bugbounty-check

Installation
SKILL.md

Bug Bounty Report Check

Overview

Review bug bounty reports with a strict evidence-first mindset. The goal is not to promise that a report is "100% valid" or guaranteed accepted; the goal is to identify what is proven, what is missing, what is unsafe or out of scope, and what must change before submission.

Only help with authorized bug bounty, responsible disclosure, internal security testing, or clearly defensive review. If authorization or scope is unclear, ask for program scope before giving exploit expansion advice.

Core Rule

Never inflate a report. A valid report needs a reproducible vulnerability, in-scope testing, concrete evidence, realistic impact, and a defensible attack chain. If any required part is missing, say so directly and mark the report as not ready.

Safety Boundaries

  • Do not help attack third-party systems outside an authorized program.
  • Do not provide instructions for credential theft, persistence, stealth, exfiltration, destructive actions, broad scanning, or bypassing program rules.
  • Do not ask the user to test against real victims when test accounts or synthetic data are required.
  • Do not invent screenshots, logs, sensitive data, impact, severity, or attack-chain steps.
  • Redact secrets, tokens, cookies, personal data, and third-party customer data from report text.
Installs
1
Repository
0xyon3/dotfiles
GitHub Stars
8
First Seen
Jul 11, 2026
bugbounty-check — 0xyon3/dotfiles