Wooyun Legacy
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter bb-methodology --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bb-methodology .claude/skills/bb-methodology && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "bb-methodology" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/bb-methodology into .claude/skills/bb-methodology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bb-methodology", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/bb-methodologyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter bb-methodology --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/bb-methodology .agents/skills/bb-methodology && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "bb-methodology" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/bb-methodology into .agents/skills/bb-methodology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bb-methodology", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter bb-methodology --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/bb-methodology .cursor/skills/bb-methodology && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "bb-methodology" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/bb-methodology into .cursor/skills/bb-methodology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bb-methodology", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/awarexone/Agentic-Bug-Hunter.git --path skills/bb-methodology--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter bb-methodology --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/bb-methodology .gemini/skills/bb-methodology && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "bb-methodology" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/bb-methodology into .gemini/skills/bb-methodology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bb-methodology", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awarexone/Agentic-Bug-Hunter bb-methodologyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/bb-methodology .github/skills/bb-methodology && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "bb-methodology" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/bb-methodology into .github/skills/bb-methodology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bb-methodology", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter bb-methodology --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/bb-methodology .opencode/skills/bb-methodology && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "bb-methodology" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/bb-methodology into .opencode/skills/bb-methodology/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "bb-methodology", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
bb-methodologyOrchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
The skill is a master orchestrator meant to start any hunting session, resume one after switching targets, or answer 'what should I do next' when the hunter feels lost; it routes to other skills based on the current phase. Its mindset section reframes hunting as proving a specific attack scenario rather than scanning for patterns, with a daily discipline of defining a target feature and CIA impact, selecting one or two vulnerability classes such as IDOR or race conditions, and executing only those without wandering, picking one of five goals per session: confidentiality, integrity, availability, account takeover or RCE.
Four thinking domains structure the approach: critical thinking that questions trust boundaries and reverse-engineers developer psychology (a new feature probably skipped the auth checks an older one has), multi-perspective checks across horizontal and vertical roles, data flow and timing, tactical pattern detection such as naming anomalies that hint at a different, less careful developer, and What-If experiments like hitting a checkout-success URL directly or replaying a request many times at once to probe for a race condition.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cd58a40. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3bashcurlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bug Bounty Hunting Methodology loads about 4.7k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 1,881 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from awarexone/Agentic-Bug-Hunter at commit cd58a40, republished under its MIT licence (© awarexone). 1,881 words, ~4,727 tokens.
.claude/skills/bb-methodology/SKILL.md (or your agent's skills folder).Master orchestrator for hunting sessions. Combines the 5-phase non-linear workflow with the critical thinking framework that separates top 1% hunters from the rest.
Hunting is not "find a bug" -- it is "prove an attack scenario." Think like an attacker with a specific goal, not a scanner looking for patterns.
Before touching any tool:
Question trust boundaries:
user_role=user cookie? Change to adminprice=1000 in POST? Change to 1<script> blocked? Try <img onerror=...>Reverse-engineer developer psychology:
/api/v2/user exists -> Does /api/v1/user still work with weaker auth?What-If experiments:
/checkout/success directly/dashboardguid=f8a2... with id=100 on sibling endpoint -> IDOR?| Perspective | What to check |
|---|---|
| Horizontal (same role) | User A's token + User B's ID -> IDOR |
| Vertical (different role) | Regular user -> /admin/deleteUser |
| Data flow (proxy view) | Hidden params in JSON: debug=false, discount_rate |
| Time/State | Race conditions, post-delete session reuse |
| Client environment | Mobile UA -> legacy API with weaker auth |
| Business impact | "What's the $ damage if this breaks?" |
userId everywhere but suddenly user_id -> different dev, weaker security200 OK with tiny response or "just a moment" text → WAF soft block, not a real response. Run bypass_403.sh to confirm and get baseline diff.Use AI to expand hypotheses, not to declare verdicts. The model is a fast adversarial planner; the browser, proxy, and live requests are the proof layer.
High-signal prompts:
| Phase | Amateur | Pro |
|---|---|---|
| Recon | Main domain only | Shadow IT, dev environments, all assets |
| Discovery | Look for errors | Look for design contradictions, business logic flaws |
| Exploit | Give up when blocked | Build filter-bypass payloads |
| Escalation | Report the phenomenon only | Chain to real harm (session steal, ATO) |
| Feasibility | Include unrealistic conditions | Minimize attack prerequisites |
| Reporting | State facts only | Quantify business risk |
| Retest | Check if old PoC fails | Analyze fix method, find incomplete patches |
+-------------------------------------------------+
| |
| +----------+ +----------+ +----------+ |
| | 1. RECON |---+| 2. MAP |---+| 3. FIND | |
| +----------+ +-----+----+ +-----+-----+ |
| ^ | | |
| | v v |
| | +----------+ +----------+ |
| +----------| 4. PROVE |---+| 5. REPORT| |
| +----------+ +----------+ |
| |
| Non-linear: stuck at any phase -> go back |
| New API found at phase 3 -> return to phase 2 |
| WAF blocks at phase 4 -> origin IP from phase 1 |
+-------------------------------------------------+THIS IS NOT LINEAR. Move freely between phases. When stuck, return to a previous phase.
