Source

awarexone/agentic-bug-hunter

15 skills · 337 combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
bug-bounty Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source…
awarexone/agentic-bug-hunter
307
2
triage-validation Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-reje…
awarexone/agentic-bug-hunter
4
3
cicd-security CI/CD pipeline security hunting — GitHub Actions workflow injection, secret exfiltration, self-hosted runner poisonin…
awarexone/agentic-bug-hunter
3
4
credential-attack Password spray methodology for bug bounty — when to do it vs web-vuln hunting, the wordlist-gen + breach-check + osin…
awarexone/agentic-bug-hunter
3
5
graphql-audit GraphQL security hunting — introspection abuse, field suggestion enumeration (clairvoyance), batching DoS, IDOR via a…
awarexone/agentic-bug-hunter
3
6
mobile-pentest Mobile app pentest for bug bounty (Android APK + iOS IPA) — runtime-first workflow: install app, proxy through Burp/m…
awarexone/agentic-bug-hunter
3
7
web2-vuln-classes Complete reference for 26 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, a…
awarexone/agentic-bug-hunter
3
8
argus Argus — the all-seeing scanner suite. Six automated scanners for high-value web + LLM bug classes — CORS misconfigura…
awarexone/agentic-bug-hunter
2
9
client-reverse Client-side request-signing and anti-bot token reversal for bug bounty — when a request carries a sign/sig/hmac/token…
awarexone/agentic-bug-hunter
2
10
report-writing Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first …
awarexone/agentic-bug-hunter
2
11
bb-methodology Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do nex…
awarexone/agentic-bug-hunter
1
12
meme-coin-audit Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), So…
awarexone/agentic-bug-hunter
1
13
security-arsenal Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with…
awarexone/agentic-bug-hunter
1
14
web2-recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), U…
awarexone/agentic-bug-hunter
1
15
web3-audit Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, …
awarexone/agentic-bug-hunter
1