bb-methodology

Guide bug bounty hunting through a structured 5-phase workflow.

1|Updated Jun 22, 2026
One-click install
npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill bb-methodology-0xhaaz
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/0xhaaz/bug-bounty-toolkit/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill bb-methodology-0xhaaz

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill unit provides a comprehensive methodology for bug bounty hunting, guiding users through a structured 5-phase workflow and a critical thinking framework to identify and validate vulnerabilities.

Core Features & Use Cases

  • 5-Phase Workflow: A non-linear, 5-phase approach to bug bounty hunting, including Recon, Mapping & Analysis, Vulnerability Discovery, Prove & Escalate, and Validate & Report.
  • Critical Thinking Framework: Combines developer psychology, anomaly detection, and What-If experiments to separate top hunters from the rest.
  • Navigation & Timing: Quick reference for non-linear navigation and a 20-minute rotation clock to stay productive.

Quick Start

Start a new bug bounty hunting session by running the bb-methodology skill with the target domain.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a structured bug bounty hunting methodology?▼

A structured bug bounty hunting methodology provides a 5-phase workflow covering Recon, Mapping & Analysis, Vulnerability Discovery, Prove & Escalate, and Validate & Report to systematically identify web application vulnerabilities.

How do I start bug bounty hunting with a critical thinking framework?▼

Start bug bounty hunting by applying critical thinking through developer psychology, anomaly detection, and What-If experiments, running a target domain through the 5-phase workflow to guide vulnerability discovery and validation.

What's the best way to stay productive during security testing sessions?▼

Stay productive during security testing by utilizing a 20-minute rotation clock and non-linear navigation approach, allowing you to systematically pivot across targets without losing focus during the vulnerability assessment process.

Can I use this vulnerability assessment workflow for any web application target?▼

Yes, the vulnerability assessment workflow supports web application targets, but it requires a deep understanding of web application vulnerabilities and security testing to effectively execute the 5-phase hunting process.

How does developer psychology improve vulnerability discovery?▼

Developer psychology improves vulnerability discovery by analyzing how developers think and code, enabling hunters to predict anomalies and design targeted What-If experiments that uncover hidden security flaws.

Why should I use a non-linear workflow for bug bounty hunting?▼

A non-linear workflow allows dynamic navigation across the five phases, enabling hunters to pivot between Recon, Vulnerability Discovery, and Validation based on real-time findings rather than being locked into a rigid sequence.