Home / aiskillstore / marketplace · pending/yangtech-gh/awesome-bug-bounty/SKILL.md · GitHub

awesome-bug-bounty skillA

awesome-bug-bounty is agent-read markdown (skill) from aiskillstore/marketplace: Use when doing bug bounty hunting, vulnerability research, security report writing/analysis, payload or WAF-bypass selection, business logic / IDOR / race / API testing, recon methodology, tool choice (Burp vs Caido vs ZAP, AI pentest agents, MCP security testing, headless browsers), or looking up writeups/programs — e.g. "find XSS payload", "business logic checklist", "SSRF bypass", "HackerOne top reports", "bug bounty methodology", "which tools to install". Merges curated knowledge with source.

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Awesome Bug Bounty

Distilled knowledge base for bug bounty hunting and authorized security research. **Paths below are relative to this skill's directory.** Prefer them; only fetch source repos (Fallback table) when deeper detail is needed.

## Operating rules

1. Read extended detail from `knowledge/*.md` before improvising:
   - `knowledge/vuln-types.md` — per-vuln hunt focus + example patterns
   - `knowledge/payloads.md` — payload/bypass cheat sheet by context
   - `knowledge/business-logic.md` — business logic + race condition playbooks
   - `knowledge/methodology.md` — recon/API methodology, best practices, non-duplicated engagement path, report template, wordlists
   - `knowledge/tools.md` — tool-choice matrix: proxies, AI-native hunters, Obscura, MCP stack, authz/API/bizlogic tools
   - `knowledge/install.md` — install commands + post-install setup (API keys, proxy CA, MCP registration)
…

Read the whole file at its exact version.

How to install

Latest version
mdr add aiskillstore/marketplace/awesome-bug-bounty@git:20260924.17b2bb0
Exact content
mdr add aiskillstore/marketplace/awesome-bug-bounty@sha256:18f1e7f0d1c3c7c5

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_rccyo2vwgf3od6dr.svg)](https://markdownregistry.com/a/art_rccyo2vwgf3od6dr)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260924.17b2bb0 latest2026-09-24 17b2bb0 9,992 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (9992 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

aiskillstore/marketplace · 427 stars · license none · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_rccyo2vwgf3od6dr
GET https://markdownregistry.com/api/v1/resolve?ref=aiskillstore/marketplace/awesome-bug-bounty
GET https://markdownregistry.com/api/v1/blob/18f1e7f0d1c3c7c56d2e1169b1979ae1a4c75b519d87c2d8baf32cd4255eb1f4

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from aiskillstore/marketplace

sitemapkit skill
aiskillstore/marketplace · pending/0nl1n1n/sitemapkit/SKILL.md · Discover and extract sitemaps from any website using SitemapKit. Use this skill whenever the user wants to find pages…
git:20260903.f89877a · audit A · 427 stars
angular-developer skill
aiskillstore/marketplace · pending/angular/angular-developer/SKILL.md · Generates Angular code and provides architectural guidance. Trigger when creating projects, components, services, or…
v1.0 · audit A · 427 stars
angular-new-app skill
aiskillstore/marketplace · pending/angular/angular-new-app/SKILL.md · Creates a new Angular app using the Angular CLI. This skill should be used whenever a user wants to create a new…
v1.0 · audit A · 427 stars
.cursorrules rules
aiskillstore/marketplace · pending/axelfreeman/marketing-mindset/.cursorrules
git:20260903.567c889 · audit A · 427 stars
AGENTS.md@pending/axelfreeman/marketing-mindset agents
aiskillstore/marketplace · pending/axelfreeman/marketing-mindset/AGENTS.md
git:20260903.567c889 · audit A · 427 stars
marketing-mindset skill
aiskillstore/marketplace · pending/axelfreeman/marketing-mindset/SKILL.md · Use when the user needs a professional marketer's operating mindset for any marketing, growth, or client-acquisition…
v0.1.0 · audit A · 427 stars
llms.txt@pending/axelfreeman/marketing-mindset llmstxt
aiskillstore/marketplace · pending/axelfreeman/marketing-mindset/llms.txt
git:20260903.567c889 · audit A · 427 stars
brand-voice-editor skill
aiskillstore/marketplace · pending/azeemkafridi/brand-voice-editor/SKILL.md · Edit social media content into a consistent brand voice while preserving facts and preparing it for BulkPublish…
git:20260902.2316198 · audit A · 427 stars
bulk-publish skill
aiskillstore/marketplace · pending/azeemkafridi/bulk-publish/SKILL.md · Upload media files (local or URL), manage media library, and batch-create posts via BulkPublish. Use when the user…
git:20260902.082a188 · audit A · 427 stars
campaign-performance-report skill
aiskillstore/marketplace · pending/azeemkafridi/campaign-performance-report/SKILL.md · Produce campaign performance reports from BulkPublish analytics with platform-aware metrics, caveats, and…
git:20260902.71e47fa · audit A · 427 stars
check-quota skill
aiskillstore/marketplace · pending/azeemkafridi/check-quota/SKILL.md · Check BulkPublish plan limits and current usage. Use when the user asks about their plan, limits, or remaining quota.
git:20260902.32a44bf · audit A · 427 stars
content-repurposing skill
aiskillstore/marketplace · pending/azeemkafridi/content-repurposing/SKILL.md · Repurpose a source article, newsletter, transcript, or announcement into a coordinated BulkPublish social content…
git:20260902.171842e · audit A · 427 stars

Every file in aiskillstore/marketplace

Browse by kind, by grade A, or by owner.