bb-methodology

Orchestrate bug-hunting sessions with a five-phase non-linear workflow.

3.3k|507|Updated May 5, 2026
One-click install
npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bb-methodology-elementalsouls
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bb-methodology-elementalsouls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Master orchestrator for bug-hunting sessions, combining a five-phase non-linear workflow with a critical-thinking mindset to ensure consistent, efficient engagements and clear handoffs between phases and skills.

Core Features & Use Cases

  • Five-phase non-linear workflow (Recon, Mapping & Analysis, Vulnerability Discovery, Prove & Escalate, Validate & Report) with dynamic routing to related bb-* skills based on current phase.
  • Mindset and discipline guidance (critical thinking, what-if experiments, and escalation rules) to improve triage quality and outcomes.
  • Seamless orchestration across the Claude BugHunter toolkit, enabling rapid start-to-finish engagements without rigid linear progression.

Quick Start

Issue a session with your target scope and allow bb-methodology to orchestrate recon, mapping, discovery, proving, and reporting.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a phase-based bug bounty workflow and how does it structure vulnerability discovery?▼

A phase-based bug bounty workflow structures vulnerability discovery into five non-linear phases: recon, mapping and analysis, vulnerability discovery, proving and escalation, and validation and reporting. This methodology enforces critical thinking and discipline through gates like the 7-Question Gate to ensure consistent triage quality and clear phase handoffs.

How do I orchestrate a bug hunting session from recon to reporting?▼

You orchestrate a bug hunting session by initiating a session with your target scope, then navigating dynamically across five phases from recon to reporting. The methodology provides non-linear routing between phases, enforcing evidence hygiene and marker discipline while dynamically routing to specialized skills based on your current phase.

Can I use this methodology for red-team engagements and security assessments?▼

Yes, this methodology is applicable to bug bounty, red-team, and assessment engagements. It provides a complete five-phase workflow with mindset and discipline guidance, including escalation rules and critical-thinking frameworks, ensuring efficient engagements across different security testing contexts.

What's the best way to maintain discipline during vulnerability discovery and triage?▼

The best way to maintain discipline during vulnerability discovery is applying enforced frameworks like the 7-Question Gate, marker discipline, and evidence hygiene. These mechanisms ensure consistent critical thinking, structured what-if experiments, and clear handoffs between phases to improve triage quality and outcomes.

Does the bug hunting workflow require rigid linear progression through all phases?▼

No, the workflow uses non-linear navigation across its five phases. You can transition dynamically between phases based on findings, with specified entry points, phase transitions, and escalation rules enabling rapid start-to-finish engagements without forcing rigid linear progression.