Agent skill

Bug Bounty Triage Validation

by awarexone in awarexone/Agentic-Bug-Hunter

Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.

MITAuto-check passedSecurity

Install Bug Bounty Triage Validation

skills CLI
$ npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awarexone/Agentic-Bug-Hunter triage-validation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/triage-validation .claude/skills/triage-validation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triage-validation
GitHub stars
5.3k
Used in
3 other repos
Token cost
~3.4k tokens
SKILL.md length
1,309 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.

  • Works in 4 steps: Program's HackerOne/Bugcrowd disclosed… → GitHub issues on target repo: is:issue… → Changelog/CHANGELOG.md — does it mention… → …
  • Deciding whether a bug bounty finding is worth reporting
  • SKILL.md covers THE 7-QUESTION GATE, 4 PRE-SUBMISSION GATES, NEVER SUBMIT LIST and COMMON N/A CLASSES — KILL…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Used before writing any bug bounty report, this skill decides whether a finding is worth submitting. It runs a seven-question gate in order, and a single wrong answer ends the review: the finding is dropped and the hunter moves on. The stated reason is protecting the validity ratio, since a not-applicable result counts against the hunter while an informative one is neutral.

The questions visible in the excerpt ask whether an attacker can use the bug right now with a real, copy-ready HTTP request, whether its impact is on the program's accepted list, whether the root cause sits in an in-scope production asset, whether it needs privileged access nobody could realistically get, whether it is already known or documented, and whether impact can be proven beyond technically possible. The description adds four pre-submission gates, an always-rejected list, a chain table, CVSS 3.1 and severity guides and a 60-second checklist.

When your agent uses it

  • Deciding whether a bug bounty finding is worth reporting
  • Checking a finding against a program's scope and impact list
  • Looking for duplicates or intended behavior before submitting
  • Estimating severity with a CVSS 3.1 quick reference

Example prompts

  • “Run the seven-question gate on this open redirect before I write it up.”
  • “Is an admin-only setting change a valid finding for this program?”
  • “Check whether my SSRF finding is a duplicate before I submit it.”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Program's HackerOne/Bugcrowd disclosed reports: Ctrl+F endpoint name + bug class
  2. GitHub issues on target repo: is:issue label:security ENDPOINT_NAME
  3. Changelog/CHANGELOG.md — does it mention this behavior?
  4. API docs / design docs — is it documented as intended?

What it can do on your machine

Read from SKILL.md and the folder at commit cd58a40. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Bounty Triage Validation loads about 3.4k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,309 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from awarexone/Agentic-Bug-Hunter at commit cd58a40, republished under its MIT licence (© awarexone). 1,309 words, ~3,357 tokens.

Download SKILL.mdSave it as .claude/skills/triage-validation/SKILL.md (or your agent's skills folder).
name
triage-validation
description
Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio.

TRIAGE & VALIDATION

One wrong answer = STOP. Kill it. Move on.

"N/A hurts your validity ratio. Informative is neutral. Only submit what passes all 7 questions."


THE 7-QUESTION GATE

Ask IN ORDER. One wrong answer = STOP immediately.


Q1: Can an attacker use this RIGHT NOW, step by step?

Complete this template:

1. Setup:   I need [own account / another user's ID / no account]
2. Request: [exact HTTP method, URL, headers, body — copy-paste ready]
3. Result:  I can [read / modify / delete] [exact data shown in response]
4. Impact:  The real-world consequence is [account takeover / PII read / money stolen]
5. Cost:    Time: [X minutes], Capital: [$0 / $X subscription required]

If you CANNOT write step 2 as a real HTTP request → KILL IT.


Q2: Is the impact on the program's accepted impact list?

Go to the program page. Find "Vulnerability Types" or "Out of Scope."

Common tiers:

  • Critical: Any-user ATO without interaction, RCE, SQLi with data exfil, admin auth bypass
  • High: Mass PII exfil, privilege escalation, internal SSRF with data, stored XSS all users
  • Medium: IDOR on specific user non-critical data, XSS on sensitive page requiring click
  • Low: Non-sensitive info disclosure, clickjacking with PoC

If your bug maps to a listed exclusion → KILL IT.


Q3: Is the root cause in an in-scope asset?

Confirm:

  • Vulnerable domain is on the in-scope list (not *.internal.target.com)
  • It's a production asset (not staging/dev unless explicitly in scope)
  • It's not a third-party service the company just uses (not Stripe, Salesforce, Google Auth)

If out-of-scope → KILL IT.


Q4: Does it require privileged access that an attacker can't realistically get?
  • "Admin can do X" = centralization risk = KILL IT (on 99% of programs)
  • "Non-admin can do X that only admin should do" = valid
  • "Requires physical access / MFA device" = usually invalid
  • "Requires compromised victim account to work" = questionable, low severity at best

Q5: Is this already known or accepted behavior?

