bb-methodology
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Provides a structured framework for bug bounty hunting, including phases for reconnaissance, mapping, discovery, and reporting.
- [SAFE]: Includes instructional code snippets in Bash and Python designed to verify the integrity of security testing logic, such as ensuring marker uniqueness and performing statistical analysis on response times. These snippets are benign and intended for logic verification.
- [SAFE]: Mentions various industry-standard security tools (e.g., Nuclei, Burp Suite, ffuf) and Out-of-Band (OOB) testing services (e.g., Interact.sh, Oastify) in a manner consistent with its purpose as a security testing methodology.
- [SAFE]: Emphasizes false-positive prevention through rigorous testing protocols such as the Body-Diff Rule and the Statistical-Sample Rule, promoting accurate and ethical security research.
Audit Metadata