bug-bounty

分类: 测试与安全 | 上传者: shuvonsecshuvonsec | 下载: 0 | 版本: v1.0(最新)

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, smart contracts, SDK audit, SIWE), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction), and reporting (4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, submission checklist). Use for ANY bug bounty task — starting a new target, doing recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports.

更新日志: Source: GitHub https://github.com/shuvonsec/claude-bug-bounty

目录结构

当前层级: 根目录

SKILL.md

登录后下载/点赞/收藏 ❤ 31 | ★ 0
评论 0

请先登录后评论。

还没有评论,快来第一个发言吧。