bug-bounty

Automate end-to-end bug bounty workflows across recon, hunting, validation, and reporting.

Updated Jun 23, 2024
One-click install
npx skills add https://github.com/n4igme/randscript --skill bug-bounty-n4igme
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/n4igme/randscript/tree/main/llm/skills/claude-hunter/skills/bug-bounty
Command: npx skills add https://github.com/n4igme/randscript --skill bug-bounty-n4igme

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty programs involve a multi-phase workflow that is often manual, error-prone, and hard to scale. This skill provides an end-to-end framework to orchestrate recon, learning, hunting, validation, and reporting, reducing cognitive load and increasing the reliability of findings.

Core Features & Use Cases

  • End-to-end lifecycle: Recon, Learn, Hunt, Validate, and Report stages with guardrails.
  • Evidence-driven reporting: Templates and checklists aligned with disclosure standards.
  • Threat-model-informed hunting: Structured intelligence, risk framing, and target prioritization.
  • Reporting automation: Consistent, publish-ready reports for internal records or external disclosures.

Quick Start

Begin by loading the bug bounty skill and initiating Recon, Learn, Hunt, Validate, and Report for a target program.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate vulnerability reporting and evidence collection for bug bounty programs?▼

Bug bounty automation streamlines vulnerability reporting and evidence collection by enforcing structured frontmatter-driven workflows, ensuring consistent, publish-ready reports aligned with disclosure standards.

What is the best way to structure recon and threat-modeling for security testing?▼

Threat-modeling and recon are structured through dedicated lifecycle stages that prioritize targets, frame risk, and gather intelligence before vulnerability hunting begins.

How do I validate security findings before submitting a bug bounty report?▼

Validate security findings by applying the 7-Question Gate guardrail during the validation stage, which ensures findings are safe, auditable, and properly verified before disclosure.

Does this bug bounty workflow support external disclosure and internal records?▼

Yes, reporting automation generates consistent, publish-ready reports designed for both external program disclosures and internal security engagement records.

Can I use optional scripts and references during the vulnerability hunting phase?▼

Yes, the bug bounty workflow supports optional scripts, references, and assets during vulnerability hunting to enhance recon, learning, and validation stages.