web-security-testing
80Run OWASP Web Security Testing
by sickn33
Web teams need a repeatable way to check common application risks before release. This skill organizes OWASP testing into phases, prompts, and reporting steps.
Plan Authorized Bug Bounty Research
Bug bounty research can become fragmented across tools, payloads, and reporting workflows. This skill organizes authorized testing into scoped, evidence-focused playbooks.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "awesome-bug-bounty" from https://skillstore.io/skills/yangtech-gh-awesome-bug-bounty.md and its manifest at https://skillstore.io/api/skills/yangtech-gh-awesome-bug-bounty/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "awesome-bug-bounty". Plan an authorized assessment for one web application and API with a strict request limit.
Expected outcome:
Using "awesome-bug-bounty". Turn a reproduced authorization issue into a concise bug bounty report.
Expected outcome:
A report with affected endpoint, role comparison, redacted evidence, impact, severity rationale, reproduction steps, and server-side authorization guidance.
Most static alerts are false positives caused by Markdown code spans, documentation links, placeholders, and named environment variables. Confirmed risks include privileged host changes, active scanners, persistent configuration edits, unverified installers, and actionable payloads for cloud metadata, command execution, and sensitive file access. No prompt injection, obfuscation, or credential-exfiltration path was found.
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/yangtech-gh-awesome-bug-bounty/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/yangtech-gh-awesome-bug-bounty?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/yangtech-gh-awesome-bug-bounty?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/yangtech-gh-awesome-bug-bounty/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/yangtech-gh-awesome-bug-bounty.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>yangtech-gh. (2026). awesome-bug-bounty security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/yangtech-gh-awesome-bug-bounty/audits/1@techreport{yangtech-gh-yangtech-gh-awesome-bug-bounty-2026,
author = {yangtech-gh},
title = {awesome-bug-bounty security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/yangtech-gh-awesome-bug-bounty/audits/1},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "awesome-bug-bounty security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "yangtech-gh"
date-released: "2026-09-24"
url: "https://skillstore.io/skills/yangtech-gh-awesome-bug-bounty/audits/1"
identifiers:
- type: other
value: "skillstore:yangtech-gh-awesome-bug-bounty:audit:1"
description: "Skillstore immutable audit report identifier"
Turn program rules into a phased reconnaissance and testing plan with rate limits and exclusions.
Select appropriate proxy, scanner, and replay tools for a suspected vulnerability class.
Convert reproduced findings into consistent, evidence-focused reports with impact and remediation.
Create a safe bug bounty plan for [authorized program]. Use the stated scope, exclusions, rate limits, and test window. Start with passive checks.
For suspected [vulnerability type] on [in-scope feature], provide a non-destructive checklist, required evidence, stop conditions, and suitable tools.
Assess this authorized test result: [redacted evidence]. Identify missing controls, reproduction steps, likely impact, false-positive risks, and safe verification steps.
Design a deduplicated workflow for [authorized program] covering web, API, authentication, and MCP surfaces. Include tool boundaries, rate caps, evidence gates, and reporting.
Author
yangtech-ghLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
1cda4003aa9ea65a9606af00b33e9c706ef03e62
Maintenance freshness
9/30/2026
Usage
0 downloads ยท 0 views
File structure
๐ knowledge/
๐ business-logic.md
๐ install.md
๐ methodology.md
๐ payloads.md
๐ tools.md
๐ vuln-types.md
๐ SKILL.md
Run OWASP Web Security Testing
by sickn33
Web teams need a repeatable way to check common application risks before release. This skill organizes OWASP testing into phases, prompts, and reporting steps.
Create Security Assessment Reports
by BytR-Ecosystems
Security findings often become inconsistent reports that are difficult to prioritize. This skill guides structured DOCX reports with risk ratings, evidence, and remediation plans.
Audit Codebases for Security Vulnerabilities
by cloudflare
Security reviews often miss trust-boundary failures or produce weak evidence. This skill structures reconnaissance, isolated validation, independent verification, and actionable reporting.
Guide Authorized Shodan Reconnaissance
by sickn33
Security teams need a repeatable way to find exposed services before attackers do. This skill organizes Shodan CLI, API, filters, exports, and reporting steps for authorized assessments.
Run Authorized Red-Team Workflows
by sickn33
Security teams need repeatable reconnaissance without losing scope discipline. This skill organizes authorized red-team and bug bounty workflows into practical steps.
Strengthen Application Security Reviews
by alirezarezvani
Security reviews often lack consistent checklists and reusable workflows. This skill provides security review scaffolds, reference guidance, and simple reporting scripts for Claude, Codex, and Claude Code.