Before touching any tool, answer these:
docs/auth-sessions.md. Then
every downstream tool (httpx, katana, ffuf, nuclei, dalfox, PoC verifiers)
sends those headers automatically and audit log entries are stamped with
a stable session_id hash.Route selection -- Wide or Deep?
| Signal | Wide (recon sweep) | Deep (focused testing) |
|---|---|---|
| New program, first day | X | |
Wildcard scope *.target.com | X | |
| Main webapp, been here >3 days | X | |
| Scope update (new domain added) | X | |
| Found interesting subdomain | X | |
| Hunting IDOR / BOLA / auth bugs | X (auth-aware) |
Goal: Maximize attack surface. Find what others missed.
Wide approach (initial sweep):
Subdomain enum -> DNS resolution -> HTTP probing -> Port scan -> Tech detectDeep approach (targeted):
Google Dorks -> JS file download -> Hidden param discovery -> API mapping| What you find | Next action |
|---|---|
| Live subdomains with tech stack | Phase 2 (Mapping) |
| Known software (WordPress, Jira) | Check CVEs + defaults immediately |
| Cloud resources (S3, Firebase) | Test permissions (read/write/list) |
| 403 or 200 + block page on endpoint | tools/bypass_403.sh <url> auto-detects soft blocks (200+block-body). Verdict: bypassed/needs_review/blocked. If all blocked after 5 min, skip |
| Nothing after 5 min on a host | Skip, try next host (5-minute rule) |
Command: /recon target.com
After every recon (mandatory):
python3 tools/lead_board.py ingest target.com
python3 tools/lead_board.py show target.com
python3 tools/lead_board.py next target.com
# Route in plain language: "GraphQL endpoint → skills/graphql-audit"
# touch status when you start / kill / report a lead(hunt.py runs ingest + EOL automatically unless --skip-leads.)
Goal: Understand the app like its developer does.
Checklist:
| What you find | Next action |
|---|---|
| JS files with interesting code | Taint analysis (Sink -> Source) |
| OAuth/SAML authentication | OAuth/SAML checklist |
| API with ID parameters | Phase 3, target IDOR |
| Complex business logic (payment, coupon) | Phase 3, target BizLogic |
| postMessage listeners | DOM analysis, postMessage-tracker |
Goal: Find the bug. Use Error-based first, then Blind-based.
Decision flow based on what you're testing:
What input are you testing?
+-- ID parameter (user_id, order_id)
| -> IDOR checklist
+-- Search/filter/sort field
| -> SQLi, NoSQLi probing
+-- URL input / webhook / PDF gen
| -> SSRF checklist
+-- Text field reflected in page
| -> XSS (DOM or reflected)
+-- File upload
| -> SVG XSS, web shell, path traversal
+-- Price/quantity/coupon
| -> Business logic, race conditions
+-- Login / 2FA / password reset
| -> Auth bypass
+-- Profile update API
| -> Mass Assignment
+-- Template / wiki editor
| -> SSTI
+-- Nothing obvious
-> Fuzz with ffuf, try Error-based probingError vs Blind decision:
', ", {{7*7}}, ${7*7}) -- watch for 500 errors, stack tracesSLEEP(10), ; sleep 10;) -- watch response timecurl attacker.com, interactsh) -- watch for DNS callbackAND 1=1 vs AND 1=0) -- watch content-length diff| What you find | Next action |
|---|---|
| Low-impact behavior (redirect, self-XSS, cookie injection) | Chain it -- find a connector gadget |
| Confirmed vuln (XSS, IDOR, SQLi) | Phase 4 (Prove and Escalate) |
| Blocked by WAF/CSP/403 or soft-block 200 | /bypass-403 <url> → check verdict (not just status) → tools/waf_encoder.py "<payload>" → if upload: tools/multipart_mutator.py → 5 min, kill |
| Known software vuln (CVE) | 1-day speed workflow |
| Nothing after 20 min on this endpoint | Rotate (20-minute rule) |
Goal: Prove maximum business impact. Turn Low into Critical.
Escalation decision:
What did you find?
