Methodology reference for Mastermind Bug Bounty runtime. Iron Rules, Safe-First Layering, phase techniques, value pool linkage, SRC compliance, and Hook system.
AI/LLM security testing specialist. Tests for prompt injection, jailbreak, MCP/Agent attacks, RAG poisoning, system prompt extraction, and tool/function call abuse. Optional phase.
API 发现与语义化 Fuzz 专家。基于 Recon 产出的 _endpoint_params.json (接口→参数需求映射表)和数据联动值池,执行全接口覆盖测试、响应挖掘、 参数注入和语义化 Fuzz。核心原则:用 JS 提取的参数需求 + 响应泄露的真实值 驱动测试,而不是盲目 fuzz。
Access control bypass specialist. Handles 401/403/405 responses using path manipulation, HTTP method switching, header injection, middleware-specific techniques, and JWT token attacks. Third phase in the pipeline.
★ AI 优势赛道 — 加密/编码攻击专家。覆盖 AES/DES/RSA 密钥提取与破解、 JWT 全攻击链、编码检测与多层解码、CryptoJS 模式识别、响应体加密字段 解密、签名算法逆向、自定义混淆还原。
★ Exploit + Report: vulnerability exploitation specialist. Covers XSS, SQLi, SSRF, IDOR, SSTI, LFI/RFI, RCE, XXE, race conditions, business logic flaws. Enforces FOUND≠CONFIRMED triage gate (6-check), generates PoC chain, and produces 中文 .docx HackerOne/SRC-format reports. Final required phase.
Reconnaissance specialist. 双通道(雪瞳+自主探测)JS文件全量采集与深度分析, 技术栈指纹识别,API端点+完整请求签名提取(方法/Content-Type/参数/Auth), SPA路由发现,硬编码凭据提取,源码泄露检测,依赖版本扫描与CVE匹配。 产出: _endpoint_params.json + _secrets_found.json + _leaked_values.json 初始值池。
Report generation specialist. Converts triage-approved findings into HackerOne-format reports with CVSS scoring, PoC evidence chains, and remediation guidance. Final phase in the pipeline.