Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

No licenceAuto-check passedSecurity

Install Program Intel

skills CLI
$ npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill program-intel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bugbountywithmarco/bugbounty-disclosed-reports program-intel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bugbountywithmarco/bugbounty-disclosed-reports.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/program-intel .claude/skills/program-intel && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
program-intel
GitHub stars
122
Token cost
~524 tokens
SKILL.md length
192 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
None found

At a glance

Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

  • Works in 3 steps: Resolve the handle. Programs are… → Pull the program's reports → Synthesize an intel brief
  • The user names a program (e.g
  • SKILL.md covers Workflow and Rules
  • Calls python3

What it does

Program Intel is an agent skill from bugbountywithmarco/bugbounty-disclosed-reports. Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus. Use when the user names a program (e.g. shopify, gitlab, nextcloud, nodejs, uber, tiktok) and wants to know what's been found there, recurring weak spots, hot endpoints/assets, and what to avoid duplicating. Helps focus hunting and avoid dupes.

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Bug bounty. It works with Shopify, GitLab, Node.js and TikTok. The repository describes itself as: Public Disclosed Bug Bounty Reports formated in markdown.

When your agent uses it

  • The user names a program (e.g
  • Tasks that involve Bug bounty

Example prompts

  • “/program-intel”

Requirements

  • Python 3
  • Node.js

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the handle. Programs are identified by Handle in each report. List
  2. Pull the program's reports
  3. Synthesize an intel brief

What it can do on your machine

Read from SKILL.md and the folder at commit b6c76d1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Program Intel loads about 524 tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 192 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~524

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 192 words (~524 tokens).

“Profile a program from its disclosed reports so the user knows where to look and what's already been reported.”

— opening of SKILL.md by bugbountywithmarco
name
program-intel

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/program-intel of bugbountywithmarco/bugbounty-disclosed-reports.

Open the folder on GitHubat commit b6c76d1

Compare with similar skills

Program Intel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Program Intel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Program Intel this skillbugbountywithmarco/bugbounty-disclosed-reports122—~524Automated safety check: PassNone
Reviewing Pull RequestsShopify/shopify-app-js543—~1.9kAutomated safety check: PassMIT
Release Lambda LayerDataDog/datadog-lambda-js126—~1.8kAutomated safety check: PassApache-2.0
Deploy To Hostinghostinger/api-mcp-server159—~2.7kAutomated safety check: NotesMIT
Seedance Ecommerce Adbeshuaxian/higgsfield-seedance2-jineng882—~11kAutomated safety check: PassNone
Competitive Pricing Strategynexscope-ai/eCommerce-Skills1.1k—~2.8kAutomated safety check: PassMIT

Similar skills

  • Reviewing Pull Requests

    Shopify/shopify-app-js

    Official

    Reviews pull requests for Shopify/shopify-app-js with comprehensive analysis including semver compliance (MAJOR/MINOR/PATCH classification), single responsibility validation, pattern consistency…

    543 GitHub stars~1.9k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Release Lambda Layer

    DataDog/datadog-lambda-js

    Official

    Walks through releasing a new datadog-lambda-js Lambda layer version — the automated Commercial release (version bump, tag, GitLab sign/publish jobs, npm publish, GitHub release) and the manual…

    126 GitHub stars~1.8k tokensUpdated today
    Testing & QAAuto-check passed
  • Deploy To Hosting

    hostinger/api-mcp-server

    Deploy an existing project to a website on Hostinger web hosting (Shared, Cloud or Agency plans) and keep it deployed: picks the right deploy for static sites, Node.js apps (Next.js, Nuxt, Express…

    159 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Seedance Ecommerce Ad

    beshuaxian/higgsfield-seedance2-jineng

    Generate e-commerce product advertisement video prompts for Seedance 2.0 on Higgsfield.

    882 GitHub stars~11k tokensUpdated 6 mo ago
    Sales & SupportAuto-check passed
  • Competitive Pricing Strategy

    nexscope-ai/eCommerce-Skills

    Build an evidence-based competitive pricing strategy for ecommerce products.

    1.1k GitHub stars~2.8k tokensUpdated 1 mo ago
    Sales & SupportAuto-check passed
  • Cicd Pipeline Generator

    ailabs-393/ai-labs-claude-skills

    This skill should be used when creating or configuring CI/CD pipeline files for automated testing, building, and deployment.

    454 GitHub stars~2.7k tokensUpdated 11 mo ago
    DevOps & CloudAuto-check passed

More from bugbountywithmarco/bugbounty-disclosed-reports

  • Recon Playbook

    bugbountywithmarco/bugbounty-disclosed-reports

    Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

    122 GitHub stars~550 tokensUpdated 2 mo ago
    Auto-check passed
  • Severity

    bugbountywithmarco/bugbounty-disclosed-reports

    Estimate the severity of a vulnerability finding and produce a CVSS 3.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus.

    122 GitHub stars~478 tokensUpdated 2 mo ago
    Auto-check passed
  • Write Report

    bugbountywithmarco/bugbounty-disclosed-reports

    Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus.

    122 GitHub stars~585 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Program Intel

What does Program Intel do?

Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus. Program Intel is an agent skill from bugbountywithmarco/bugbounty-disclosed-reports. Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

When should I use Program Intel?

Program Intel fits situations like: the user names a program (e.g; tasks that involve Bug bounty.

How do I install Program Intel in Claude Code?

Run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill program-intel -a claude-code`. Or copy the skill folder (.claude/skills/program-intel in bugbountywithmarco/bugbounty-disclosed-reports) into .claude/skills/program-intel in your project. Claude Code loads it when a task matches its description.

How do I install Program Intel in Codex?

Run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill program-intel -a codex`. Or copy the skill folder (.claude/skills/program-intel in bugbountywithmarco/bugbounty-disclosed-reports) into .agents/skills/program-intel in your project. Codex loads it when a task matches its description.

Can I use Program Intel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill program-intel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/program-intel, .gemini/skills/program-intel, .github/skills/program-intel and .opencode/skills/program-intel in your project.

What does Program Intel need to run?

Going by SKILL.md and its folder, Program Intel needs the command-line tools its instructions call (python3). Our summary lists: Python 3; Node.js.

Does Program Intel access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Program Intel safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Program Intel use?

No licence was found for Program Intel or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Program Intel use?

About 524 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Program Intel?

Skills that share tags, products or a category with Program Intel: Reviewing Pull Requests (Shopify/shopify-app-js, 543 stars), Release Lambda Layer (DataDog/datadog-lambda-js, 126 stars), Deploy To Hosting (hostinger/api-mcp-server, 159 stars) and Seedance Ecommerce Ad (beshuaxian/higgsfield-seedance2-jineng, 882 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Program Intel?

bugbountywithmarco (a GitHub user) maintains it in bugbountywithmarco/bugbounty-disclosed-reports, which has 122 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on July 14, 2026.

Source: bugbountywithmarco/bugbounty-disclosed-reports on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.