Wooyun Legacy
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter triage-validation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/triage-validation .claude/skills/triage-validation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "triage-validation" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/triage-validation into .claude/skills/triage-validation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-validation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/triage-validationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter triage-validation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/triage-validation .agents/skills/triage-validation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "triage-validation" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/triage-validation into .agents/skills/triage-validation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-validation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter triage-validation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/triage-validation .cursor/skills/triage-validation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "triage-validation" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/triage-validation into .cursor/skills/triage-validation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-validation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/awarexone/Agentic-Bug-Hunter.git --path skills/triage-validation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter triage-validation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/triage-validation .gemini/skills/triage-validation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "triage-validation" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/triage-validation into .gemini/skills/triage-validation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-validation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awarexone/Agentic-Bug-Hunter triage-validationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/triage-validation .github/skills/triage-validation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "triage-validation" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/triage-validation into .github/skills/triage-validation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-validation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awarexone/Agentic-Bug-Hunter triage-validation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awarexone/Agentic-Bug-Hunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/triage-validation .opencode/skills/triage-validation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "triage-validation" agent skill from https://github.com/awarexone/Agentic-Bug-Hunter/tree/main/skills/triage-validation into .opencode/skills/triage-validation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-validation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
triage-validationScreens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.
Used before writing any bug bounty report, this skill decides whether a finding is worth submitting. It runs a seven-question gate in order, and a single wrong answer ends the review: the finding is dropped and the hunter moves on. The stated reason is protecting the validity ratio, since a not-applicable result counts against the hunter while an informative one is neutral.
The questions visible in the excerpt ask whether an attacker can use the bug right now with a real, copy-ready HTTP request, whether its impact is on the program's accepted list, whether the root cause sits in an in-scope production asset, whether it needs privileged access nobody could realistically get, whether it is already known or documented, and whether impact can be proven beyond technically possible. The description adds four pre-submission gates, an always-rejected list, a chain table, CVSS 3.1 and severity guides and a 60-second checklist.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit cd58a40. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Bug Bounty Triage Validation loads about 3.4k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,309 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from awarexone/Agentic-Bug-Hunter at commit cd58a40, republished under its MIT licence (© awarexone). 1,309 words, ~3,357 tokens.
.claude/skills/triage-validation/SKILL.md (or your agent's skills folder).One wrong answer = STOP. Kill it. Move on.
"N/A hurts your validity ratio. Informative is neutral. Only submit what passes all 7 questions."
Ask IN ORDER. One wrong answer = STOP immediately.
Complete this template:
1. Setup: I need [own account / another user's ID / no account]
2. Request: [exact HTTP method, URL, headers, body — copy-paste ready]
3. Result: I can [read / modify / delete] [exact data shown in response]
4. Impact: The real-world consequence is [account takeover / PII read / money stolen]
5. Cost: Time: [X minutes], Capital: [$0 / $X subscription required]If you CANNOT write step 2 as a real HTTP request → KILL IT.
Go to the program page. Find "Vulnerability Types" or "Out of Scope."
Common tiers:
If your bug maps to a listed exclusion → KILL IT.
Confirm:
*.internal.target.com)If out-of-scope → KILL IT.
Search:
is:issue label:security ENDPOINT_NAMEIf acknowledged/design decision → KILL IT.
alert(1) or alert(document.domain)If you can only show "technically possible" → DOWNGRADE severity, not kill.
Check the NEVER SUBMIT list below. If it's on this list without a chain → KILL IT.
For any finding made under an authenticated hunt, record the answer to each:
1. Session ID: [12-char BBHUNT_SESSION_ID hash from audit.jsonl]
2. Identity: [low-priv user A / high-priv user B / API key / etc.]
3. Anonymous repro: Does the same request work with NO auth header?
4. Cross-identity: Does it work under session B with the same data scope?
5. Stale-cred repro: Does a logged-out / expired session still get the data?Why this matters:
audit.jsonl entries are tagged with session_id. Re-run the request
under each identity and confirm the bug holds before writing the report.
This is the most common reason "confirmed IDOR" findings come back as N/A.
If you cannot answer the identity questions, treat the finding as unproven. Blank answers auto-fail on auth-related findings.
Run in sequence. ALL 4 must PASS.
[ ] Bug is REAL — confirmed with actual HTTP requests, not code reading alone
[ ] Bug is IN SCOPE — checked program scope page explicitly
[ ] Reproducible from scratch — can reproduce starting from fresh session
[ ] Evidence ready — screenshot, response body, or video[ ] Can answer: "What can attacker DO that they couldn't before?"
