OlympHill
Bugcrowd Reporting (Grade A) logo

Bugcrowd Reporting (Grade A)Security-tested testing-security skill for Claude AI. Grade A. Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, m

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

Bugcrowd-specific reporting tactics complementing report-writing. This skill provides strategies for selecting VRT categories, manual severity overrides, and rebuttal templates for out-of-scope (OOS) clauses. It's used for Bugcrowd submissions, especially when VRT defaults seem incorrect or triagers close issues as OOS. The skill includes techniques for target selection, researcher-side hygiene, and chained-finding cross-references. It pairs with report-writing and triage-validation skills.

Key features

  • VRT category search-and-fallback strategy
  • Manual severity override
  • OOS-clause rebuttal templates
  • Chained-finding cross-reference patterns
  • Target selection for QA-vs-prod programs
  • Researcher-side hygiene

Pricing

Model
Free
Category
Skills
Rating
No reviews yet

Use cases

Bugcrowd Submission with Non-Standard Impact

Use when filing a Bugcrowd submission with an impact that doesn't align with VRT default severities.

Triager Downgrade or OOS Closure

Use when a triager closes an issue as OOS or downgrades its severity, and you need to rebut with additional context.

Pros & Cons

Pros

  • Improves accuracy in VRT category selection
  • Enhances severity assessment with manual override options
  • Provides OOS-clause rebuttal templates
  • Supports researcher-side hygiene and best practices

Cons

  • Limited to Bugcrowd-specific use cases
  • Requires familiarity with VRT and Bugcrowd's submission flow
  • May not be directly applicable to other bug bounty platforms

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

Why this exists?

Most Claude bug‑hunting setups are either too generic (one big "security" prompt) or too fragmented (bookmarking dozens of disclosed reports). Neither scales past the second target. This bundle was built and validated through authorized engagements that exposed capability gaps: bug‑bounty work revealed missing hypothesis discipline, lack of per‑program reporting tactics, disorganized engagement coordination, and poor evidence hygiene. External red‑team work added gaps such as conservative defaults that retracted real findings, no mid‑engagement situational awareness, and missing enterprise‑platform attack chains (e.g., M365/Entra, SharePoint, SSL‑VPN, vCenter, Android APKs). The bundle addresses these issues with structured methodology, red‑team mindset, up‑to‑date CVE knowledge, and integrated reporting tools.

Asked by Petra Vogel · Jul 22, 2026

How it works?

It follows a six‑phase, non‑linear workflow: recon → map & rank → hunt → validate → report, with scope enforced in code and a 7‑Question Gate before any submission. You can drive the process in two ways: by describing what you’re testing in plain English, which automatically loads the relevant skill set, or by using the /hunt scaffold and the cbh CLI, which provides an engagement‑folder structure, state management, and orchestration. Documentation includes a usage guide, a worked example, a diagram of the six‑phase architecture, and a skill‑to‑phase mapping.

Asked by Jana Krejčí · Jun 2, 2026

What's inside?

The bundle contains 82 skills, auto‑loaded by topic with no need to invoke them by name. Coverage spans the external attack surface: Web application hunting (13 skills, e.g., XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open‑redirect), Authentication & identity (7 skills, e.g., auth‑bypass, session, OAuth, SAML, MFA‑bypass, ATO), API & infrastructure (15 skills, e.g., GraphQL, gRPC, WebSocket, API‑misconfig, host‑header, RCE), Advanced & concurrency (6 skills, e.g., race‑condition, HTTP smuggling, deserialization, cache‑poison), Framework‑specific (4 skills, e.g., Next.js, Node.js, Laravel, Spring Boot), Enterprise identity & cloud (3 skills, e.g., M365/Entra, Okta, cloud‑IAM), Infrastructure & appliance (4 skills, e.g., VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM), Red‑team tradecraft (4 skills, e.g., redteam‑mindset, APK pipeline, supply‑chain recon, mid‑engagement IR), Recon & OSINT (4 skills), and Workflow, reporting & specialized (11 skills). The catalog is searchable in docs/skills.md, and the bundle also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine that maps a target’s attack surface and routes each finding to the appropriate skill.

Asked by Joanna Kowalski · May 17, 2026

What is this?

claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug‑hunting researcher or red‑team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb‑methodology + redteam‑mindset: the 5‑phase non‑linear workflow, critical‑thinking framework, and red‑team operator discipline. Hunt webapps — 48 hunt‑skills curated from 681 disclosed HackerOne reports: per‑class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL‑VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post‑credential escalation. Ship it — triage‑validation + reporting + evidence‑hygiene: the 7‑Question Gate, VRT‑aware severity, OOS rebuttals, PII redaction, and red‑team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads.

Asked by Bruno Kaufmann · Apr 26, 2026

Ask a question

Skills alternatives

Manage Headers (Grade A) logo

Manage Headers (Grade A)

Skills

Security-tested development skill for Claude AI. Grade A. Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection

(0)
Free
Using Git Worktrees (Grade A) logo

Using Git Worktrees (Grade A)

Skills

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

(0)
Free
Ga4 Bigquery Schema (Grade A) logo

Ga4 Bigquery Schema (Grade A)

Skills

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

(0)
Free
Meta Capi (Grade A) logo

Meta Capi (Grade A)

Skills

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

(0)
Free
Callees (Grade A) logo

Callees (Grade A)

Skills

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

(0)
Free
Test Module Name (Grade A) logo

Test Module Name (Grade A)

Skills

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

(0)
Free
Board Of Directors (Grade A) logo

Board Of Directors (Grade A)

Skills

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

(0)
Free
Advpl Mvc Avancado (Grade A) logo

Advpl Mvc Avancado (Grade A)

Skills

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)

(0)
Free