Bug bounty skills for agents
Product revision 2026.09. 15 stack skills. Load one as an MCP prompt by its slug, or call get_skill for the linked playbooks, checklists, and disclosure cards.
Install the hosted MCP, then call list_skills or get_skill with the slug. Browser utilities named on a skill stay in the browser. Paste tools named under local MCP stay on the local connector.
Scope and intake
A program is in front of you and nothing is mapped yet.
Ask: Which hosts are in scope, which two accounts do I own, and what will I refuse to read?
Stop: The in-scope hosts, the accounts, and one out-of-scope object are written down.
Playbooks: scope-and-intake
Checklists: first-hour
Tell the agent: Load the vulns.co skill intake with get_skill. Do not propose requests until scope, two owned accounts, and one object you will not read are named.
Access control and tenant boundaries
The app has users, orgs, or object ids.
Ask: Can account A read or change an object that belongs to account B, including a job, export, or leftover endpoint?
Stop: One object you own is denied to the other account, and one object you should not own is not returned.
Playbooks: idor-hunting, tenant-isolation, export-webhook-authz, mass-assignment-play
Checklists: authz, tenant-check, export-webhook-check
Hunts: idor, tenant, webhook, assignment
Disclosures: bykea-zombie-endpoint-idor, hackerone-graphql-tag-idor
Tell the agent: Load the vulns.co skill access-control. Ask for the checklist before a request. Compare two saved responses locally. Do not call a missing id a finding until the other account's object comes back.
Session, cookies, and passkeys
Login, recovery, or cookies are in scope.
Ask: Which cookie or token does the server trust, and can recovery issue a session the primary login would not?
Stop: You can name the cookie or token, the recovery path, and whether a second browser still holds a session after logout.
Playbooks: account-takeover, passkey-webauthn, cookie-session-binding, two-factor-bypass, jwt-attacks, reset-token-binding
Checklists: authn-ato, passkey-check, session-cookie-check, jwt-check
Hunts: session, passkey, 2fa, jwt, reset
Disclosures: nextcloud-webauthn-public-key
Tell the agent: Load the vulns.co skill session. Record the browser and the cookie setting you observed. Do not claim third-party cookies are gone.
OAuth, DPoP, and mix-up
The target has an authorization server or signs in with one.
Ask: Is the authorization code bound to this client, and can the token be replayed without the proof the server claimed to require?
Stop: You have the authorization response fields you observed, including whether iss is checked, and you have not reused a code.
Playbooks: oauth-dpop-mixup, oauth-attacks
Checklists: oauth-modern-check
Hunts: oauth
Disclosures: pixiv-oauth-redirect-code
Tell the agent: Load the vulns.co skill oauth. Treat oauth-attacks and oauth-dpop-mixup as one path: mix-up and downgrade first, older redirect bugs second. The pixiv card shows a redirect that left the registered callback. Do not replay its redirect.
GraphQL APIs
A GraphQL endpoint or a persisted-query client is in the app.
Ask: Does the operation name or the persisted query id skip the authorization check the HTTP route was supposed to enforce?
Stop: One allowed operation and one denied operation are saved, and suggestions or introspection are labeled as inventory.
Playbooks: graphql-abuse, graphql-persisted-queries
Checklists: graphql-check
Hunts: graphql
Disclosures: hackerone-graphql-tag-idor
Tell the agent: Load the vulns.co skill graphql. Fingerprint only. A suggestion or an open introspection result is not the finding. The finding is an operation that acts on an object the caller does not own.
JavaScript and client trust
The app ships a bundle, a source map, or a message listener.
Ask: Which source reaches which sink, and which of those sinks is behind an origin check?
Stop: You have line numbers for the listener or sink, and you have not claimed execution from a pattern match.
Playbooks: javascript-analysis, js-spa-hunting, postmessage-dom
Checklists: js-review
Hunts: xss, postmessage
Disclosures: nasa-globe-upload-stored-xss
Tell the agent: Load the vulns.co skill javascript. Analyze saved source locally. Report line numbers and the missing check. Do not paste a payload into the hosted MCP.
Cache deception and cache poisoning
A response might be stored and later reused.
Ask: Is a private response stored at a URL the cache treats as static, or does an unkeyed input change what other users receive?
Stop: You can say which of the two bugs you observed. Do not file one as the other.
Playbooks: cache-deception, web-cache-poisoning
Checklists: cache-deception-check, cache-check
Hunts: cache-deception, cache
Disclosures: algolia-web-cache-deception, paypal-smuggled-cached-response
Tell the agent: Load the vulns.co skill cache. web-cache-poisoning is poisoning only. cache-deception is deception only. The Algolia card is deception. The PayPal card is smuggling that stored a cached response. Report them separately.
