awesome-bug-bounty skillA
awesome-bug-bounty is agent-read markdown (skill) from aiskillstore/marketplace: Use when doing bug bounty hunting, vulnerability research, security report writing/analysis, payload or WAF-bypass selection, business logic / IDOR / race / API testing, recon methodology, tool choice (Burp vs Caido vs ZAP, AI pentest agents, MCP security testing, headless browsers), or looking up writeups/programs — e.g. "find XSS payload", "business logic checklist", "SSRF bypass", "HackerOne top reports", "bug bounty methodology", "which tools to install". Merges curated knowledge with source.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Awesome Bug Bounty Distilled knowledge base for bug bounty hunting and authorized security research. **Paths below are relative to this skill's directory.** Prefer them; only fetch source repos (Fallback table) when deeper detail is needed. ## Operating rules 1. Read extended detail from `knowledge/*.md` before improvising: - `knowledge/vuln-types.md` — per-vuln hunt focus + example patterns - `knowledge/payloads.md` — payload/bypass cheat sheet by context - `knowledge/business-logic.md` — business logic + race condition playbooks - `knowledge/methodology.md` — recon/API methodology, best practices, non-duplicated engagement path, report template, wordlists - `knowledge/tools.md` — tool-choice matrix: proxies, AI-native hunters, Obscura, MCP stack, authz/API/bizlogic tools - `knowledge/install.md` — install commands + post-install setup (API keys, proxy CA, MCP registration) …
Read the whole file at its exact version.
How to install
mdr add aiskillstore/marketplace/awesome-bug-bounty@git:20260924.17b2bb0mdr add aiskillstore/marketplace/awesome-bug-bounty@sha256:18f1e7f0d1c3c7c5Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_rccyo2vwgf3od6dr)
1 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (9992 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
aiskillstore/marketplace · 427 stars · license none · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_rccyo2vwgf3od6dr GET https://markdownregistry.com/api/v1/resolve?ref=aiskillstore/marketplace/awesome-bug-bounty GET https://markdownregistry.com/api/v1/blob/18f1e7f0d1c3c7c56d2e1169b1979ae1a4c75b519d87c2d8baf32cd4255eb1f4
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.