MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

bb-methodology

bb-methodology is an code AI skill with a core value of Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next.

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/bb-methodology && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/bb-methodology/SKILL.md -o ./skills/bb-methodology/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

> **⚠️ AUTHORIZED USE ONLY**

> This skill is for educational purposes or authorized security assessments only.

> You must have explicit, written permission from the system owner before using this tool.

> Misuse of this tool is illegal and strictly prohibited.


> **Mandatory confirmation gate**

> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

> 1. Ask the user to state the exact target URL, IP, account, or resource.

> 2. Ask the user to confirm written authorization and the permitted scope.

> 3. Show the exact command(s) and explain their expected effect.

> 4. Wait for explicit confirmation in the current conversation.

>

> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.


# Bug Bounty Methodology: Workflow + Mindset


Master orchestrator for hunting sessions. Combines the 5-phase non-linear workflow with the critical thinking framework that separates top 1% hunters from the rest.


---


PART 0: MODE CONFIRMATION (Before Anything Else)


**Confirm the engagement type before deciding what counts as a finding.** The same target produces a different report shape depending on which mode applies. Getting this wrong is the single biggest waste of time in this workflow — answer it explicitly before Phase 0.


| Engagement type | What counts as a finding | What gets rejected |

|---|---|---|

| **Bug bounty** (H1 / Bugcrowd / Intigriti / private VDP) | Impact-demonstrated bugs ONLY. Full chain to attacker-attainable harm. | Hygiene (EoL software alone, permissive CSP alone, stack traces, info disclosure without concrete impact, "best practice" violations) |

| **Red team** (external client engagement) | Hygiene findings + recon + IoCs + defensive-state observations are ALL deliverables | Nothing — even "no finding here" is reportable as a positive defensive observation |

| **Pentest** (signed SoW / WAPT) | Depends on SoW. Read scope explicitly. Usually accepts hygiene + impact + recon | Out-of-scope assets, unsigned testing |

| **Internal audit** | Compliance-mapped findings (PCI / ISO / NIST / DPDPA / GDPR) | Findings without a control-mapping |


**Hard rule:** Before Phase 0 runs, write the engagement type as the first line in your hunt notes. If you can't answer it from the user's instruction, ASK once. Don't assume — the mistake costs both you and the triager.


**Lesson from an authorized engagement:** First-pass on this target produced 5 hygiene findings (SP2013 EoL, permissive CSP, stack traces) shipped in red-team format. The engagement was bug-bounty. Findings would have been N/A'd as "informational, no impact demonstrated." After the corrected pass with hygiene-as-context-not-finding, the same target yielded 11 impact-demonstrated bugs including 3 Critical.


---


PART 1: MINDSET (How to Think)


Core Principle


Hunting is not "find a bug" -- it is "prove an attack scenario." Think like an attacker with a specific goal, not a scanner looking for patterns.


Daily Discipline: Define, Select, Execute


Before touching any tool:


1. **Define**: "Today I target [feature/domain] to achieve [CIA impact]"

2. **Select**: Choose 1-2 vuln classes (IDOR, Race Condition, etc.)

3. **Execute**: Focus ONLY on selected techniques. No wandering.


5 Ultimate Goals (Pick One Per Session)


1. **Confidentiality** -- steal data the attacker shouldn't see

2. **Integrity** -- modify data the attacker shouldn't change

3. **Availability** -- disrupt service (app-level DoS only)

4. **Account Takeover** -- control another user's account

5. **RCE** -- execute commands on the server


4 Thinking Domains


#### 1. Critical Thinking (deep analysis)


**Question trust boundaries:**

- Frontend control disabled? Send request directly via proxy

- `user_role=user` cookie? Change to `admin`

- `price=1000` in POST? Change to `1`

- `<script>` blocked? Try `<img onerror=...>`


**Reverse

🎯 Best For

  • Claude users
  • Software engineers
  • Development teams
  • Tech leads

💡 Use Cases

  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply bb-methodology to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Is bb-methodology compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for bb-methodology?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install bb-methodology?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/bb-methodology/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills