Topic · Security

Best bug bounty skills, page 2

Skills #49–75 of 75, ranked by score.

Bug bounty skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Bug bounty skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

uphiago/recon-skills1.3k—~2kAutomated safety check: PassMIT1 mo ago
50

A skill your agent uses when starting or restructuring an authorized external web and API assessment.

uphiago/recon-skills1.3k—~1.9kAutomated safety check: PassMIT1 mo ago
51

Mobile (Android + iOS) application penetration testing methodology.

SnailSploit/Claude-Red7.3k—~3.5kAutomated safety check: PassMIT18 days ago
52

Bugcrowd-specific reporting tactics complementing report-writing

sickn33/agentic-awesome-skills47k1 repo~5.9kAutomated safety check: PassMITtoday
53

Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs.

briiirussell/cybersecurity-skills413—~1.1kAutomated safety check: NotesMIT4 mo ago
54

Attack cameras via RTSP, ONVIF, Axis config when 554 open. An agent skill from uphiago/recon-skills.

uphiago/recon-skills1.3k—~2.3kAutomated safety check: PassMIT1 mo ago
55

Map subdomains via crt.sh and subfinder at recon kickoff. An agent skill from uphiago/recon-skills.

uphiago/recon-skills1.3k—~3.3kAutomated safety check: PassMIT1 mo ago
56

Screenshot all live hosts for rapid visual triage and technology fingerprinting.

uphiago/recon-skills1.3k—~1.5kAutomated safety check: PassMIT1 mo ago
57

Complete bug bounty workflow

sickn33/agentic-awesome-skills47k1 repo~5kAutomated safety check: NotesMITtoday
58

Domain assessment and web application mapping - subdomain discovery, port scanning, endpoint enumeration, API discovery, and attack surface analysis.

transilienceai/communitytools562—~1.4kAutomated safety check: PassMIT2 mo ago
59

Hunting skill for auth bypass vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~8.2kAutomated safety check: PassMITyesterday
60

Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~5.7kAutomated safety check: PassMITyesterday
61

Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~5.5kAutomated safety check: PassMITyesterday
62

Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…

jeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMITtoday
63

Triage ASM/recon output for ownership before testing — separate the target's real assets from namespace-collision noise.

elementalsouls/Claude-BugHunter4.8k—~1.9kAutomated safety check: NotesMITyesterday
64

Hunting skill for business logic vulnerabilities. An agent skill from majiayu000/claude-skill-registry.

majiayu000/claude-skill-registry6662 repos~4.4kAutomated safety check: PassMITtoday
65

Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes.

forefy/.context152—~2.1kAutomated safety check: PassMIT3 days ago
66

Map a bug-bounty scope and rank targets by payout, crowding, and freshness.

forefy/.context152—~2.1kAutomated safety check: PassMIT3 days ago
67

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity…

elementalsouls/Claude-BugHunter4.8k—~5.2kAutomated safety check: PassMITyesterday
68

Audit all open HackerOne-sourced VULN Jira tickets and their linked engineering child items to identify what needs action.

bitwarden/ai-plugins154—~3.4kAutomated safety check: PassUnknowntoday
69

Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.

trilwu/secskills156—~3.4kAutomated safety check: PassMIT1 mo ago
70
70.Hack

Entry P0 primary router and operating doctrine for HackSkills.

yaklang/hack-skills2.4k—~4.7kAutomated safety check: NotesMIT25 days ago
71

Enumerate web technologies, headers, endpoints, and metadata from a target

NeoTheCapt/RedteamAgent142—~770Automated safety check: PassNo licence2 mo ago
72

Reconnaissance and methodology playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

langbyyi/CyberStrikeAI-SRC1341 repo~3.1kAutomated safety check: WarnApache-2.0yesterday
73

Operate Cyberful as an authorized application-security control room.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.0-only1 mo ago
74

A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

jeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: NotesMITtoday
75

Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report.

criptogus/agent-evolve-network288—~1.2kAutomated safety check: PassCC-BY-SA-4.028 days ago