[ ] Answer is more than "see non-sensitive data" (unless program pays for info disclosure)
[ ] Real victim: another user's data, company's data, financial loss
[ ] Not relying on victim doing something unlikely[ ] Searched HackerOne Hacktivity for this program + similar bug title/endpoint
[ ] Searched GitHub issues for target repo
[ ] Read most recent 5 disclosed reports for this program
[ ] Not a "known issue" in their changelog or public docs
[ ] Google: "TARGET_NAME ENDPOINT_NAME bug bounty"[ ] Title: [Bug Class] in [Endpoint] allows [actor] to [impact]
[ ] Steps to Reproduce: copy-pasteable HTTP request
[ ] Evidence: screenshot/video of actual impact (not just 200 status)
[ ] Severity: matches CVSS 3.1 score AND program's severity definitions
[ ] Remediation: 1-2 sentences of concrete fix
[ ] NEVER used "could potentially" or "may allow"Submitting these destroys your validity ratio.
Missing CSP / HSTS / security headers
Missing SPF / DKIM / DMARC
GraphQL introspection alone (no auth bypass, no IDOR demonstrated)
Banner / version disclosure without working CVE exploit
Clickjacking on non-sensitive pages (no sensitive action PoC)
Tabnabbing
CSV injection (no actual code execution shown)
CORS wildcard (*) without credential exfil proof of concept
Logout CSRF
Self-XSS (only exploits own account)
Open redirect alone (no ATO or OAuth theft chain)
OAuth client_secret in mobile app (known, expected)
SSRF DNS callback only (no internal service access or data)
Host header injection alone (no password reset poisoning PoC)
Rate limit on non-critical forms (search, contact, login with Cloudflare)
Session not invalidated on logout
Concurrent sessions
Internal IP in error message
Mixed content
SSL weak ciphers
Missing HttpOnly / Secure cookie flags alone
Broken external links
Autocomplete on password fields
Pre-account takeover (usually — very specific conditions required)These pass basic gut-check but consistently come back N/A. Each row has a specific signal that tells you to kill it before writing the report.
| Finding | Why it N/As | Kill signal — if you see this, stop |
|---|---|---|
| Reflected XSS | CSP blocks execution; sandbox context; no session access | Dalfox found alert(1) but no cookie in response; Content-Security-Policy header present |
| SSRF — DNS callback only | No internal data reached; programs require HTTP response with data | Interactsh/Collaborator got DNS ping but no HTTP reply with internal content |
| IDOR — own data only | Attacker == victim; no cross-account access proven | User ID in response matches your own test account |
| SQLi — error message only | WAF filtered or error is cosmetic; no data exfiltrated | Got DB error string but no actual table rows returned |
CORS wildcard * | * blocks withCredentials; no PII actually exfiltrated | Access-Control-Allow-Credentials: true absent; credentialed request returns 403 |
| Rate limit missing — non-sensitive endpoint | Program only pays for rate-limit on auth/payment/OTP surfaces | Endpoint handles search, contact form, or sits behind Cloudflare |
Nuclei info template match | Version detection, not exploitation | Template severity is info; no CVE PoC executed against live service |
| MFA rate limit (no lockout) | Impact depends on OTP brute-force succeeding — it usually doesn't | 15 requests returned 200 but no OTP code was accepted |
| Open redirect alone | Redirect is informational without token theft chain | No OAuth redirect_uri parameter; no auth code or token in the redirected URL |
| Auth bypass — admin precondition | Requires compromised admin to trigger; attacker can't get there | "Admin can do X on behalf of user" — attacker must already be admin |
XSS via alert(document.domain) | Not proof of session theft | PoC shows domain popup only; no document.cookie exfil, no event listener |
| SAML metadata exposed | Disclosure only — aids attack but is not standalone impact | No private key or signing cert extracted; metadata is publicly documented by IdP |
Decision rule: if your finding matches a kill signal → classify as [INFORMATIONAL], do not run /validate, move on.
Build the chain first, prove it works end to end, THEN report.
