Bug Bounty Hunting Methodology
awarexone/Agentic-Bug-Hunter
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add yeswehack/claude-kit --skill gotchas -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yeswehack/claude-kit gotchas --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yeswehack/claude-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gotchas .claude/skills/gotchas && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gotchas" agent skill from https://github.com/yeswehack/claude-kit/tree/main/skills/gotchas into .claude/skills/gotchas/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gotchas", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yeswehack/claude-kit/tree/main/skills/gotchasType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yeswehack/claude-kit --skill gotchas -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yeswehack/claude-kit gotchas --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yeswehack/claude-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/gotchas .agents/skills/gotchas && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gotchas" agent skill from https://github.com/yeswehack/claude-kit/tree/main/skills/gotchas into .agents/skills/gotchas/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gotchas", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yeswehack/claude-kit --skill gotchas -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yeswehack/claude-kit gotchas --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yeswehack/claude-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/gotchas .cursor/skills/gotchas && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gotchas" agent skill from https://github.com/yeswehack/claude-kit/tree/main/skills/gotchas into .cursor/skills/gotchas/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gotchas", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yeswehack/claude-kit.git --path skills/gotchas--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yeswehack/claude-kit --skill gotchas -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yeswehack/claude-kit gotchas --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yeswehack/claude-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/gotchas .gemini/skills/gotchas && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gotchas" agent skill from https://github.com/yeswehack/claude-kit/tree/main/skills/gotchas into .gemini/skills/gotchas/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gotchas", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yeswehack/claude-kit gotchasInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yeswehack/claude-kit --skill gotchas -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yeswehack/claude-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/gotchas .github/skills/gotchas && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gotchas" agent skill from https://github.com/yeswehack/claude-kit/tree/main/skills/gotchas into .github/skills/gotchas/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gotchas", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yeswehack/claude-kit --skill gotchas -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yeswehack/claude-kit gotchas --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yeswehack/claude-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/gotchas .opencode/skills/gotchas && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gotchas" agent skill from https://github.com/yeswehack/claude-kit/tree/main/skills/gotchas into .opencode/skills/gotchas/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gotchas", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gotchasReference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps.
Gotchas is an agent skill from yeswehack/claude-kit. Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps. Load this when a bug bounty report claims a specific vulnerability class. Apply only the section that matches the claimed class.
Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Web application vulnerabilities and Bug bounty. The repository describes itself as: Claude Code plugin for writing triager-grade bug bounty reports. The licence is GPL-3.0.
Read from SKILL.md and the folder at commit 3928c34. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gotchas loads about 4.3k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 2,330 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
Collaborator, webhook.site, hunter's server). Include the inbound log.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yeswehack/claude-kit at commit 3928c34, republished under its GPL-3.0 licence (© yeswehack). 2,330 words, ~4,329 tokens.
.claude/skills/gotchas/SKILL.md (or your agent's skills folder).For each class: minimum proof (what the PoC must show), common N/A (typical false positives that get auto-closed), overclaim traps (impact claims that need extra evidence).
Apply only the section matching the report's claimed class.
Minimum proof
alert(document.domain) proves it).Common N/A
alert(1) on null origin, sandboxed iframe, data: / blob: URL.javascript: href requiring the victim to manually paste the URL.Overclaim traps
HttpOnly — JS can't read it.Minimum proof (one of)
SLEEP(n) payload, multiple runs at varying n.Common N/A
Overclaim traps
xp_cmdshell / INTO OUTFILE, or writing files goes
past proof into damage and can breach the program rules. Prove the
primitive, describe the impact, don't exercise it.Minimum proof
Common N/A
Overclaim traps
Minimum proof
Common N/A
Overclaim traps
AC:H and say where the ID would come from. Don't claim mass
exploitation off a single self-owned resource whose ID you already
knew. Sequential / short / predictable IDs are the ones that justify
AC:L.Minimum proof
Lax blocks most cross-site POSTs;
the PoC must work despite it.Common N/A
SameSite=Lax/Strict cookies blocking the cross-site request.Overclaim traps
Minimum proof (one of)
id, whoami, hostname).Common N/A
system() / exec() without controlled execution.Overclaim traps
id, whoami, hostname, or an
OOB callback) and stop. Do not pivot, escalate privileges, move
laterally, read other users' data, or run destructive commands to
"demonstrate" reach — that's past proof and into damage, and it
breaches most program rules. Report the execution primitive; describe
the impact without exercising it.Minimum proof
{{7*7}} → 49, <%=7*7%> → 49, etc.).Common N/A
{{7*7}} as a literal string (no evaluation).Server-side vs client-side
{{7*7}} → 49 in a client-side framework (Angular, Vue) is
CSTI, not server-side SSTI. Its impact is XSS (JS execution
in the browser), not server RCE — report it as XSS and prove JS
execution accordingly. Don't claim server compromise from a
client-side template evaluation.Minimum proof
/etc/passwd).Common N/A
Do not
Minimum proof
redirect_uri, password reset link, login flow.Common N/A
Overclaim traps
redirect_uri you can't
actually PoC. If proving the token leak requires an authenticated
account (or the IDP's real consent flow) you don't have, the impact
is theoretical and non-reproducible — a triager can't replay it,
so it isn't valid. Either obtain an account and show the token
landing on your endpoint, or report only the redirect you can prove
(typically Low) and state plainly the ATO chain is unverified.Minimum proof
Common N/A
/admin and seeing the SPA's JS/HTML render is not a
bypass — the framework serves the bundle to everyone and the API
calls behind it still return 401/403. You must show a protected
action or data actually returned without auth (an admin API
responding with real data, a privileged operation succeeding). "The
page loads" is not an impact.Covers leaked secrets found anywhere: JS bundles, HTML/source comments,
API responses, git/config exposure, and secrets hardcoded in mobile
apps (decompiled APK/IPA, strings, strings.xml, embedded config).
