CtrlK
BlogDocsLog inGet started
Tessl Logo

bb-methodology

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other skills based on current hunting phase. Also use when asking "what should I do next" or "where am I in the process."

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, highly actionable methodology document with a clearly sequenced 5-phase workflow, explicit validation gates, and concrete tooling/payload guidance. Its main weaknesses are length and redundancy, plus a monolithic single-file structure with no progressive disclosure into bundle files.

Suggestions

De-duplicate 'Define, Select, Execute' (present in both PART 1 and Phase 0) and consolidate the mode-confirmation guidance so PART 0 and the Operator Notes 'Mode-confirmation, in practice' section do not repeat each other.

Split the large inline blocks — the Tool Routing by Phase table, the PART 4 discipline rules, and the Operator Notes — into reference files under references/ and link to them one level deep, turning the monolithic SKILL.md into an overview with progressive disclosure.

Trim general-concept framing in the Mindset section (e.g., explanatory prose around Critical/Multi-Perspective thinking) to tighten token efficiency while keeping the concrete checklists and decision trees.

DimensionReasoningScore

Conciseness

The body is ~500 lines with real redundancy — 'Define, Select, Execute' appears both in PART 1 and again as Phase 0, and mode confirmation is covered in PART 0 then revisited in Operator Notes — so it is substantive but not lean, fitting 'mostly efficient but includes some unnecessary explanation or could be tightened' rather than the 'every token earns its place' level above.

2 / 3

Actionability

Provides concrete, executable guidance — named tool pipelines ('subfinder -> amass -> puredns -> httpx'), copy-paste payloads ('{{7*7}}', '${7*7}', 'SLEEP(10)'), a ready diff command, and precise numeric thresholds (n>=10 interleaved trials, >=2sigma) — meeting 'fully executable…specific examples; copy-paste ready' for an instruction/methodology skill.

3 / 3

Workflow Clarity

The 5-phase non-linear flow is explicitly sequenced with validation checkpoints and feedback loops — the Phase 5 'Pre-report gate' running /validate ('Any fail? -> KILL the finding'), the Multi-Tool Reproduction Bar, and PART 4 discipline rules with re-validate loops — plus checklists, matching 'clear sequence with explicit validation steps; feedback loops'.

3 / 3

Progressive Disclosure

No bundle files exist and the skill is a single ~500-line monolithic SKILL.md with content that could be split (tool-routing table, discipline rules, operator notes) living inline; sections are well-organized, so it clears the 'poor organization' level below, but fits 'content that should be separate is inline' rather than the 'appropriately split…one-level-deep references' anchor.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description with explicit 'Use when' trigger guidance, concrete enumerated capabilities, and natural user-facing trigger terms including verbatim user questions. It clearly answers both what the skill does and when to invoke it.

DimensionReasoningScore

Specificity

Names multiple concrete capabilities — 'combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments)' and 'Routes to all other skills based on current hunting phase' — in third person, matching the 'lists multiple specific concrete actions' anchor rather than the vague 'Names domain and some actions' level below.

3 / 3

Completeness

Explicitly answers both what ('Master orchestrator that combines…workflow with…framework…Routes to all other skills') and when ('Use at the START of any bug bounty hunting session…', 'Also use when asking…'), satisfying the 'clearly answers both what AND when with explicit triggers' anchor.

3 / 3

Trigger Term Quality

Includes natural phrases a user would say, even quoted verbatim — 'bug bounty hunting session', 'switching targets', 'feeling lost about what to do next', 'what should I do next', 'where am I in the process' — giving strong coverage rather than the 'some relevant keywords but missing common variations' level.

3 / 3

Distinctiveness Conflict Risk

Positions a clear niche as the top-level master orchestrator that 'Routes to all other skills based on current hunting phase' with distinct start-of-session triggers, fitting 'clear niche with distinct triggers'; it is more bounded than the 'could still overlap with similar skills' level below.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (513 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.