Hunting Methodology
SkillSecurityBug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Hunting Methodology skill
What this skill tells your AI
The instructions your AI receives, as published by h-mmer/pentest-agents in skills/hunting-methodology/SKILL.md and read by ahel’s review.
The 5-Phase Non-Linear Workflow
Phase 1: Understand the Target (before touching anything)
- Read program scope, policy, safe harbor
- Read 5+ disclosed reports in hacktivity
- Map crown jewels: what would hurt the company most?
- Understand the business domain — what features handle money, PII, auth?
Phase 2: Map the Surface
- Subdomain enumeration → live hosts → tech stack detection
- JS bundle analysis → API endpoints, secrets, internal URLs
- Run
/surfacefor P1/P2/Kill ranking
Phase 3: Hunt (the actual testing)
- Pick P1 target from surface ranking
- Select vuln class based on tech stack:
- Rails/Django/Laravel → IDOR, mass assignment
- Express/Node → prototype pollution, path traversal
- Spring Boot → Actuator, SSTI
- Next.js → SSRF via Server Actions
- GraphQL → introspection, IDOR via node(), mutation auth bypass
- Test with concrete payloads (see /hunt)
- Apply the Sibling Rule on every endpoint
- 20-minute rotation if no progress
- Build a depth matrix before declaring a class exhausted:
- Dimensions:
entrypoint × method × content-type × encoding × bypass - Minimum 30 combinations on P1 surface (seed with
uv run python3 $CLAUDE_PROJECT_DIR/tools/intel_engine.py matrix <class>) - Do not stop at the first blocked payload — mutate and continue
- Dimensions:
- Run cross-context variants for every promising input:
- URL / query, JSON, form-urlencoded, multipart, GraphQL variables
- Header / cookie mirrors, reflected values, stored values, async jobs / webhooks
- Execute encoding ladders systematically:
- raw → URL → double-URL → unicode escape → mixed-case / separator insertion
- Keep the semantic payload constant through each ladder step
- Then stack encodings in a single payload:
html-entity+URL(%26lt%3Bscript%26gt%3B),URL+html-entity,unicode-escape+URL,base64+URL. WAFs typically decode once; targets decode twice, so a payload that looks benign after a single decode still executes at the sink.
- Execute auth-state permutations:
- unauthenticated, low-priv user A, low-priv user B, high-priv, expired token, stale session, cross-tenant
- Compare response deltas (status, length, timing), not only status codes
- Treat every bypass as a family, not a one-off:
- For WAF / filter blocks, try separator insertion, case toggling, alternate delimiters, parser differentials, and protocol / host normalization tricks
- Log negative evidence (what failed and why) via
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> recon "coverage-<class>" "<details>"so autopilot resume avoids repeating exhausted paths.
Phase 4: Validate + Chain
- Run 7-Question Gate on any signal
- If PASS → check A→B chain table
- If CHAIN REQUIRED → build the chain or drop it
- If KILL → move on immediately
Phase 5: Report + Submit
- Quality check (score ≥ 7)
- Dupcheck against hacktivity
- Submit with PoC + evidence + CVSS 4.0
Wide vs Deep Route Selection
Wide route (recon-heavy): New target, unknown surface, no prior data.
- Run
/pipelinefor broad coverage first - Then
/surfaceto prioritize
Deep route (hunt-heavy): Known target, mapped surface, returning hunter.
- Run
/resumeto see what's untested - Pick the highest-ROI untested endpoint
- Go deep on one vuln class
Developer Psychology
Developers make CLASS mistakes, not random ones:
- If they forgot auth on endpoint A, they probably forgot on B and C
- If they use sequential integer IDs anywhere, they use them everywhere
- If input validation is weak in one form, check ALL forms
- New features (< 30 days) have the weakest security
- Acquired companies (different code, different team) = fresh attack surface
Time Management
| Rule | Action |
|---|---|
| 5-minute rule | No interesting signals after 5 min → skip target |
| 20-minute rotation | No progress in 20 min → rotate vuln class or endpoint |
| 1-hour rule | Stuck on one target for 1 hour → switch programs entirely |
| A→B time box | 20 min per B candidate, max 3 candidates |
| Exhaustion rule | A class is "exhausted" only after the depth matrix baseline + sibling coverage (see Phase 3 steps 6-11) |
ROI Ranking by Bug Class
| Bug Class | Competition | Avg Payout | Verdict |
|---|---|---|---|
| IDOR | Medium | High | Best ROI — always test first |
| Auth bypass | Medium | High | Second priority |
| Business logic | Low | High | Unique to each target |
| Race conditions | Low | Medium-High | Under-tested |
| OAuth/OIDC chains | Low | High | Complex but high payoff |
| SSRF → cloud | Medium | Very High | If you find DNS callback |
| Cache poisoning | Low | High | Rare skill |
| XSS | Very High | Medium | Skip unless you have a chain |
| Open redirect | Very High | Low | Only with OAuth chain |
| Missing headers | Infinite | $0 | Never submit |
Signals
- GitHub stars
- 908
- Forks
- 169
- Last commit
- Jun 2026
Advanced
- Catalog kind
- skill
- Gateway key
hunting-methodology- Source
- github.com/h-mmer/pentest-agents