bug-bounty-methodology

Installation
SKILL.md

What this skill does

Provides a complete cognitive and operational framework for bug bounty hunting sessions. Combines a 5-phase non-linear workflow (Recon → Map → Discover → Prove → Report) with four thinking domains (Critical, Multi-Perspective, Tactical, Strategic) and developer psychology reversal techniques. Routes decisions about what to test, which tool to use, and how to escalate findings based on phase, target type, and time elapsed.

When to use

  • At the start of any new bug bounty hunting session
  • When switching to a new program or target
  • When feeling stuck or unsure what to do next
  • When a finding has low impact and you want to escalate it
  • When asking "what should I test next?" or "where am I in the process?"
  • When a WAF or filter is blocking your payload and you need a bypass strategy

Prerequisites

  • A valid, authorized bug bounty scope (HackerOne, Bugcrowd, Intigriti, Immunefi, or private program)
  • A proxy tool (Burp Suite or Caido) running and intercepting traffic
  • Two test accounts on the target application (attacker account A, victim account B)
  • No external tools are required — this skill is a cognitive framework
Installs
7
GitHub Stars
21
First Seen
May 9, 2026
bug-bounty-methodology — woohyun212/security-skill