CtrlK
BlogDocsLog inGet started
Tessl Logo

bb-methodology

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other skills based on current hunting phase. Also use when asking "what should I do next" or "where am I in the process."

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The content is highly actionable with clear, validated workflows and concrete tooling. Its main weaknesses are repetition that inflates length and a monolithic structure with several phantom references to bundle files that are not present.

Suggestions

Deduplicate the Define/Select/Execute discipline and the time-boxing rules, stating each once and cross-referencing rather than re-explaining.

Either provide the referenced bundle files (docs/auth-sessions.md, tools/bypass_403.sh, tools/waf_encoder.py, tools/multipart_mutator.py) or split the large inline tool-routing and comparison tables into referenced files so the SKILL.md body is a concise overview.

DimensionReasoningScore

Conciseness

The ~380-line body is dense and action-oriented with little concept filler, but repeats the Define/Select/Execute discipline in both PART 1 and Phase 0 and re-states the 5/20/45-minute rules in multiple places, so it could be tightened.

2 / 3

Actionability

Highly concrete guidance throughout: named tools (bypass_403.sh, waf_encoder.py, subfinder, ffuf -ac, nuclei -tags cve), slash commands (/recon, /validate, /report), specific payloads ({{7*7}}, SLEEP(10), AND 1=1), and copy-paste-ready ASCII decision trees.

3 / 3

Workflow Clarity

The 5-phase non-linear flow is explicitly sequenced with validation checkpoints such as the Pre-report gate ('Run /validate (7-Question Gate)', 'All 7 pass? -> Write report / Any fail? -> KILL') and feedback loops for triage and re-test.

3 / 3

Progressive Disclosure

The body is a single monolithic document with tool-routing tables and the Amateur-vs-Pro comparison kept inline, and it references files that do not exist in the bundle (docs/auth-sessions.md, tools/bypass_403.sh, tools/waf_encoder.py).

2 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it states concrete capabilities, includes natural trigger phrases, answers both what and when with explicit triggers, and carves out a distinct orchestrator niche. No changes needed.

DimensionReasoningScore

Specificity

Lists multiple concrete actions: 'combines the 5-phase non-linear hunting workflow', 'critical thinking framework (developer psychology, anomaly detection, What-If experiments)', and 'Routes to all other skills based on current hunting phase'.

3 / 3

Completeness

Clearly answers both what (master orchestrator combining workflow + framework, routes to other skills) and when (explicit 'Use at the START of any bug bounty hunting session' and 'Also use when asking...').

3 / 3

Trigger Term Quality

Natural phrases a user would say are well covered: 'when switching targets', 'feeling lost about what to do next', 'what should I do next', and 'where am I in the process'.

3 / 3

Distinctiveness Conflict Risk

Claims a clear niche as the 'Master orchestrator' that 'Routes to all other skills based on current hunting phase', a distinct coordinator role unlikely to trigger for the wrong skill.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
shuvonsec/claude-bug-bounty
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.