Agent skill

Bug Bounty Campaign Driver

by Encod3d-Sec in Encod3d-Sec/TORCH

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

MITAuto-check passedSecurity

Install Bug Bounty Campaign Driver

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill bb-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH bb-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/bb-workflow .claude/skills/bb-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bb-workflow
GitHub stars
329
Used in
1 other repo
Token cost
~1.8k tokens
SKILL.md length
881 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

  • Works in 4 steps: python3 scripts/campaign.py init --type… → Passes 0-3 (OSINT/Wayback, crawl,… → python3 scripts/campaign.py board -… → …
  • Starting a bug-bounty engagement from a programme scope file
  • SKILL.md covers The loop, Start / resume, Browser observation… and Gates (the driver enforces; do…, plus 5 more sections
  • Calls python3 and bash

What it does

The skill is built around scripts/campaign.py. The agent runs campaign.py next, does exactly what the printed action block lists, records the outcome with the note command and repeats, so the driver rather than free-form prose enforces the gates. Starting or resuming goes through init, which validates scope.md and the autonomy envelope and stops when scope.md is empty, so you have to fill it from the programme brief first.

Early passes cover OSINT and Wayback lookups, crawling, fingerprinting and CVE checks, all feeding state.md, and the agent must read JavaScript bundles and handlers end to end rather than only grep them. The board command then writes the killchain rows and next serves one at a time. For internet targets it drives a real browser through the chrome-devtools MCP to list network requests and capture rendered evidence, and uses a VM-side browser for hosts behind a VPN. It is designed to run without operator approvals, so it belongs only on programmes you are authorized to test.

When your agent uses it

  • Starting a bug-bounty engagement from a programme scope file
  • Resuming a half-finished campaign from the driver's saved state
  • Working through a wildcard scope with one required step printed per turn
  • Collecting browser-based evidence for a web finding

Example prompts

  • “Run the bb workflow on this programme, whose scope is in scope.md.”
  • “Resume the campaign and tell me what the driver says to do next.”
  • “Initialize a bug-bounty campaign for the *.example.com wildcard scope.”

Requirements

  • Python 3 for scripts/campaign.py
  • A filled-in scope.md for the programme
  • The chrome-devtools MCP for browser observation

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. python3 scripts/campaign.py init --type bb - validates scope.md + the autonomy envelope,
  2. Passes 0-3 (OSINT/Wayback, crawl, fingerprint, CVE) feed state.md. Read every JS bundle and
  3. python3 scripts/campaign.py board - writes the killchain 4a rows. Refuses on an empty state.
  4. Enter the loop. next serves one row, depth-first, one open row at a time.

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bug Bounty Campaign Driver loads about 1.8k tokens when it runs. Until then it costs about 135 tokens; SKILL.md has 881 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 881 words, ~1,811 tokens.

Download SKILL.mdSave it as .claude/skills/bb-workflow/SKILL.md (or your agent's skills folder).
name
bb-workflow
description
Autonomous bug-bounty campaign driver. Runs a full programme end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (including which Skill and tool to run) every turn. Use when starting or resuming a bug-bounty engagement, "run the bb workflow", "hunt this program", "9-pass campaign", or when handed a *.scope wildcard to test for TIER1 findings. Single agent, refuter-verified, wiki-first, tool-first.

bb-workflow

The driver is the plan. You run one command, do exactly what it prints, record the result, repeat. Nothing here is advisory: the gates are enforced by scripts/campaign.py, so follow its output literally rather than improvising. This exists because prose routing failed - 22 Skill calls against 341 hand-rolled curls in the reference campaign; the board fixes that by making the mandate tool output, fresh every turn.

The loop

python3 scripts/campaign.py next        # prints ONE required-action block
# do EXACTLY what it lists, in order
python3 scripts/campaign.py note <row> --arsenal <slug>     # after Skill(wiki-arsenal)
python3 scripts/campaign.py done <row> --poc <img> --kind req   # | --dead R | --park Q | --find F
# repeat

Start / resume

  1. python3 scripts/campaign.py init --type bb - validates scope.md + the autonomy envelope, repairs engagement_type/schema, prints the Deadends size. If it exits 2, fix what it names (an empty scope.md is the one thing it cannot invent - fill it from the programme brief first).
  2. Passes 0-3 (OSINT/Wayback, crawl, fingerprint, CVE) feed state.md. Read every JS bundle and handler end to end (Skill-less; volume-reduce first: source-map, drop vendor, beautify, read). Grep never substitutes for the read.
  3. python3 scripts/campaign.py board - writes the killchain 4a rows. Refuses on an empty state.
  4. Enter the loop. next serves one row, depth-first, one open row at a time.

