Bug Bounty

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (prompt injection, indirect injection, ASCII smuggling, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining, bypass tables, language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, validation gates, CVSS 3.1, PoC generation, submission checklist). Use for ANY bug bounty task — recon, hunting, source audit, AI testing, validation, or reporting. 中文触发词:漏洞赏金、安全测试、渗透测试、漏洞挖掘、信息收集、子域名枚举、XSS测试、SQL注入、SSRF、安全审计、漏洞报告

26zl a448349 40.3 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/bug-bounty commit a448349455

Frequently asked questions

npx skillmds@latest add 26zl/bug-bounty