Deep Eye — Bug Bounty Skill
Policy first. Deep Eye accelerates surface coverage; impact + PoC win bounties.
Preconditions
- Program policy read (scope, OOS, rate limits, safe harbor).
- In-scope only — no third-party collateral.
- Local config; never commit API keys or session cookies.
ROI module pack
Enable in vulnerability_scanner.enabled_checks:
enabled_checks:
- idor
- api_bola_deep
- jwt_deep
- oauth_testing
- graphql_deep
- ssrf_cloud
- cloud_misconfig
- cors_csp
- open_redirect_deep
- stored_xss
- sql_injection
- xss
- ssrf
- mass_assignment
Optional: ai_triage.enabled, bug_bounty.enabled (Markdown under reports/bounty/).
Commands
python deep_eye.py --setup
python deep_eye.py -u https://IN_SCOPE -v --formats json,html
python deep_eye.py -u https://IN_SCOPE --scope-nl "only /api/* host target.com"
python deep_eye.py -u https://IN_SCOPE --retest-new reports/prior.json
OpenAPI: openapi.enabled: true + source.
Hunt order
- Authz —
idor,api_bola_deep - Token/auth —
jwt_deep,oauth_testing,login_replay - SSRF/cloud —
ssrf_cloud,cloud_misconfig - GraphQL —
graphql_deep - Stored XSS chains —
stored_xss - Secrets — only if actionable (
secret_scanning)
Report template
## Summary
## Steps to reproduce
## PoC
## Impact
## Remediation
## Environment
Finding keys: type, severity, url, parameter, payload, evidence, remediation.
Rules
Respect rate limits; redact PII; check duplicates; show delta impact on partial dupes.