Browser observation (chrome-devtools MCP)

The programme's targets are internet-reachable, so drive them through a real browser, not just curl - a modern site's real attack surface is only visible rendered. Use the chrome-devtools MCP:

  • Pass 1 crawl: navigate_page to each app, then list_network_requests - the XHR/fetch calls a page makes reveal the API endpoints/routes a static crawl never sees (this is exactly the lead a curl-only recon misses). take_snapshot for the rendered DOM; evaluate_script to read client config / __NEXT_DATA__ / JS globals.
  • Confirmation + evidence: DOM-XSS fires in the real DOM (evaluate_script / console); a rendered take_screenshot of the exploited state is a valid web PoC (G3).

Caveat: chrome-devtools drives a local browser, so it only reaches internet targets. For a VPN-boxed host it cannot connect - use the VM-side browser (scripts/browser.sh / capture.sh web) as the equivalent. pt-workflow / ctf-workflow default to the VM browser for that reason.

Manual login / MFA the agent cannot do headlessly (Smart-ID, Mobile-ID, a CAPTCHA) -> Skill(chrome-devtools-browser): a VISIBLE chromium on the VM desktop (scripts/browser-visible.sh) the operator logs into, driven + observed live via the chrome-devtools MCP - capture the authenticated session and the real /… API calls, then feed the hunt skills.

Gates (the driver enforces; do not fight them)

  • G1 no exploit action until the row's arsenal card exists (Skill(wiki-arsenal) fills it).
  • G2 a row cannot close unless its mapped Skill(hunt-*) actually fired.
  • G3 a row cannot close without typed evidence: req (default), burp, or web (visual classes only). A page render is not evidence of a bug.
  • G8 run the mapped tool before hand-rolling; the driver warns if you skipped it.

Autonomy

No approvals. Out-of-envelope work parks to decisions.md and the loop moves on - it never blocks and never asks a question. A confirmed TIER1 is written up and chained but does not stop the run; the campaign ends when the board is exhausted (two dry reframe rounds) or the request budget is spent.

Show full SKILL.md (396 more words)Show less

Model routing

Explicit per-role model assignment (the driver enforces the verifier gate; the rest is operating policy):

  • Main brain - Opus 5 1M: the campaign.py loop, board/state, strategy, Burp/chrome-devtools, finding write-ups. This session.
  • Verifier - Opus (fresh context), MANDATORY: before any CONFIRMED, campaign.py verify <F> prints an Opus refuter prompt; dispatch ONE fresh Opus agent that reads the raw PoC, tries to REFUTE, and writes verdicts/<F>.json. done --find refuses unless that verdict exists, is refuted:false, and cites the finding's PoC (anti-rubber-stamp). Fails CLOSED.
  • RTL - Opus (fresh context): Skill(redteamlead) for direction at a fork or when a vector stalls.
  • Short tasks - Haiku: Skill(wiki-arsenal) deep, Skill(delegate) (mechanical exploit-run), Skill(ingest) recon-parse. Bounded, fully-specified, single-shot ONLY.

The line that keeps quota safety: Haiku is allowed for a bounded single job, never for open-ended parallel hunting.