+-- XSS
| +-- Can steal cookie/token? -> Session hijack -> ATO
| +-- Cookie is HttpOnly? -> Force email change via XHR -> ATO
| +-- Self-XSS only? -> Find CSRF to trigger it
+-- IDOR
| +-- Can read PII? -> Automate scraping, show scale
| +-- Can change password/email? -> Direct ATO
| +-- UUID only? -> Find UUID leak source, then retry
+-- SSRF
| +-- DNS only? -> DON'T REPORT. Try cloud metadata
| +-- Can reach 169.254.169.254? -> Extract keys -> RCE
| +-- Internal port scan? -> Find Redis/K8s -> RCE
+-- SQLi
| +-- Error-based? -> Extract data (passwords, tokens)
| +-- Can INTO OUTFILE? -> Web shell -> RCE
| +-- Blind? -> Boolean/Time extraction
+-- Open Redirect
| +-- OAuth flow? -> Token theft -> ATO
| +-- javascript: scheme? -> XSS
+-- Blocked by defense
| -> Bypass (WAF/CSP/proxy/sanitizer/2FA)
+-- Low-impact, can't escalate alone
-> Find connector gadget for chainAfter proving impact, check:
Goal: Get paid. Make triager's job easy.
Pre-report gate:
Run /validate (7-Question Gate)
+-- All 7 pass? -> Write report
+-- Any fail? -> KILL the finding. Don't waste time.
+-- Borderline? -> Run /triage for quick go/no-goReport:
Run /report
+-- Platform-specific format (H1/Bugcrowd/Intigriti/Immunefi)
+-- Title: [Bug Class] in [Endpoint] allows [role] to [impact]
+-- Impact-first summary (sentence 1 = what attacker CAN do)
+-- Exact HTTP requests in Steps to Reproduce
+-- Under 600 words
+-- CVSS 3.1 score that MATCHES actual impactAfter submission:
/remember for hunt memory| I'm stuck because... | Go to... |
|---|---|
| Can't find any subdomains | Phase 1: Try different recon sources, Google Dorks |
| Found subdomain but don't know what to test | Phase 2: Map the app, download JS, understand auth |
| Testing but nothing works | Phase 3: Switch vuln class (20-min rotation rule) |
| Found a bug but impact is low | Phase 4: Escalation paths or gadget chaining |
| WAF/CSP/403 blocking my payload | /bypass-403 → fingerprint WAF → waf_encoder.py variants → kill if 5 min spent (403 even after /bypass-403 + WAF fingerprint + waf_encoder.py variants) |
| Been stuck for 45 min on one param | STOP. Rabbit hole. Move to next endpoint. |
| New API endpoint discovered during testing | Return to Phase 2: map it before attacking |
| Found one bug | A->B signal: same dev made more mistakes. Hunt 20 min for siblings. |
Every 20 minutes ask yourself: "Am I making progress?"
| Phase | Tools | Why this order |
|---|---|---|
| Recon: Subdomains | subfinder -> amass -> puredns -> httpx | Passive first (no detection) -> resolve DNS -> probe HTTP + tech stack |
| Recon: URLs | gau + waymore -> katana -> uro | Archive (forgotten endpoints) -> active crawl (JS-rendered) -> deduplicate |
| Recon: JS | jsluice + mantra + trufflehog --only-verified | Extract URLs/secrets -> find API keys -> verify keys actually work |
| Recon: Ports | naabu (wide) -> rustscan (deep) | Fast top-1000 sweep -> full 65535 on interesting targets |
| Recon: Scan | nuclei -tags cve -> nuclei -tags takeover | Known CVEs first -> then takeover (act immediately) |
| After recon (ALWAYS) | python3 tools/lead_board.py ingest <target> → show → next | Route every signal to a hunt-* skill; never lose a lead. touch when you start/kill/report |
| After recon: EOL | python3 tools/eol_check.py --tech "php=7.4,nginx=1.18" | Flag EOL products from technologies.txt fingerprints |
| Mapping: Params | arjun + paramspider + ParamMiner / tools/param_discovery.sh | Brute-force hidden params + mine archives + cache headers |
| Mapping: GraphQL | bash tools/graphql_audit.sh <url> | Introspection → fingerprint → batching → IDOR → injection |
| Mapping: CI/CD | bash tools/cicd_scanner.sh owner/repo | Workflow injection / secret exfil / runner poisoning |
| Mapping: JS code | Download -> jsluice -> VS Code/Cursor grep | Extract -> static analysis -> AI-assisted taint analysis |
| Mapping: Dorks | Manual Google Dorks | Custom per-target queries find what automation misses |
| Discovery: Fuzz | ffuf -ac + cewl custom wordlist | Auto-calibrate filtering + target-specific words beat generic lists |
| Discovery: XSS | kxss -> dalfox | Filter (which params reflect?) -> scan (only reflective params) |
| Discovery: SQLi | ghauri | Modern blind SQLi on ID-like parameters |
| Discovery: SSRF | interactsh-client | Self-hosted OOB listener for blind SSRF/XXE/RCE |
| Discovery: WAF | wafw00f → tools/bypass_403.sh → tools/waf_encoder.py → waf_response_analyzer.py | Fingerprint → soft-block aware bypass → encoded variants → score response |
| Exploit: 403 | tools/bypass_403.sh / byp4xx | Soft-block (200+block body) aware; verdict: bypassed/needs_review/blocked |
| Exploit: Upload | tools/multipart_mutator.py --file shell --field f | Parser-confusion multipart variants |