Search:

  1. Program's HackerOne/Bugcrowd disclosed reports: Ctrl+F endpoint name + bug class
  2. GitHub issues on target repo: is:issue label:security ENDPOINT_NAME
  3. Changelog/CHANGELOG.md — does it mention this behavior?
  4. API docs / design docs — is it documented as intended?

If acknowledged/design decision → KILL IT.


Q6: Can you prove impact beyond "technically possible"?
  • XSS → show actual cookie theft or session hijack, not just alert(1) or alert(document.domain)
  • SSRF → hit an internal endpoint that returns data, not just DNS ping
  • SQLi → show actual data exfil from a real table, not just error message
  • IDOR → show actual other-user's data in response, not just a 200 status code

If you can only show "technically possible" → DOWNGRADE severity, not kill.


Q7: Is this a known-invalid bug class?

Check the NEVER SUBMIT list below. If it's on this list without a chain → KILL IT.


Q8: Identity check — which session found this, and does it survive?

For any finding made under an authenticated hunt, record the answer to each:

1. Session ID:        [12-char BBHUNT_SESSION_ID hash from audit.jsonl]
2. Identity:          [low-priv user A / high-priv user B / API key / etc.]
3. Anonymous repro:   Does the same request work with NO auth header?
4. Cross-identity:    Does it work under session B with the same data scope?
5. Stale-cred repro:  Does a logged-out / expired session still get the data?

Why this matters:

  • IDOR / BOLA: must work with session A reading session B's data — if it only works with no auth, that's "missing auth" not IDOR (different bug, different severity).
  • Priv-esc: must work with low-priv session reading high-priv data — if both sessions can already see it, no bug.
  • Auth bypass: must work without a valid session — if it stops working when you log out, you've found a permissions issue, not a bypass.
  • Always check both directions: a finding that only reproduces under one identity is often a real, scoped permission boundary, not a vuln.

audit.jsonl entries are tagged with session_id. Re-run the request under each identity and confirm the bug holds before writing the report. This is the most common reason "confirmed IDOR" findings come back as N/A.

If you cannot answer the identity questions, treat the finding as unproven. Blank answers auto-fail on auth-related findings.



4 PRE-SUBMISSION GATES

Run in sequence. ALL 4 must PASS.

Gate 0: Reality Check (30 seconds)
[ ] Bug is REAL — confirmed with actual HTTP requests, not code reading alone
[ ] Bug is IN SCOPE — checked program scope page explicitly
[ ] Reproducible from scratch — can reproduce starting from fresh session
[ ] Evidence ready — screenshot, response body, or video
Gate 1: Impact Validation (2 minutes)
[ ] Can answer: "What can attacker DO that they couldn't before?"
[ ] Answer is more than "see non-sensitive data" (unless program pays for info disclosure)
[ ] Real victim: another user's data, company's data, financial loss
[ ] Not relying on victim doing something unlikely
Gate 2: Deduplication Check (5 minutes)
[ ] Searched HackerOne Hacktivity for this program + similar bug title/endpoint
[ ] Searched GitHub issues for target repo
[ ] Read most recent 5 disclosed reports for this program
[ ] Not a "known issue" in their changelog or public docs
[ ] Google: "TARGET_NAME ENDPOINT_NAME bug bounty"
Gate 3: Report Quality (10 minutes)
[ ] Title: [Bug Class] in [Endpoint] allows [actor] to [impact]
[ ] Steps to Reproduce: copy-pasteable HTTP request
[ ] Evidence: screenshot/video of actual impact (not just 200 status)
[ ] Severity: matches CVSS 3.1 score AND program's severity definitions
[ ] Remediation: 1-2 sentences of concrete fix
[ ] NEVER used "could potentially" or "may allow"

NEVER SUBMIT LIST

Submitting these destroys your validity ratio.

Missing CSP / HSTS / security headers
Missing SPF / DKIM / DMARC
GraphQL introspection alone (no auth bypass, no IDOR demonstrated)
Banner / version disclosure without working CVE exploit
Clickjacking on non-sensitive pages (no sensitive action PoC)
Tabnabbing
CSV injection (no actual code execution shown)
CORS wildcard (*) without credential exfil proof of concept
Logout CSRF
Self-XSS (only exploits own account)
Open redirect alone (no ATO or OAuth theft chain)
OAuth client_secret in mobile app (known, expected)
SSRF DNS callback only (no internal service access or data)
Host header injection alone (no password reset poisoning PoC)
Rate limit on non-critical forms (search, contact, login with Cloudflare)
Session not invalidated on logout
Concurrent sessions
Internal IP in error message
Mixed content
SSL weak ciphers
Missing HttpOnly / Secure cookie flags alone
Broken external links
Autocomplete on password fields
Pre-account takeover (usually — very specific conditions required)

COMMON N/A CLASSES — KILL SIGNALS

These pass basic gut-check but consistently come back N/A. Each row has a specific signal that tells you to kill it before writing the report.

