration, password reset, data export)
  • Download and analyze JS files for hidden routes, secrets, logic
  • Identify roles and permissions (user, admin, API keys)
  • Note "weird" behaviors (anomalies in naming, errors, timing)
What you findNext action
JS files with interesting codeTaint analysis (Sink -> Source)
OAuth/SAML authenticationOAuth/SAML checklist
API with ID parametersPhase 3, target IDOR
Complex business logic (payment, coupon)Phase 3, target BizLogic
postMessage listenersDOM analysis, postMessage-tracker
Show full SKILL.md (739 more words)Show less
Phase 3: VULNERABILITY DISCOVERY

Goal: Find the bug. Use Error-based first, then Blind-based.

Decision flow based on what you're testing:

What input are you testing?
+-- ID parameter (user_id, order_id)
|   -> IDOR checklist
+-- Search/filter/sort field
|   -> SQLi, NoSQLi probing
+-- URL input / webhook / PDF gen
|   -> SSRF checklist
+-- Text field reflected in page
|   -> XSS (DOM or reflected)
+-- File upload
|   -> SVG XSS, web shell, path traversal
+-- Price/quantity/coupon
|   -> Business logic, race conditions
+-- Login / 2FA / password reset
|   -> Auth bypass
+-- Profile update API
|   -> Mass Assignment
+-- Template / wiki editor
|   -> SSTI
+-- Nothing obvious
    -> Fuzz with ffuf, try Error-based probing

Error vs Blind decision:

  1. Try Error-based first (send ', ", {{7*7}}, ${7*7}) -- watch for 500 errors, stack traces
  2. No error? Time-based (SLEEP(10), ; sleep 10;) -- watch response time
  3. No time diff? OOB (curl attacker.com, interactsh) -- watch for DNS callback
  4. Still nothing? Boolean (AND 1=1 vs AND 1=0) -- watch content-length diff
What you findNext action
Low-impact behavior (redirect, self-XSS, cookie injection)Chain it -- find a connector gadget
Confirmed vuln (XSS, IDOR, SQLi)Phase 4 (Prove and Escalate)
Blocked by WAF/CSP/403 or soft-block 200/bypass-403 <url> → check verdict (not just status) → tools/waf_encoder.py "<payload>" → if upload: tools/multipart_mutator.py → 5 min, kill
Known software vuln (CVE)1-day speed workflow
Nothing after 20 min on this endpointRotate (20-minute rule)
Phase 4: PROVE & ESCALATE

Goal: Prove maximum business impact. Turn Low into Critical.

Escalation decision:

What did you find?
+-- XSS
|   +-- Can steal cookie/token? -> Session hijack -> ATO
|   +-- Cookie is HttpOnly? -> Force email change via XHR -> ATO
|   +-- Self-XSS only? -> Find CSRF to trigger it
+-- IDOR
|   +-- Can read PII? -> Automate scraping, show scale
|   +-- Can change password/email? -> Direct ATO
|   +-- UUID only? -> Find UUID leak source, then retry
+-- SSRF
|   +-- DNS only? -> DON'T REPORT. Try cloud metadata
|   +-- Can reach 169.254.169.254? -> Extract keys -> RCE
|   +-- Internal port scan? -> Find Redis/K8s -> RCE
+-- SQLi
|   +-- Error-based? -> Extract data (passwords, tokens)
|   +-- Can INTO OUTFILE? -> Web shell -> RCE
|   +-- Blind? -> Boolean/Time extraction
+-- Open Redirect
|   +-- OAuth flow? -> Token theft -> ATO
|   +-- javascript: scheme? -> XSS
+-- Blocked by defense
|   -> Bypass (WAF/CSP/proxy/sanitizer/2FA)
+-- Low-impact, can't escalate alone
    -> Find connector gadget for chain

After proving impact, check:

  • Can attack work with 0-1 clicks? (minimize prerequisites)
  • Does it affect all users or specific role?
  • What's the business $ impact?
Phase 5: VALIDATE & REPORT

Goal: Get paid. Make triager's job easy.

