What problem does it solve? Security researchers on SRC, crowdsourced testing, and bug bounty programs often guess commands and miss high-value vulnerability classes; this Skill replaces ad-hoc testing with a repeatable five-phase workflow (intake, recon, enum, hunt, report) backed by real disclosed-case statistics and structured payloads. ## Core Features & Use Cases - Five-phase methodology: Intake scope parsing, passive recon, active enumeration, vulnerability hunting, and CVSS 4.0 report generation with evidence discipline rules. - 19 attack-class playbooks: SQLi, XSS, RCE, SSRF, IDOR, OAuth/JWT/SAML, file upload, path traversal, race conditions, GraphQL, mobile, LLM prompt injection, and more, each embedding real HackerOne High/Critical cases and WAF/EDR bypass variants. - Knowledge base: 305 structured payloads, 263 WAF/EDR bypass steps, 2887 disclosed HackerOne reports, WooYun statistical residue, Chinese-component fingerprint and default-credential dictionaries, plus banking and telecom vertical playbooks. - Use Case: Given a bug bounty program URL, the Skill scopes the engagement, enumerates subdomains and endpoints, prioritizes high-hit-rate classes like password reset (88% high-severity rate) and arbitrary account takeover, then produces a submission-ready report. ## Quick Start Ask the AI to run the src-hunter workflow against your authorized bug bounty target, for example by saying "use src-hunter to test https://target.example.com within its program scope".