bug-bounty
communityby shuvonsec
Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, smart contracts, SDK audit, SIWE), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction), and reporting (4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, submission checklist). Use for ANY bug bounty task — starting a new target, doing recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports.
Loading skill details...
Quality
Description
README
Installation
View sourceInstall this skill using the Skillsmith CLI or MCP server:
Using npx (recommended):
Using Skillsmith CLI:
Or ask your assistant:
Details
- Category
- Trust Tier
- Version