Pre-report gate:

Run /validate (7-Question Gate)
+-- All 7 pass? -> Write report
+-- Any fail? -> KILL the finding. Don't waste time.
+-- Borderline? -> Run /triage for quick go/no-go

Report:

Run /report
+-- Platform-specific format (H1/Bugcrowd/Intigriti/Immunefi)
+-- Title: [Bug Class] in [Endpoint] allows [role] to [impact]
+-- Impact-first summary (sentence 1 = what attacker CAN do)
+-- Exact HTTP requests in Steps to Reproduce
+-- Under 600 words
+-- CVSS 3.1 score that MATCHES actual impact

After submission:

  • While waiting for triage: try to escalate further (A->B signal method)
  • If fix deployed: re-test for bypass (incomplete patch = new bug)
  • Record finding with /remember for hunt memory

PART 3: NAVIGATION & TIMING

Non-Linear Navigation Quick Reference
I'm stuck because...Go to...
Can't find any subdomainsPhase 1: Try different recon sources, Google Dorks
Found subdomain but don't know what to testPhase 2: Map the app, download JS, understand auth
Testing but nothing worksPhase 3: Switch vuln class (20-min rotation rule)
Found a bug but impact is lowPhase 4: Escalation paths or gadget chaining
WAF/CSP/403 blocking my payload/bypass-403 → fingerprint WAF → waf_encoder.py variants → kill if 5 min spent (403 even after /bypass-403 + WAF fingerprint + waf_encoder.py variants)
Been stuck for 45 min on one paramSTOP. Rabbit hole. Move to next endpoint.
New API endpoint discovered during testingReturn to Phase 2: map it before attacking
Found one bugA->B signal: same dev made more mistakes. Hunt 20 min for siblings.
20-Minute Rotation Clock

Every 20 minutes ask yourself: "Am I making progress?"

  • Yes -> Continue
  • No -> Rotate to next: endpoint -> subdomain -> vuln class -> target
  • Been on same target 2+ weeks with no findings? -> Consider switching program
Tool Routing by Phase
PhaseToolsWhy this order
Recon: Subdomainssubfinder -> amass -> puredns -> httpxPassive first (no detection) -> resolve DNS -> probe HTTP + tech stack
Recon: URLsgau + waymore -> katana -> uroArchive (forgotten endpoints) -> active crawl (JS-rendered) -> deduplicate
Recon: JSjsluice + mantra + trufflehog --only-verifiedExtract URLs/secrets -> find API keys -> verify keys actually work
Recon: Portsnaabu (wide) -> rustscan (deep)Fast top-1000 sweep -> full 65535 on interesting targets
Recon: Scannuclei -tags cve -> nuclei -tags takeoverKnown CVEs first -> then takeover (act immediately)
After recon (ALWAYS)python3 tools/lead_board.py ingest <target> → show → nextRoute every signal to a hunt-* skill; never lose a lead. touch when you start/kill/report
After recon: EOLpython3 tools/eol_check.py --tech "php=7.4,nginx=1.18"Flag EOL products from technologies.txt fingerprints
Mapping: Paramsarjun + paramspider + ParamMiner / tools/param_discovery.shBrute-force hidden params + mine archives + cache headers
Mapping: GraphQLbash tools/graphql_audit.sh <url>Introspection → fingerprint → batching → IDOR → injection
Mapping: CI/CDbash tools/cicd_scanner.sh owner/repoWorkflow injection / secret exfil / runner poisoning
Mapping: JS codeDownload -> jsluice -> VS Code/Cursor grepExtract -> static analysis -> AI-assisted taint analysis
Mapping: DorksManual Google DorksCustom per-target queries find what automation misses
Discovery: Fuzzffuf -ac + cewl custom wordlistAuto-calibrate filtering + target-specific words beat generic lists
Discovery: XSSkxss -> dalfoxFilter (which params reflect?) -> scan (only reflective params)
Discovery: SQLighauriModern blind SQLi on ID-like parameters
Discovery: SSRFinteractsh-clientSelf-hosted OOB listener for blind SSRF/XXE/RCE
Discovery: WAFwafw00f → tools/bypass_403.sh → tools/waf_encoder.py → waf_response_analyzer.pyFingerprint → soft-block aware bypass → encoded variants → score response
Exploit: 403tools/bypass_403.sh / byp4xxSoft-block (200+block body) aware; verdict: bypassed/needs_review/blocked
Exploit: Uploadtools/multipart_mutator.py --file shell --field fParser-confusion multipart variants
Exploit: Takeovertools/takeover_scanner.sh / subzyCNAME against vulnerable services
Exploit: Cloudtools/cloud_recon.sh + aws CLIScan bucket permissions -> extract metadata credentials
Exploit: Secretstools/secrets_hunter.sh / trufflehog --only-verifiedOnly verified working keys (no false positives)
Orchestratepython3 tools/hunt.py --target TRecon → lead ingest → EOL → scan (add --graphql / --cve-hunt as needed)
Session End Checklist
  • lead_board.py show <target> — any high-priority leads still new / stale?
  • Save all Burp/Caido project files
  • Record any "weird but not yet exploitable" behaviors (future gadgets)
  • Update notes with failed attempts (don't re-test with same techniques)
  • Log findings with /remember
  • touch every lead you killed or reported

© awarexone, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/bb-methodology of awarexone/Agentic-Bug-Hunter.

