← Search

Security Bounty Hunter
Security
⚙ Needs: Use "Security Bounty Hunter" with your Muse.

Security Bounty Hunter

Hunt remotely reachable, bounty-worthy vulnerabilities in repos: SSRF, auth bypass, injection, traversal, with a triage workflow that skips the noise platforms reject.

At a glance
What
Hunt remotely reachable, bounty-worthy vulnerabilities in repos: SSRF, auth bypass, injection, traversal, with a triage workflow that skips the noise platforms reject.
Cost
Free
Needs
Use "Security Bounty Hunter" with your Muse.
Install
Copy the installer prompt below into your Muse — your agent does the rest.

Version:

⌁

Install

Copy the install package below, then paste it into Muse
Wanna be extra careful?

The install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?

How to check a build before installing →

Use "Security Bounty Hunter" with your Muse. Prerequisites: none to install. Pure guidance; only use on targets you are authorized to test. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/security-bounty-hunter/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Hunt for bounty-worthy vulnerabilities in [repo/program], scope: [program rules]." 3. Work through the workflow with Muse: confirm scope, find entrypoints, triage, prove exploitability, then draft the report. Tip: start with the program's SECURITY.md and exclusions; the skill's skip list saves hours of dead-end triage. Safety: a skill is plain-text instructions; it runs nothing by itself. Only test authorized targets; never exfiltrate real data.

?

Questions

How do I install a build?

Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.

Where does my money go?

Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.

What does the ✓ next to a creator’s name mean?

It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.