Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

No licenceAuto-check passedSecurity

Install Recon Playbook

skills CLI
$ npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill recon-playbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bugbountywithmarco/bugbounty-disclosed-reports recon-playbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bugbountywithmarco/bugbounty-disclosed-reports.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/recon-playbook .claude/skills/recon-playbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
recon-playbook
GitHub stars
120
Token cost
~550 tokens
SKILL.md length
221 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
None found

At a glance

Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

  • Works in 3 steps: Gather precedent. Use the shared search… → Extract patterns across the reports → Produce a playbook with these sections
  • The user asks how do I hunt for X
  • SKILL.md covers Workflow and Rules
  • Calls python3

What it does

Recon Playbook is an agent skill from bugbountywithmarco/bugbounty-disclosed-reports. Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus. Use when the user asks "how do I hunt for X", "give me a methodology / checklist for X", "what should I test on a <tech target", or wants a recon plan grounded in real disclosed bugs (e.g. SSRF, IDOR, rate-limit, cache deception, subdomain takeover, OAuth).

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Bug bounty and Rate limiting. The repository describes itself as: Public Disclosed Bug Bounty Reports formated in markdown.

When your agent uses it

  • The user asks how do I hunt for X
  • Give me a methodology / checklist for X
  • What should I test on a <tech target
  • Wants a recon plan grounded in real disclosed bugs (e.g

Example prompts

  • “how do I hunt for X”
  • “give me a methodology / checklist for X”
  • “what should I test on a <tech target”
  • “/recon-playbook”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Gather precedent. Use the shared search helper to pull the relevant reports
  2. Extract patterns across the reports
  3. Produce a playbook with these sections

What it can do on your machine

Read from SKILL.md and the folder at commit b6c76d1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Recon Playbook loads about 550 tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 221 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~550

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 221 words (~550 tokens).

“Turn the disclosed-report corpus into an actionable hunting playbook for a given vuln class or target type.”

— opening of SKILL.md by bugbountywithmarco
name
recon-playbook

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/recon-playbook of bugbountywithmarco/bugbounty-disclosed-reports.

Open the folder on GitHubat commit b6c76d1

Compare with similar skills

Recon Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Recon Playbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Recon Playbook this skillbugbountywithmarco/bugbounty-disclosed-reports120—~550Automated safety check: PassNone
Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT
Bug Bounty Campaign DriverEncod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT
Bug Bounty Triage Validationawarexone/Agentic-Bug-Hunter5.3k3 repos~3.4kAutomated safety check: PassMIT

Similar skills

  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Bug Bounty Triage Validation

    awarexone/Agentic-Bug-Hunter

    Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.

    5.3k GitHub starsUsed in 3 repos~3.4k tokens
    SecurityAuto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    SecurityAuto-check passed

More from bugbountywithmarco/bugbounty-disclosed-reports

  • Program Intel

    bugbountywithmarco/bugbounty-disclosed-reports

    Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

    120 GitHub stars~524 tokensUpdated 2 mo ago
    Auto-check passed
  • Severity

    bugbountywithmarco/bugbounty-disclosed-reports

    Estimate the severity of a vulnerability finding and produce a CVSS 3.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus.

    120 GitHub stars~478 tokensUpdated 2 mo ago
    Auto-check passed
  • Write Report

    bugbountywithmarco/bugbounty-disclosed-reports

    Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus.

    120 GitHub stars~585 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Recon Playbook

What does Recon Playbook do?

Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus. Recon Playbook is an agent skill from bugbountywithmarco/bugbounty-disclosed-reports. Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

When should I use Recon Playbook?

Recon Playbook fits situations like: the user asks how do I hunt for X; give me a methodology / checklist for X; what should I test on a <tech target; wants a recon plan grounded in real disclosed bugs (e.g.

How do I install Recon Playbook in Claude Code?

Run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill recon-playbook -a claude-code`. Or copy the skill folder (.claude/skills/recon-playbook in bugbountywithmarco/bugbounty-disclosed-reports) into .claude/skills/recon-playbook in your project. Claude Code loads it when a task matches its description.

How do I install Recon Playbook in Codex?

Run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill recon-playbook -a codex`. Or copy the skill folder (.claude/skills/recon-playbook in bugbountywithmarco/bugbounty-disclosed-reports) into .agents/skills/recon-playbook in your project. Codex loads it when a task matches its description.

Can I use Recon Playbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill recon-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/recon-playbook, .gemini/skills/recon-playbook, .github/skills/recon-playbook and .opencode/skills/recon-playbook in your project.

What does Recon Playbook need to run?

Going by SKILL.md and its folder, Recon Playbook needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Recon Playbook access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Recon Playbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Recon Playbook use?

No licence was found for Recon Playbook or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Recon Playbook use?

About 550 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Recon Playbook?

Skills that share tags, products or a category with Recon Playbook: Bug Bounty Hunting Methodology (awarexone/Agentic-Bug-Hunter, 5.3k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Bug Bounty Campaign Driver (Encod3d-Sec/TORCH, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Recon Playbook?

bugbountywithmarco (a GitHub user) maintains it in bugbountywithmarco/bugbounty-disclosed-reports, which has 120 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on July 14, 2026.

Source: bugbountywithmarco/bugbounty-disclosed-reports on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.