Discipline (carried, not restated - hunt-core owns the gates)

  • Do NOT invoke superpowers:brainstorming or superpowers:writing-plans mid-campaign, and keep no parallel TaskCreate list. The board is the plan.
  • Model routing (see ## Model routing): Opus-1M drives the loop; bounded short tasks go to Haiku; the mandatory Opus verifier gates every finding (done --find refuses without a passing verdicts/<F>.json). Still no open-ended hunter fan-out (it exhausted the weekly quota last time) - Haiku is only for single, fully-specified jobs.
  • Load-bearing exploit requests go through Burp Repeater when it is reachable; degrade to capture.sh req when it is not. Never block on Burp.
  • Scope and the enumeration ceiling come from scope.md, never from this skill.
  • RCE-first: with >1 vector open, take the code-exec one first - it is the attack vector with impact; chase lower-impact classes only after code-exec is ruled out or the target needs them.
  • Read whole, not grep: on a post-foothold host where a sudoer has no findable password and the usual vectors dead-end, READ /etc/pam.d/{sudo,su} + /etc/sudoers.d/* and linpeas output WHOLE - a pam_ssh_agent_auth/pam_exec/NOPASSWD line is the tell a grep skips. See [[linux-privesc]].
  • Long tools: run pspy/linpeas via bash scripts/vm-bg.sh <eng> <win> '<tool>' (stages to /dev/shm, runs in the stabilized shell, --read/--wait 120 the logfile); never retry a broken tool pattern >2x - switch method or call Skill(redteamlead).

Close-out

When next prints the close-out chain, run it: Skill(triage) -> Skill(evidence) -> Skill(report) -> Skill(learn).

If the driver is unavailable

Manual fallback, same gates by hand: read Approach.md, take the top open row for the current asset, run its wiki lookup then its hunt skill, capture req evidence, mark it [x]; on exhaustion one Deadends.md line and [!].

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/workflow/bb-workflow of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Encod3d-Sec/TORCH, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Bug Bounty Campaign Driver next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bug Bounty Campaign Driver compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bug Bounty Campaign Driver this skillEncod3d-Sec/TORCH3291 repos~1.8kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT
Insecure Deserialization PlaybookPentesterFlow/agent1.4k—~1.7kAutomated safety check: PassApache-2.0
Project Settings Cascadesamugit83/redamon2.9k—~2.4kAutomated safety check: PassMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0

Similar skills

  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

    1.4k GitHub stars~1.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Project Settings Cascade

    samugit83/redamon

    Changing or adding a project setting / default value in RedAmon.

    2.9k GitHub stars~2.4k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Hunt Idor

    Encod3d-Sec/TORCH

    IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

    329 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about Bug Bounty Campaign Driver

What does Bug Bounty Campaign Driver do?

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn. py.py next, does exactly what the printed action block lists, records the outcome with the note command and repeats, so the driver rather than free-form prose enforces the gates.

When should I use Bug Bounty Campaign Driver?

Bug Bounty Campaign Driver fits situations like: starting a bug-bounty engagement from a programme scope file; resuming a half-finished campaign from the driver's saved state; working through a wildcard scope with one required step printed per turn; collecting browser-based evidence for a web finding.

How do I install Bug Bounty Campaign Driver in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill bb-workflow -a claude-code`. Or copy the skill folder (skills/workflow/bb-workflow in Encod3d-Sec/TORCH) into .claude/skills/bb-workflow in your project. Claude Code loads it when a task matches its description.

How do I install Bug Bounty Campaign Driver in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill bb-workflow -a codex`. Or copy the skill folder (skills/workflow/bb-workflow in Encod3d-Sec/TORCH) into .agents/skills/bb-workflow in your project. Codex loads it when a task matches its description.

Can I use Bug Bounty Campaign Driver in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill bb-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bb-workflow, .gemini/skills/bb-workflow, .github/skills/bb-workflow and .opencode/skills/bb-workflow in your project.

What does Bug Bounty Campaign Driver need to run?

Going by SKILL.md and its folder, Bug Bounty Campaign Driver needs the command-line tools its instructions call (python3 and bash). Our summary lists: Python 3 for scripts/campaign.py; A filled-in scope.md for the programme; The chrome-devtools MCP for browser observation.

Does Bug Bounty Campaign Driver access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bug Bounty Campaign Driver safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bug Bounty Campaign Driver use?

Bug Bounty Campaign Driver is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bug Bounty Campaign Driver use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bug Bounty Campaign Driver?

Skills that share tags, products or a category with Bug Bounty Campaign Driver: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars), Insecure Deserialization Playbook (PentesterFlow/agent, 1.4k stars) and Project Settings Cascade (samugit83/redamon, 2.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bug Bounty Campaign Driver?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.