Open the folder on GitHubat commit cd58a40

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in awarexone/Agentic-Bug-Hunter, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Bug Bounty Hunting Methodology next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Bounty Hunting Methodology compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Bounty Hunting Methodology this skillawarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Bug Bounty Campaign DriverEncod3d-Sec/TORCH3291 repos~1.8kAutomated safety check: PassMIT
Recon Playbookbugbountywithmarco/bugbounty-disclosed-reports122—~550Automated safety check: PassNone
Gotchasyeswehack/claude-kit105—~4.3kAutomated safety check: WarnGPL-3.0
Unauthenticated API Endpoint Reconuphiago/recon-skills1.3k—~2kAutomated safety check: PassMIT

Similar skills

  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed
  • Recon Playbook

    bugbountywithmarco/bugbounty-disclosed-reports

    Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

    122 GitHub stars~550 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Gotchas

    yeswehack/claude-kit

    Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps.

    105 GitHub stars~4.3k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunt Cache Poison

    elementalsouls/Claude-BugHunter

    Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~5.7k tokensUpdated yesterday
    SecurityAuto-check passed

More from awarexone/Agentic-Bug-Hunter

All 10 skills in this repo
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    Auto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 2 days ago
    Auto-check passed
  • Meme Coin Security Audit

    awarexone/Agentic-Bug-Hunter

    Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

    5.3k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Bug Bounty Triage Validation

    awarexone/Agentic-Bug-Hunter

    Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.

    5.3k GitHub starsUsed in 3 repos~3.4k tokens
    Auto-check passed
  • Bug Bounty Report Writing

    awarexone/Agentic-Bug-Hunter

    Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.

    5.3k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check passed
  • Web2 Recon

    awarexone/Agentic-Bug-Hunter

    Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

    5.3k GitHub starsUsed in 2 repos~6.4k tokens
    Auto-check: warnings

Categories

Questions about Bug Bounty Hunting Methodology

What does Bug Bounty Hunting Methodology do?

Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments. The skill is a master orchestrator meant to start any hunting session, resume one after switching targets, or answer 'what should I do next' when the hunter feels lost; it routes to other skills based on the current phase. Its mindset section reframes hunting as proving a specific attack scenario rather than scanning for patterns, with a daily discipline of defining a target feature and CIA impact, selecting one or two vulnerability classes such as IDOR or race conditions, and executing only those without wandering, picking one of five goals per session: confidentiality, integrity, availability, account takeover or RCE.

When should I use Bug Bounty Hunting Methodology?

Bug Bounty Hunting Methodology fits situations like: starting a new bug bounty hunting session; switching to a new target and needing a fresh plan; feeling unsure what to do next in an ongoing hunt; deciding which vulnerability class to focus a session on.

How do I install Bug Bounty Hunting Methodology in Claude Code?

Run `npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a claude-code`. Or copy the skill folder (skills/bb-methodology in awarexone/Agentic-Bug-Hunter) into .claude/skills/bb-methodology in your project. Claude Code loads it when a task matches its description.

How do I install Bug Bounty Hunting Methodology in Codex?

Run `npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a codex`. Or copy the skill folder (skills/bb-methodology in awarexone/Agentic-Bug-Hunter) into .agents/skills/bb-methodology in your project. Codex loads it when a task matches its description.

Can I use Bug Bounty Hunting Methodology in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bb-methodology, .gemini/skills/bb-methodology, .github/skills/bb-methodology and .opencode/skills/bb-methodology in your project.

What does Bug Bounty Hunting Methodology need to run?

Going by SKILL.md and its folder, Bug Bounty Hunting Methodology needs the command-line tools its instructions call (python3, bash and curl).

Does Bug Bounty Hunting Methodology access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Bug Bounty Hunting Methodology safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bug Bounty Hunting Methodology use?

Bug Bounty Hunting Methodology is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Bounty Hunting Methodology use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Bounty Hunting Methodology?

Skills that share tags, products or a category with Bug Bounty Hunting Methodology: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Bug Bounty Campaign Driver (Encod3d-Sec/TORCH, 329 stars), Recon Playbook (bugbountywithmarco/bugbounty-disclosed-reports, 122 stars) and Gotchas (yeswehack/claude-kit, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Bounty Hunting Methodology?

awarexone (a GitHub organization) maintains it in awarexone/Agentic-Bug-Hunter, which has 5,282 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 5, 2026.

Source: awarexone/Agentic-Bug-Hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.