| Standalone Finding | Chain Required | Valid Result |
|---|---|---|
| Open redirect | + OAuth redirect_uri → auth code theft | ATO (Critical) |
| Clickjacking | + sensitive action + working PoC | Medium |
| CORS wildcard | + credentialed request exfils user PII | High |
| CSRF | + sensitive action (transfer funds, change email, delete account) | High |
| Rate limit bypass | + OTP/reset token brute force succeeds | Medium/High |
| SSRF DNS-only | + internal service access + data returned | Medium |
| Host header injection | + password reset email uses injected host | High |
| Prompt injection | + reads other user's data (IDOR) | High |
| S3 bucket listing | + JS bundles contain API keys or OAuth secrets | Medium/High |
| Self-XSS | + CSRF to trigger it on victim without their knowledge | Medium |
| Subdomain takeover | + OAuth redirect_uri registered at that subdomain | Critical |
| GraphQL introspection | + auth bypass mutation or IDOR on node() | High |
| Finding | Score | Severity | Vector |
|---|---|---|---|
| IDOR read PII, any user, auth required | 6.5 | Medium | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| IDOR write/delete, any user | 7.5 | High | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| Auth bypass → admin panel | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Stored XSS → cookie theft, stored | 8.8 | High | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
| SQLi → full DB dump | 8.6 | High | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| SSRF → cloud metadata | 9.1 | Critical | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
| Race → double spend | 7.5 | High | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
| GraphQL auth bypass | 8.7 | High | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| JWT none algorithm | 9.1 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| What you have | Metric | Value |
|---|---|---|
| Exploitable over internet | AV | Network (N) |
| No special timing or race | AC | Low (L) |
| Free account needed | PR | Low (L) |
| No login needed | PR | None (N) |
| Admin needed | PR | High (H) |
| No victim action | UI | None (N) |
| Victim must click | UI | Required (R) |
| Reads all data | C | High (H) |
| Reads some data | C | Low (L) |
| Modifies all data | I | High (H) |
| Crashes service | A | High (H) |
| Affects only app | S | Unchanged (U) |
| Affects browser/OS/cloud | S | Changed (C) |
The goal is to QUICKLY disqualify bad leads so you hunt real bugs:
Writing a report before confirming the bug exists (most common)
Submitting theoretical impact without proof
"The API returns more fields than necessary" (sensitivity matters — is it actually sensitive?)
Chaining A+B into one report when they're separate bugs (two separate payouts)
Reporting B saying "similar to A in my other report" — fresh Gate 0 for every bug
Overclaiming severity — triagers trust you less next time
Under-describing impact — triager doesn't understand why it matters© awarexone, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/triage-validation of awarexone/Agentic-Bug-Hunter.
Open the folder on GitHubat commit cd58a40
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in awarexone/Agentic-Bug-Hunter, which our catalogue first saw on October 7, 2026.
Bug Bounty Triage Validation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Bug Bounty Triage Validation this skillawarexone/Agentic-Bug-Hunter | 5.3k | 3 repos | ~3.4k | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Bug Bounty Campaign DriverEncod3d-Sec/TORCH | 329 | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Recon Playbookbugbountywithmarco/bugbounty-disclosed-reports | 122 | — | ~550 | Automated safety check: Pass | None | |
| Gotchasyeswehack/claude-kit | 107 | — | ~4.3k | Automated safety check: Warn | GPL-3.0 | |
| Unauthenticated API Endpoint Reconuphiago/recon-skills | 1.3k | — | ~2k | Automated safety check: Pass | MIT |
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
bugbountywithmarco/bugbounty-disclosed-reports
Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.
yeswehack/claude-kit
Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps.
uphiago/recon-skills
Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.
elementalsouls/Claude-BugHunter
Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.
awarexone/Agentic-Bug-Hunter
Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.
awarexone/Agentic-Bug-Hunter
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
awarexone/Agentic-Bug-Hunter
Screens EVM and Solana meme coins for rug pull signs such as hidden mint, honeypot logic and fee tricks, starting with fast kill signals before any code review.
awarexone/Agentic-Bug-Hunter
Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.
awarexone/Agentic-Bug-Hunter
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…
Categories
Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early. Used before writing any bug bounty report, this skill decides whether a finding is worth submitting. It runs a seven-question gate in order, and a single wrong answer ends the review: the finding is dropped and the hunter moves on.
Bug Bounty Triage Validation fits situations like: deciding whether a bug bounty finding is worth reporting; checking a finding against a program's scope and impact list; looking for duplicates or intended behavior before submitting; estimating severity with a CVSS 3.1 quick reference.
Run `npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a claude-code`. Or copy the skill folder (skills/triage-validation in awarexone/Agentic-Bug-Hunter) into .claude/skills/triage-validation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a codex`. Or copy the skill folder (skills/triage-validation in awarexone/Agentic-Bug-Hunter) into .agents/skills/triage-validation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awarexone/Agentic-Bug-Hunter --skill triage-validation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-validation, .gemini/skills/triage-validation, .github/skills/triage-validation and .opencode/skills/triage-validation in your project.
SKILL.md names no scripts, command-line tools or credentials: Bug Bounty Triage Validation is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Bug Bounty Triage Validation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Bug Bounty Triage Validation: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Bug Bounty Campaign Driver (Encod3d-Sec/TORCH, 329 stars), Recon Playbook (bugbountywithmarco/bugbounty-disclosed-reports, 122 stars) and Gotchas (yeswehack/claude-kit, 107 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awarexone (a GitHub organization) maintains it in awarexone/Agentic-Bug-Hunter, which has 5,296 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 5, 2026.
Source: awarexone/Agentic-Bug-Hunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.