FindingWhy it N/AsKill signal — if you see this, stop
Reflected XSSCSP blocks execution; sandbox context; no session accessDalfox found alert(1) but no cookie in response; Content-Security-Policy header present
SSRF — DNS callback onlyNo internal data reached; programs require HTTP response with dataInteractsh/Collaborator got DNS ping but no HTTP reply with internal content
IDOR — own data onlyAttacker == victim; no cross-account access provenUser ID in response matches your own test account
SQLi — error message onlyWAF filtered or error is cosmetic; no data exfiltratedGot DB error string but no actual table rows returned
CORS wildcard ** blocks withCredentials; no PII actually exfiltratedAccess-Control-Allow-Credentials: true absent; credentialed request returns 403
Rate limit missing — non-sensitive endpointProgram only pays for rate-limit on auth/payment/OTP surfacesEndpoint handles search, contact form, or sits behind Cloudflare
Nuclei info template matchVersion detection, not exploitationTemplate severity is info; no CVE PoC executed against live service
MFA rate limit (no lockout)Impact depends on OTP brute-force succeeding — it usually doesn't15 requests returned 200 but no OTP code was accepted
Open redirect aloneRedirect is informational without token theft chainNo OAuth redirect_uri parameter; no auth code or token in the redirected URL
Auth bypass — admin preconditionRequires compromised admin to trigger; attacker can't get there"Admin can do X on behalf of user" — attacker must already be admin
XSS via alert(document.domain)Not proof of session theftPoC shows domain popup only; no document.cookie exfil, no event listener
SAML metadata exposedDisclosure only — aids attack but is not standalone impactNo private key or signing cert extracted; metadata is publicly documented by IdP

Decision rule: if your finding matches a kill signal → classify as [INFORMATIONAL], do not run /validate, move on.


Show full SKILL.md (390 more words)Show less

CONDITIONALLY VALID — CHAIN REQUIRED

Build the chain first, prove it works end to end, THEN report.

Standalone FindingChain RequiredValid Result
Open redirect+ OAuth redirect_uri → auth code theftATO (Critical)
Clickjacking+ sensitive action + working PoCMedium
CORS wildcard+ credentialed request exfils user PIIHigh
CSRF+ sensitive action (transfer funds, change email, delete account)High
Rate limit bypass+ OTP/reset token brute force succeedsMedium/High
SSRF DNS-only+ internal service access + data returnedMedium
Host header injection+ password reset email uses injected hostHigh
Prompt injection+ reads other user's data (IDOR)High
S3 bucket listing+ JS bundles contain API keys or OAuth secretsMedium/High
Self-XSS+ CSRF to trigger it on victim without their knowledgeMedium
Subdomain takeover+ OAuth redirect_uri registered at that subdomainCritical
GraphQL introspection+ auth bypass mutation or IDOR on node()High

CVSS 3.1 QUICK REFERENCE

Common Score Examples
FindingScoreSeverityVector
IDOR read PII, any user, auth required6.5MediumAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
IDOR write/delete, any user7.5HighAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Auth bypass → admin panel9.8CriticalAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Stored XSS → cookie theft, stored8.8HighAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
SQLi → full DB dump8.6HighAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
SSRF → cloud metadata9.1CriticalAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Race → double spend7.5HighAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
GraphQL auth bypass8.7HighAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
JWT none algorithm9.1CriticalAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Metric Quick Guide
What you haveMetricValue
Exploitable over internetAVNetwork (N)
No special timing or raceACLow (L)
Free account neededPRLow (L)
No login neededPRNone (N)
Admin neededPRHigh (H)
No victim actionUINone (N)
Victim must clickUIRequired (R)
Reads all dataCHigh (H)
Reads some dataCLow (L)
Modifies all dataIHigh (H)
Crashes serviceAHigh (H)
Affects only appSUnchanged (U)
Affects browser/OS/cloudSChanged (C)

KILL FAST RULES

The goal is to QUICKLY disqualify bad leads so you hunt real bugs:

  1. 5-minute rule: If you can't fill in Q1's template in 5 minutes → move on
  2. Precondition count: More than 2 preconditions simultaneously required → kill it
  3. Impact test: "What does attacker walk away with?" — if nothing tangible → kill it
  4. Admin bypass: "Admin can do X" is NEVER a bug → kill it immediately
  5. Design doc test: If it's documented behavior → kill it immediately
  6. Rabbit hole signal: 30+ min on Q6 with no reproducible PoC → kill it

