bug-bounty-methodology
Installation
SKILL.md
Bug Bounty Methodology Skill
Overview
This skill provides a complete, target-agnostic bug bounty hunting methodology inspired by industry experts like Hadx and Daniel Miessler. It emphasizes systematic reconnaissance, parallel execution for efficiency, and vulnerability-specific testing workflows that apply to any web application target.
Core Philosophy
Three-Phase Approach:
- Intelligence Gathering (Passive Recon) - No direct target interaction
- Active Enumeration - Verification and endpoint discovery
- Targeted Exploitation - Vulnerability-specific testing based on findings
Key Principles:
- Target-agnostic workflows that apply universally
- Parallel agent execution for 5-7 hour tasks completed in ~1 hour wall time
- Systematic documentation of all findings
- Prioritization based on bug bounty program criteria
- Reproducible steps with exact commands