bug-bounty

Execute reconnaissance, vulnerability analysis, and reporting for web applications and APIs.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill bug-bounty-pdparchitect
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: bug-bounty
Source: https://github.com/pdparchitect/rook/tree/main/skills/bug-bounty
Command: npx skills add https://github.com/pdparchitect/rook --skill bug-bounty-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the fragmentation of the bug bounty workflow by providing a unified, systematic pipeline for reconnaissance, vulnerability research, and professional reporting.

Core Features & Use Cases

  • Full-Cycle Workflow: Orchestrates the entire process from initial asset discovery and subdomain enumeration to deep-dive vulnerability hunting and PoC generation.
  • Advanced Hunting Methodologies: Implements specialized techniques for A-to-B bug chaining, cluster hunting, and identifying complex vulnerabilities like IDOR, SSRF, and race conditions.
  • Professional Reporting: Provides structured gates and templates to ensure findings are validated, impactful, and written with a professional tone suitable for submission.

Quick Start

Use the bug bounty skill to perform a full reconnaissance and vulnerability scan on the target domain example.com.

Frequently Asked Questions about bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate reconnaissance and vulnerability scanning for bug bounty targets?▼

You can automate bug bounty reconnaissance and vulnerability scanning by orchestrating a unified pipeline that handles asset discovery, subdomain enumeration, and deep-dive vulnerability hunting across web applications and APIs.

What is the best way to find complex vulnerabilities like IDOR and SSRF during a security audit?▼

Finding complex vulnerabilities like IDOR and SSRF requires advanced hunting methodologies such as A-to-B bug chaining and cluster hunting, which validate exploitable security flaws by integrating automated tool orchestration with manual testing.

How do I chain multiple vulnerabilities to demonstrate higher impact in bug bounty reports?▼

You can chain vulnerabilities to demonstrate higher impact by applying specialized A-to-B bug chaining techniques and cluster hunting methodologies, systematically linking individual security flaws to show compound exploit scenarios.

Can I use this security audit workflow for cloud infrastructure and APIs?▼

Yes, this security audit workflow targets web applications, APIs, and cloud infrastructure, systematically identifying exploitable security flaws and validating findings across these diverse environments.

How do I generate professional vulnerability reports suitable for bug bounty submission?▼

You generate professional vulnerability reports by using structured gates and templates that ensure findings are validated, impactful, and written with a professional tone suitable for bug bounty submission.

Does this bug bounty workflow validate findings before reporting?▼

Yes, the bug bounty workflow validates findings by integrating automated tool orchestration with manual methodology, ensuring that identified vulnerabilities are confirmed exploitable before generating the final report.