bb-methodology

Coordinate a five-phase bug bounty workflow with YAML frontmatter metadata.

Updated May 31, 2026
One-click install
npx skills add https://github.com/grivera82/pi-bughunter --skill bb-methodology-grivera82
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: bb-methodology
Source: https://github.com/grivera82/pi-bughunter/tree/main/skills/bb-methodology
Command: npx skills add https://github.com/grivera82/pi-bughunter --skill bb-methodology-grivera82

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Master orchestrator for hunting sessions that coordinates the 5-phase non-linear bug-hunting workflow and the associated critical-thinking framework, enabling consistent, repeatable engagements.

Core Features & Use Cases

  • Orchestrates phase transitions (Recon, Mapping, Find, Prove, Report) and Phase 0/session setup to align teams on engagement type and goals.
  • Routes to all other huntSkills (e.g., hunt-dispatch, hunt-auth-bypass) to load the right toolset based on current hunting phase.
  • Provides mode-confirmation and discipline rules to improve validation and triage quality, making engagements faster and more reliable.

Quick Start

Define the engagement type and select 1–2 vulnerability classes at the start to activate the non-linear 5-phase workflow.

Frequently Asked Questions about bb-methodology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a non-linear bug bounty workflow and how does it manage engagements?▼

A non-linear bug bounty workflow coordinates five phases—Recon, Mapping, Find, Prove, and Report—allowing dynamic phase transitions. It streamlines engagements by aligning session goals and routing to specialized toolsets based on the current hunting phase.

How do I structure a bug hunting session for red-team or WAPT engagements?▼

Structure a bug hunting session by defining the engagement type and selecting 1–2 vulnerability classes at the start. This activates a five-phase workflow that guides recon, mapping, finding, proving, and reporting for red-team and WAPT-style engagements.

Can I use this methodology for both bug bounty and red-team security testing?▼

Yes, this methodology applies across bug bounty, red-team, and WAPT-style engagements. It provides a critical-thinking framework and mode-confirmation rules to improve validation and triage quality across different security testing contexts.

What's the best way to improve validation and triage quality during security testing?▼

Improve validation and triage quality by applying mode-confirmation and discipline rules within a structured workflow. These rules enforce critical thinking during phase transitions, making engagements faster and more reliable.

Does this bug hunting methodology route to other skills for specific vulnerability classes?▼

Yes, the methodology routes to other hunt skills like hunt-dispatch and hunt-auth-bypass to load the right toolset. Cross-skill routing triggers based on the current hunting phase and vulnerability class focus.

Why should I use a mindset-driven workflow instead of ad-hoc bug hunting?▼

A mindset-driven workflow provides consistent, repeatable engagements through structured phase orchestration and critical-thinking frameworks. Ad-hoc hunting lacks mode-confirmation and discipline rules, reducing validation quality and engagement reliability.