Bug bounty: методология охоты на уязвимости
★ 8.1 · general
bb-methodology is a Claude Code skill that acts as the master orchestrator for bug bounty hunting sessions, combining a 5-phase non-linear workflow with a critical thinking framework built around developer psychology, anomaly detection, and What-If experiments. It helps define a CIA-Impact goal, narrow focus to 1–2 vulnerability classes per session, and route to the right techniques based on the current hunting phase. The skill includes a 7-phase amateur-vs-pro comparison, a multi-perspective testing matrix covering horizontal, vertical, time-state, and client-environment angles, tactical anomaly patterns, and a dedicated section on using AI as a second analyst to generate hypotheses and turn them into reproducible HTTP experiments. Use it at the start of a session, when switching targets, or whenever the next step is unclear.