
from claude-bughunter2,450
A five-phase bug-hunting workflow and critical-thinking playbook that orients security hunting sessions, maps steps from recon to report, and enforces quality g
Provides a comprehensive, practice-oriented methodology for bug bounty and red-team sessions. The skill defines a five-phase non-linear workflow (Recon, Map, Find, Prove, Report) plus session-start checks and hard quality gates (marker discipline, body-diff, statistical sampling). It is designed to orchestrate hunting sessions and route to more focused hunt-* skills.
Use at the start of any security testing session, when switching targets or techniques, or when the operator is unsure what to do next. Also useful as an orchestrator when a user asks for 'what should I do next' or requests guidance across phases.
Targets security-focused agent runtimes that support long-form procedural guidance and slash commands (Claude Code, other code-capable assistants). It is intended for operators running automated and manual tooling in tandem.
A comprehensive 5-phase bug bounty methodology skill that guides security researchers through recon, mapping, vulnerability discovery, proof/escalation, and reporting. It includes strong discipline rules (marker discipline, body-diff, statistical sample, shell-loop ban) that prevent false positives. No scripts — purely instructional SKILL.md content. Well-written with clear decision trees and real engagement lessons, but the sheer length and monolithic structure may overwhelm casual users.
Security score high — the skill promotes responsible disclosure and validation discipline. No exfiltration, no destructive commands, no hardcoded credentials. Slightly deducts for referencing aggressive recon tools (subfinder, amass, nuclei) without explicit scope-confirmation guards, and the pushback protocol could inadvertently encourage continuing past ethical boundaries. Architecture is good but the monolithic SKILL.md with no references/ or scripts/ directory limits modularity. Usefulness is solid for bug bounty hunters but niche audience.
Hunt SSRF
Guided hunting methodology for server-side request forgery (SSRF): detection, OOB validation, payloads, bypass techniques, and escalation chains.
Hunt SharePoint
Enumerate and assess on-prem Microsoft SharePoint servers for version disclosure, anonymous endpoints, legacy SOAP login abuse, ToolShell preconditions (CVE-202