Minimum proof
200 on an endpoint that requires it), with the
secret redacted in the report.Common N/A
apiKey config, Stripe
publishable pk_..., Sentry DSNs, reCAPTCHA site keys, Mixpanel/
analytics tokens. These are designed to ship in the client — a
leak isn't a finding unless you prove a real, non-intended capability
(e.g. an unrestricted Maps key billing abuse, or a Firebase config
with wide-open security rules — and then the finding is the open
rules, proven separately).sk_test_..., changeme,
documented sample keys).Overclaim traps
Minimum proof
200s.Common N/A
Overclaim traps
200 responses
without showing the persisted state changed. The proof is the
final ledger / balance, not the response codes.Minimum proof
Origin in
Access-Control-Allow-Origin and returns
Access-Control-Allow-Credentials: true.fetch(url, {credentials:'include'}), reads the response
cross-origin, and shows the victim's actual data exfiltrated — not
just the headers.Common N/A (this is where most CORS reports die)
ACAO: * without ACAC: true. The browser refuses to send
credentials to a wildcard origin, so a credentialed read is
impossible — a public endpoint returning * leaks nothing an
attacker couldn't already fetch server-side. Not a finding alone.Origin but the endpoint returns only public /
unauthenticated data. No secret crosses the boundary.ACAC: true with a fixed, trusted ACAO (not reflected, not
attacker-controlled).OPTIONS) reflecting the origin while the actual
GET/POST doesn't, or the real response body carries nothing
sensitive.null origin allowed" with no PoC — exploiting null needs a
sandboxed iframe; show it working.Overclaim traps
Minimum proof
/etc/passwd, win.ini, or an app config / source file the
endpoint must not serve).../, %2e%2e%2f, ....//, absolute path,
null-byte truncation).../) and LFI (include/execute a
file) kept distinct. If code execution is claimed (log poisoning,
PHP php://filter / wrapper chain, session-file inclusion), show
the executed output — not just the file read.Common N/A
403 / 404 / 500 on ../ payloads with no file returned. An
error is not a read.Overclaim traps
/etc/passwd. State what
the process user can actually read — a private key or app secret
proves impact; /etc/passwd alone is usually just the confirmation
primitive.Apply general PoC and impact rigor (see triage). The report
should clearly explain the class and its impact model in its first
paragraph since the triager won't have a class-specific mental model
to fall back on.
© yeswehack, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/gotchas of yeswehack/claude-kit.
Open the folder on GitHubat commit 3928c34
Gotchas next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gotchas this skillyeswehack/claude-kit | 105 | — | ~4.3k | Automated safety check: Warn | GPL-3.0 | |
| Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter | 5.3k | 2 repos | ~4.7k | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | |
| Bug Bounty Campaign DriverEncod3d-Sec/TORCH | 329 | 1 repos | ~1.8k | Automated safety check: Pass | MIT | |
| Bug Bounty Triage Validationawarexone/Agentic-Bug-Hunter | 5.3k | 3 repos | ~3.4k | Automated safety check: Pass | MIT |
awarexone/Agentic-Bug-Hunter
Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
awarexone/Agentic-Bug-Hunter
Screens a vulnerability finding with a seven-question gate and pre-submission checks before any report is written, so weak or out-of-scope findings are dropped early.
bugbountywithmarco/bugbounty-disclosed-reports
Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.
Categories
Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps. Gotchas is an agent skill from yeswehack/claude-kit. Reference table of per-class false-positive patterns, minimum proof requirements, and impact overclaim traps.
Gotchas fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Bug bounty.
Run `npx skills add yeswehack/claude-kit --skill gotchas -a claude-code`. Or copy the skill folder (skills/gotchas in yeswehack/claude-kit) into .claude/skills/gotchas in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yeswehack/claude-kit --skill gotchas -a codex`. Or copy the skill folder (skills/gotchas in yeswehack/claude-kit) into .agents/skills/gotchas in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yeswehack/claude-kit --skill gotchas -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gotchas, .gemini/skills/gotchas, .github/skills/gotchas and .opencode/skills/gotchas in your project.
SKILL.md names no scripts, command-line tools or credentials: Gotchas is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a paste, webhook or tunnelling service often used to send data out. Read the flagged lines before installing; the check is not a guarantee either way.
Gotchas is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Gotchas: Bug Bounty Hunting Methodology (awarexone/Agentic-Bug-Hunter, 5.3k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Bug Bounty Campaign Driver (Encod3d-Sec/TORCH, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yeswehack (a GitHub organization) maintains it in yeswehack/claude-kit, which has 105 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on August 25, 2026.
Source: yeswehack/claude-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.