Security Bounty Hunter
Hunt remotely reachable, bounty-worthy vulnerabilities in repos: SSRF, auth bypass, injection, traversal, with a triage workflow that skips the noise platforms reject.
- What
- Hunt remotely reachable, bounty-worthy vulnerabilities in repos: SSRF, auth bypass, injection, traversal, with a triage workflow that skips the noise platforms reject.
- Cost
- Free
- Needs
- Use "Security Bounty Hunter" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: a practical vulnerability-hunting playbook tuned for one question: does this actually pay? The skill biases hard toward remotely reachable, user-controlled attack paths and throws away the patterns bounty platforms routinely reject as informative or out of scope. In scope: SSRF through user-controlled URLs, auth bypass in middleware or API guards, remote deserialization and upload-to-RCE paths, SQL injection in reachable endpoints, command injection in request handlers, path traversal in file-serving paths, auto-triggered XSS. Explicitly skipped unless the program says otherwise: local-only pickle.loads, eval in CLI-only tooling, hardcoded shell=True, missing security headers alone, generic rate-limit complaints, self-XSS, out-of-scope CI injection, demo or test-only code. The workflow: check program scope first (rules, SECURITY.md, disclosure channel, exclusions), find real entrypoints (HTTP handlers, uploads, background jobs, webhooks, parsers, integration endpoints), use static tooling as triage input only, read the real code path, then prove exploitability before writing the report. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: only hunt on targets you are authorized to test; a checklist is not a pentest and never submit unverified findings. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Security Bounty Hunter" with your Muse. Prerequisites: none to install. Pure guidance; only use on targets you are authorized to test. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/security-bounty-hunter/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Hunt for bounty-worthy vulnerabilities in [repo/program], scope: [program rules]." 3. Work through the workflow with Muse: confirm scope, find entrypoints, triage, prove exploitability, then draft the report. Tip: start with the program's SECURITY.md and exclusions; the skill's skip list saves hours of dead-end triage. Safety: a skill is plain-text instructions; it runs nothing by itself. Only test authorized targets; never exfiltrate real data.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.