Agents, MCP, and retrieval
A feature calls tools, retrieves documents, or connects an MCP server.
Ask: Is the tool token wider than the tool, or did retrieval return another tenant's text into a context I am allowed to see?
Stop: You can show the token audience or the retrieved chunk boundary. A confused answer with no authority behind it is not the report.
Playbooks: mcp-tool-trust, rag-document-trust
Checklists: mcp-agent-check, rag-check
Disclosures: cloudflare-playground-mcp-xss
Tell the agent: Load the vulns.co skill ai-agent. Use mcp-tool-trust or rag-document-trust for the test. ai-llm-testing only classifies the surface. A prompt that only confuses the model is not the report. The Cloudflare card is a session that could act on a connected MCP server. Quote the low score the program disclosed.
CI and dependency trust
Workflows, packages, or update channels are in scope.
Ask: Does a pull request workflow run untrusted code with the base repository's secrets, or does a package name resolve to an owner the build did not pin?
Stop: You have the workflow trigger and the permission it has, or the package coordinate and who published it. Do not run a hostile install.
Playbooks: github-actions-trust, dependency-confusion, cicd-secret-recon
Checklists: supply-chain-check
Hunts: supply-chain
Disclosures: xz-utils-upstream-backdoor
Tell the agent: Load the vulns.co skill supply-chain. Read the workflow file you already have. Do not print a workflow exploit.
Mobile links and API hosts
An app claims links or ships an API host in the binary.
Ask: Which hosts does the app trust for links, and does the API check the same object ownership as the UI?
Stop: You have the association file or the claimed hosts, and one API call compared across two accounts.
Playbooks: mobile-applinks
Checklists: mobile-link-check
Hunts: mobile
Disclosures: bykea-zombie-endpoint-idor
Tell the agent: Load the vulns.co skill mobile. Read the association file. A hardcoded endpoint is inventory until a second account receives another user's object.
Parsers, archives, and fail-open
The server opens a file, an archive, or a document the user supplied.
Ask: Does the parser trust a path, a type, or an error state the caller controls?
Stop: You can show the boundary that was crossed, or you can show the error path failed closed.
Playbooks: archive-parser-boundaries, exception-fail-open
Checklists: parser-check, exception-path-check
Hunts: parser
Disclosures: nasa-cmr-zip-slip-file-write
Tell the agent: Load the vulns.co skill parser. Describe the boundary. Do not include an archive entry that writes outside the destination.
Write the report
The minimum proof is already in hand.
Ask: What did I show, what did I infer, and what should the program change?
Stop: The draft names the boundary, the evidence, the source-reported impact, and the fix, and it leaves out payloads and other people's data.
Playbooks: report-writing
Checklists: report-quality
Tell the agent: Load the vulns.co skill report. Use build_evidence_plan before drafting. Quote severity from the source. Do not predict a payout.
Cloud object storage
A bucket, a blob store, or a server-side fetch is in scope.
Ask: Is this object store theirs, and has a callback already shown a server-side fetch before any metadata hop?
Stop: You can attribute the store, or you can say the next hop was not allowed. A marketing file is written down as not a finding.
Playbooks: cloud-storage-misconfig, cloud-metadata-boundary
Checklists: cloud-check
Hunts: cloud
Tell the agent: Load the vulns.co skill cloud. Attribute the bucket before you call it theirs. A marketing file is not a finding. Metadata stays off the request until a callback you control already proved a server-side fetch, and the program allows that next check.
Provisioning and invites
The app creates users through SCIM, directory sync, or invites.
Ask: Can a token I hold create a user or change a role in an org I belong to, when that route should refuse me?
Stop: Two orgs you belong to are named, and one write is either refused or stored. No user was created in a third org.
Playbooks: scim-invite-provision
Hunts: provision
Tell the agent: Load the vulns.co skill provision. Use two orgs you belong to. An invite token is a lead until it changes a role you do not hold.
Billing and credits
A price, credit, refund, coupon, or quantity is stored by the server.
Ask: Which amount did the server store, and does that ledger state match the rule the product claims?
Stop: One object you own shows the client amount and the stored amount. A shared balance was not drained.
Playbooks: money-movement
Hunts: billing
Disclosures: upserve-negative-quantity
Tell the agent: Load the vulns.co skill billing. The price that counts is the one the server stores. The Upserve card is a charged total that no longer matched the order. Do not drain a shared balance.