What problem does it solve? Bug bounty hunting involves many disconnected phases — recon, learning the target, hunting dozens of vulnerability classes, validating exploitability, and writing reports that programs accept. This Skill consolidates the entire pipeline into one workflow with checklists, bypass tables, and validation gates so hunters avoid wasted effort on theoretical or out-of-scope findings. ## Core Features & Use Cases - Full Recon Pipeline: Subdomain enumeration, live host probing, URL collection, nuclei scanning, JS secret extraction, cloud asset enumeration, and HackerOne scope retrieval with ready-to-run commands. - Vulnerability Hunting Checklists: Deep testing guides for IDOR, SSRF, XSS, SQLi, OAuth/OIDC, GraphQL, race conditions, file upload, business logic, and LLM/AI agent attacks (ASI01-ASI10), including bypass tables for SSRF IPs, open redirects, and file uploads. - A-to-B Bug Chaining: A cluster-hunt protocol that escalates single findings (e.g., SSRF to cloud metadata to IAM credential theft) into higher-payout chains. - Validation & Reporting: A 7-Question Gate, impact-first triage rules, CVSS 3.1 scoring, and report templates to kill weak findings before submission. - Use Case: Starting on a new HackerOne program, pull the program scope, run the standard recon pipeline, fingerprint the tech stack, then hunt IDOR variants across API endpoints using the two-account testing method. ## Quick Start Ask the agent to start a bug bounty recon and hunting session against a specified in-scope target domain.