| name | bug-bounty |
| description | Bug bounty workflow using Deep Eye for recon/scan and high-signal report writing (HackerOne/Bugcrowd). Use for bug bounty, VDP, HackerOne, Bugcrowd, bounty report, /bug-bounty. Only in-scope program assets. |
Deep Eye — Bug Bounty Skill
Policy first. Deep Eye accelerates surface coverage; impact + PoC win bounties.
Preconditions
- Program policy read (scope, OOS, rate limits, safe harbor).
- In-scope only — no third-party collateral.
- Local config; never commit API keys or session cookies.
ROI module pack
Enable in vulnerability_scanner.enabled_checks:
enabled_checks:
- idor
- api_bola_deep
- jwt_deep
- oauth_testing
- graphql_deep
- ssrf_cloud
- cloud_misconfig
- cors_csp
- open_redirect_deep
- stored_xss
- sql_injection
- xss
- ssrf
- mass_assignment
Optional: ai_triage.enabled, bug_bounty.enabled (Markdown under reports/bounty/).
Commands
python deep_eye.py --setup
python deep_eye.py -u https://IN_SCOPE -v --formats json,html
python deep_eye.py -u https://IN_SCOPE --scope-nl "only /api/* host target.com"
python deep_eye.py -u https://IN_SCOPE --retest-new reports/prior.json
OpenAPI: openapi.enabled: true + source.
Hunt order
- Authz —
idor, api_bola_deep
- Token/auth —
jwt_deep, oauth_testing, login_replay
- SSRF/cloud —
ssrf_cloud, cloud_misconfig
- GraphQL —
graphql_deep
- Stored XSS chains —
stored_xss
- Secrets — only if actionable (
secret_scanning)
Report template
## Summary
## Steps to reproduce
## PoC
## Impact
## Remediation
## Environment
Finding keys: type, severity, url, parameter, payload, evidence, remediation.
Rules
Respect rate limits; redact PII; check duplicates; show delta impact on partial dupes.