Agent skill

Hackenproof Triage Marketplace

by Gabson0x in Gabson0x/bountyforge

HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.

No licenceAuto-check passedSecurity

Install Hackenproof Triage Marketplace

skills CLI
$ npx skills add Gabson0x/bountyforge --skill hackenproof-triage-marketplace -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Gabson0x/bountyforge hackenproof-triage-marketplace --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hackenproof-triage-marketplace .claude/skills/hackenproof-triage-marketplace && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hackenproof-triage-marketplace
GitHub stars
442
Token cost
~1.2k tokens
SKILL.md length
561 words
Files
5 (incl. references)
Skills in repo
6
Repo updated
First seen
Licence
None found

At a glance

HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.

  • Works in 5 steps: Apply global HackenProof classification… → Run pre-validation gates in strict order → Start technical validation only after… → …
  • Analyzing security reports
  • SKILL.md covers Workflow, Mandatory Tool Sequence, Pre-Validation Gates and Decision Rules, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hackenproof Triage Marketplace is an agent skill from Gabson0x/bountyforge. HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations. Use when analyzing security reports, validating scope and exploitability, assigning severity, detecting duplicates, setting report state, adding labels/comments, and preparing consistent triage decisions for HackenProof programs.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `agents/openai.yaml`, `references/hackenproof-global-policy.md` and `references/severity-mapping.md`).

It sits in Security, covering Bug bounty. The repository describes itself as: all round pentest skill.

When your agent uses it

  • Analyzing security reports
  • Validating scope and exploitability
  • Assigning severity
  • Detecting duplicates

Example prompts

  • “/hackenproof-triage-marketplace”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Apply global HackenProof classification baseline from references/hackenproof-global-policy.md.
  2. Run pre-validation gates in strict order
  3. Start technical validation only after all pre-validation gates pass.
  4. Classify severity, choose state transition, and apply labels.
  5. Post a concise decision comment with explicit rationale and next action.

What it can do on your machine

Read from SKILL.md and the folder at commit 068399d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hackenproof Triage Marketplace loads about 1.2k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 561 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 561 words (~1,163 tokens).

“Execute consistent, evidence-based triage for HackenProof bug bounty reports.”

— opening of SKILL.md by Gabson0x
name
hackenproof-triage-marketplace

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (references) in skills/hackenproof-triage-marketplace of Gabson0x/bountyforge.

  • SKILL.md
  • agents/openai.yaml
  • references/hackenproof-global-policy.md
  • references/severity-mapping.md
  • references/triage-comment-templates.md

Open the folder on GitHubat commit 068399d

Compare with similar skills

Hackenproof Triage Marketplace next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hackenproof Triage Marketplace compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hackenproof Triage Marketplace this skillGabson0x/bountyforge442—~1.2kAutomated safety check: PassNone
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings

More from Gabson0x/bountyforge

  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 24 days ago
    Auto-check passed
  • Security Arsenal

    Gabson0x/bountyforge

    Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection…

    442 GitHub stars~8.5k tokensUpdated 24 days ago
    Auto-check: warnings
  • Web2 Recon

    Gabson0x/bountyforge

    Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

    442 GitHub stars~1.6k tokensUpdated 24 days ago
    Auto-check passed
  • Web2 Vuln Classes

    Gabson0x/bountyforge

    Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.

    442 GitHub stars~11k tokensUpdated 24 days ago
    Auto-check: warnings
  • Code Sleuth

    Gabson0x/bountyforge

    Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.

    442 GitHub stars~1.5k tokensUpdated 24 days ago
    Auto-check passed

Categories

Questions about Hackenproof Triage Marketplace

What does Hackenproof Triage Marketplace do?

HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations. Hackenproof Triage Marketplace is an agent skill from Gabson0x/bountyforge. HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.

When should I use Hackenproof Triage Marketplace?

Hackenproof Triage Marketplace fits situations like: analyzing security reports; validating scope and exploitability; assigning severity; detecting duplicates.

How do I install Hackenproof Triage Marketplace in Claude Code?

Run `npx skills add Gabson0x/bountyforge --skill hackenproof-triage-marketplace -a claude-code`. Or copy the skill folder (skills/hackenproof-triage-marketplace in Gabson0x/bountyforge) into .claude/skills/hackenproof-triage-marketplace in your project. Claude Code loads it when a task matches its description.

How do I install Hackenproof Triage Marketplace in Codex?

Run `npx skills add Gabson0x/bountyforge --skill hackenproof-triage-marketplace -a codex`. Or copy the skill folder (skills/hackenproof-triage-marketplace in Gabson0x/bountyforge) into .agents/skills/hackenproof-triage-marketplace in your project. Codex loads it when a task matches its description.

Can I use Hackenproof Triage Marketplace in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Gabson0x/bountyforge --skill hackenproof-triage-marketplace -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hackenproof-triage-marketplace, .gemini/skills/hackenproof-triage-marketplace, .github/skills/hackenproof-triage-marketplace and .opencode/skills/hackenproof-triage-marketplace in your project.

What does Hackenproof Triage Marketplace need to run?

SKILL.md names no scripts, command-line tools or credentials: Hackenproof Triage Marketplace is instructions for the agent only.

Does Hackenproof Triage Marketplace access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hackenproof Triage Marketplace safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hackenproof Triage Marketplace use?

No licence was found for Hackenproof Triage Marketplace or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Hackenproof Triage Marketplace use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Hackenproof Triage Marketplace?

Skills that share tags, products or a category with Hackenproof Triage Marketplace: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Bug Bounty Hunting Methodology (awarexone/Agentic-Bug-Hunter, 5.3k stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars) and Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hackenproof Triage Marketplace?

Gabson0x (a GitHub user) maintains it in Gabson0x/bountyforge, which has 442 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 16, 2026.

Source: Gabson0x/bountyforge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.