vulns.co
/
GKData.io MCP

Agent orchestration for bug bounty

Five roles, in order. The parent loads the orchestrate prompt, then one role prompt per sub-agent. A later role cannot cite evidence the previous handoff did not record.

How the parent splits the work

  1. Call get_team with the skill slug, or load the prompt orchestrate with that skill.
  2. Spawn one sub-agent per role, in order. Give it the prompt role-mapper, then role-solver, and so on, with the same skill argument.
  3. Pass only the previous handoff forward. The handoff is role, skill, showed, inferred, and stop.
  4. The parent does not merge five opinions into a finding. Only the validator's showed list may enter the draft.

1. Mapper

Reads: Program scope and notes you already saved.

Writes: In-scope hosts, the accounts you own, the objects, and the trust boundaries.

Refuses: State-changing requests, and any claim of impact.

Stop: Two accounts and one object you will not read are named.

Prompt name: role-mapper

2. Solver

Reads: The mapper handoff and one skill.

Writes: One hypothesis, the allow case, the deny case, and what was saved.

Refuses: A second hypothesis in the same pass.

Stop: One comparison is saved, or the handoff says not tested.

Prompt name: role-solver

3. Skeptic

Reads: The solver handoff only.

Writes: Pass, fail, or insufficient, and the cheaper falsifying test.

Refuses: New scope, and a stronger impact than the solver recorded.

Stop: The claim is killed, or it is reduced to one remaining discriminator.

Prompt name: role-skeptic

4. Validator

Reads: The claim the skeptic left standing.

Writes: What was shown, and what was inferred.

Refuses: A new bug, and other people's data.

Stop: The minimum proof is recorded, or the claim is withdrawn.

Prompt name: role-validator

5. Reporter

Reads: The validator handoff and the report skill.

Writes: A draft with the boundary, the evidence, the source-reported impact, and the fix.

Refuses: Payloads, an upgraded severity, and a predicted payout.

Stop: The draft can be checked against the validator handoff line by line.

Prompt name: role-reporter

The roster is the same record the MCP returns. Skills choose the question. Install the MCP to load the prompts.