ANTI-PATTERNS THAT LOSE MONEY

Writing a report before confirming the bug exists (most common)
Submitting theoretical impact without proof
"The API returns more fields than necessary" (sensitivity matters — is it actually sensitive?)
Chaining A+B into one report when they're separate bugs (two separate payouts)
Reporting B saying "similar to A in my other report" — fresh Gate 0 for every bug
Overclaiming severity — triagers trust you less next time
Under-describing impact — triager doesn't understand why it matters

© awarexone, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/triage-validation of awarexone/Agentic-Bug-Hunter.

Open the folder on GitHubat commit cd58a40

Used in 3 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in awarexone/Agentic-Bug-Hunter, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Bug Bounty Triage Validation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Bounty Triage Validation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Bounty Triage Validation this skillawarexone/Agentic-Bug-Hunter5.3k3 repos~3.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Bug Bounty Campaign DriverEncod3d-Sec/TORCH3291 repos~1.8kAutomated safety check: PassMIT
Recon Playbookbugbountywithmarco/bugbounty-disclosed-reports122—~550Automated safety check: PassNone
Gotchasyeswehack/claude-kit107—~4.3kAutomated safety check: WarnGPL-3.0
Unauthenticated API Endpoint Reconuphiago/recon-skills1.3k—~2kAutomated safety check: PassMIT

Similar skills

  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed
  • Recon Playbook

    bugbountywithmarco/bugbounty-disclosed-reports

    Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

    122 GitHub stars~550 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Gotchas

    yeswehack/claude-kit

    Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps.

    107 GitHub stars~4.3k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunt Cache Poison

    elementalsouls/Claude-BugHunter

    Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~5.7k tokensUpdated today
    SecurityAuto-check passed

More from awarexone/Agentic-Bug-Hunter

All 10 skills in this repo
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    Auto-check passed
  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    Auto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 2 days ago
    Auto-check passed
  • Meme Coin Security Audit

    awarexone/Agentic-Bug-Hunter

    Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.

    5.3k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Bug Bounty Report Writing

    awarexone/Agentic-Bug-Hunter

    Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.

    5.3k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check passed
  • Web2 Recon

    awarexone/Agentic-Bug-Hunter

    Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

    5.3k GitHub starsUsed in 2 repos~6.4k tokens
    Auto-check: warnings

Categories

Questions about Bug Bounty Triage Validation

What does Bug Bounty Triage Validation do?

Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early. Used before writing any bug bounty report, this skill decides whether a finding is worth submitting. It runs a seven-question gate in order, and a single wrong answer ends the review: the finding is dropped and the hunter moves on.

When should I use Bug Bounty Triage Validation?

Bug Bounty Triage Validation fits situations like: deciding whether a bug bounty finding is worth reporting; checking a finding against a program's scope and impact list; looking for duplicates or intended behavior before submitting; estimating severity with a CVSS 3.1 quick reference.

How do I install Bug Bounty Triage Validation in Claude Code?

Run `npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a claude-code`. Or copy the skill folder (skills/triage-validation in awarexone/Agentic-Bug-Hunter) into .claude/skills/triage-validation in your project. Claude Code loads it when a task matches its description.

How do I install Bug Bounty Triage Validation in Codex?

Run `npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a codex`. Or copy the skill folder (skills/triage-validation in awarexone/Agentic-Bug-Hunter) into .agents/skills/triage-validation in your project. Codex loads it when a task matches its description.

Can I use Bug Bounty Triage Validation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-validation, .gemini/skills/triage-validation, .github/skills/triage-validation and .opencode/skills/triage-validation in your project.

What does Bug Bounty Triage Validation need to run?

SKILL.md names no scripts, command-line tools or credentials: Bug Bounty Triage Validation is instructions for the agent only.

Does Bug Bounty Triage Validation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bug Bounty Triage Validation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bug Bounty Triage Validation use?

Bug Bounty Triage Validation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Bounty Triage Validation use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Bounty Triage Validation?

Skills that share tags, products or a category with Bug Bounty Triage Validation: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Bug Bounty Campaign Driver (Encod3d-Sec/TORCH, 329 stars), Recon Playbook (bugbountywithmarco/bugbounty-disclosed-reports, 122 stars) and Gotchas (yeswehack/claude-kit, 107 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Bounty Triage Validation?

awarexone (a GitHub organization) maintains it in awarexone/Agentic-Bug-Hunter, which has 5,296 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 5, 2026.

Source: awarexone/Agentic-Bug-Hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.