| Exploit: Takeover | tools/takeover_scanner.sh / subzy | CNAME against vulnerable services |
| Exploit: Cloud | tools/cloud_recon.sh + aws CLI | Scan bucket permissions -> extract metadata credentials |
| Exploit: Secrets | tools/secrets_hunter.sh / trufflehog --only-verified | Only verified working keys (no false positives) |
| Orchestrate | python3 tools/hunt.py --target T | Recon → lead ingest → EOL → scan (add --graphql / --cve-hunt as needed) |
lead_board.py show <target> — any high-priority leads still new / stale?/remembertouch every lead you killed or reported© awarexone, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/bb-methodology of awarexone/Agentic-Bug-Hunter.
Open the folder on GitHubat commit cd58a40
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in awarexone/Agentic-Bug-Hunter, which our catalogue first saw on October 7, 2026.
Bug Bounty Hunting Methodology next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bug Bounty Hunting Methodology this skillawarexone/Agentic-Bug-Hunter | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Bug Bounty Campaign DriverEncod3d-Sec/TORCH | 329 | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Recon Playbookbugbountywithmarco/bugbounty-disclosed-reports | 122 | — | ~550 | Automated safety check: Pass | None | |
| Gotchasyeswehack/claude-kit | 105 | — | ~4.3k | Automated safety check: Warn | GPL-3.0 | |
| Unauthenticated API Endpoint Reconuphiago/recon-skills | 1.3k | — | ~2k | Automated safety check: Pass | MIT |
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
bugbountywithmarco/bugbounty-disclosed-reports
Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.
yeswehack/claude-kit
Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps.
uphiago/recon-skills
Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.
elementalsouls/Claude-BugHunter
Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
awarexone/Agentic-Bug-Hunter
Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.
awarexone/Agentic-Bug-Hunter
Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.
awarexone/Agentic-Bug-Hunter
Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.
awarexone/Agentic-Bug-Hunter
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…
Categories
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments. The skill is a master orchestrator meant to start any hunting session, resume one after switching targets, or answer 'what should I do next' when the hunter feels lost; it routes to other skills based on the current phase. Its mindset section reframes hunting as proving a specific attack scenario rather than scanning for patterns, with a daily discipline of defining a target feature and CIA impact, selecting one or two vulnerability classes such as IDOR or race conditions, and executing only those without wandering, picking one of five goals per session: confidentiality, integrity, availability, account takeover or RCE.
Bug Bounty Hunting Methodology fits situations like: starting a new bug bounty hunting session; switching to a new target and needing a fresh plan; feeling unsure what to do next in an ongoing hunt; deciding which vulnerability class to focus a session on.
Run `npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a claude-code`. Or copy the skill folder (skills/bb-methodology in awarexone/Agentic-Bug-Hunter) into .claude/skills/bb-methodology in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a codex`. Or copy the skill folder (skills/bb-methodology in awarexone/Agentic-Bug-Hunter) into .agents/skills/bb-methodology in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awarexone/Agentic-Bug-Hunter --skill bb-methodology -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bb-methodology, .gemini/skills/bb-methodology, .github/skills/bb-methodology and .opencode/skills/bb-methodology in your project.
Going by SKILL.md and its folder, Bug Bounty Hunting Methodology needs the command-line tools its instructions call (python3, bash and curl).
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bug Bounty Hunting Methodology is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bug Bounty Hunting Methodology: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Bug Bounty Campaign Driver (Encod3d-Sec/TORCH, 329 stars), Recon Playbook (bugbountywithmarco/bugbounty-disclosed-reports, 122 stars) and Gotchas (yeswehack/claude-kit, 105 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awarexone (a GitHub organization) maintains it in awarexone/Agentic-Bug-Hunter, which has 5,282 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 5, 2026.
Source: awarexone/Agentic-Bug-Hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.