bug-bounty-methodology

Installation
SKILL.md

Bug Bounty Methodology Skill

Overview

This skill provides a complete, target-agnostic bug bounty hunting methodology inspired by industry experts like Hadx and Daniel Miessler. It emphasizes systematic reconnaissance, parallel execution for efficiency, and vulnerability-specific testing workflows that apply to any web application target.

Core Philosophy

Three-Phase Approach:

  1. Intelligence Gathering (Passive Recon) - No direct target interaction
  2. Active Enumeration - Verification and endpoint discovery
  3. Targeted Exploitation - Vulnerability-specific testing based on findings

Key Principles:

  • Target-agnostic workflows that apply universally
  • Parallel agent execution for 5-7 hour tasks completed in ~1 hour wall time
  • Systematic documentation of all findings
  • Prioritization based on bug bounty program criteria
  • Reproducible steps with exact commands
Installs
1
GitHub Stars
3
First Seen
Jun 16, 2026
bug-bounty-methodology — aibot88/sec_skill_store