bug-bounty

Coordinate recon, hunting, validation, and reporting for bug bounty programs.

1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/mlvpatel/sentinel-ai-offensive --skill bug-bounty-mlvpatel
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/mlvpatel/sentinel-ai-offensive/tree/main
Command: npx skills add https://github.com/mlvpatel/sentinel-ai-offensive --skill bug-bounty-mlvpatel

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

Automates and standardizes the full bug bounty lifecycle from reconnaissance to reporting, enabling teams to consistently surface high-impact vulnerabilities with a repeatable workflow.

Core Features & Use Cases

  • End-to-end orchestration: Recon, learning, hunting, validation, and report generation within a single workflow.
  • Memory-enabled analysis: Persistent memory of targets and findings to accelerate future hunts.
  • Compliance-minded: Built-in gates, schema validation, and audit trails to demonstrate regulatory alignment.

Quick Start

Install the skill and run /recon on a target to begin the end-to-end bug bounty workflow.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate bug bounty hunting workflows from reconnaissance to reporting?▼

To automate bug bounty hunting, you orchestrate end-to-end workflows from recon to report generation. This skill coordinates recon, learning, hunting, validation, and reporting to surface vulnerabilities using a repeatable methodology.

Can I run bug bounty recon on enterprise web apps and smart contracts?▼

Yes, you can run bug bounty recon on enterprise web apps and smart contracts. The workflow applies to targets ranging from web applications to smart contracts within enterprise and open-source bug bounty programs.

How do I validate vulnerabilities found during a bug bounty hunt?▼

You validate vulnerabilities found during a bug bounty hunt using built-in 7-Question Gate validation and a 4-gate review. The workflow enforces safe-method validation to ensure findings are accurate before reporting.

Does this bug bounty workflow maintain persistent memory of targets and findings?▼

Yes, this bug bounty workflow maintains persistent hunt memory of targets and findings. This memory-enabled analysis accelerates future hunts by retaining target data and findings across sessions.

How do I generate compliance audit logs for a bug bounty program?▼

You generate compliance audit logs for a bug bounty program using immutable logging and versioned schemas. This workflow provides built-in gates, schema validation, and audit trails to demonstrate regulatory alignment.

What is the best way to standardize threat modeling for bug bounty hunting?▼

The best way to standardize threat modeling for bug bounty hunting is applying a repeatable methodology with enforced gates. This workflow satisfies threat modeling, safe-method enforcement, and 4-gate review for consistent results.