vulns.co
/
GKData.io MCP

Bug bounty skills for agents

Product revision 2026.09. 15 stack skills. Load one as an MCP prompt by its slug, or call get_skill for the linked playbooks, checklists, and disclosure cards.

Install the hosted MCP, then call list_skills or get_skill with the slug. Browser utilities named on a skill stay in the browser. Paste tools named under local MCP stay on the local connector.

Scope and intake

A program is in front of you and nothing is mapped yet.

Ask: Which hosts are in scope, which two accounts do I own, and what will I refuse to read?

Stop: The in-scope hosts, the accounts, and one out-of-scope object are written down.

Playbooks: scope-and-intake

Checklists: first-hour

Tell the agent: Load the vulns.co skill intake with get_skill. Do not propose requests until scope, two owned accounts, and one object you will not read are named.

Access control and tenant boundaries

The app has users, orgs, or object ids.

Ask: Can account A read or change an object that belongs to account B, including a job, export, or leftover endpoint?

Stop: One object you own is denied to the other account, and one object you should not own is not returned.

Playbooks: idor-hunting, tenant-isolation, export-webhook-authz, mass-assignment-play

Checklists: authz, tenant-check, export-webhook-check

Hunts: idor, tenant, webhook, assignment

Disclosures: bykea-zombie-endpoint-idor, hackerone-graphql-tag-idor

Tell the agent: Load the vulns.co skill access-control. Ask for the checklist before a request. Compare two saved responses locally. Do not call a missing id a finding until the other account's object comes back.

Session, cookies, and passkeys

Login, recovery, or cookies are in scope.

Ask: Which cookie or token does the server trust, and can recovery issue a session the primary login would not?

Stop: You can name the cookie or token, the recovery path, and whether a second browser still holds a session after logout.

Playbooks: account-takeover, passkey-webauthn, cookie-session-binding, two-factor-bypass, jwt-attacks, reset-token-binding

Checklists: authn-ato, passkey-check, session-cookie-check, jwt-check

Hunts: session, passkey, 2fa, jwt, reset

Disclosures: nextcloud-webauthn-public-key

Tell the agent: Load the vulns.co skill session. Record the browser and the cookie setting you observed. Do not claim third-party cookies are gone.

OAuth, DPoP, and mix-up

The target has an authorization server or signs in with one.

Ask: Is the authorization code bound to this client, and can the token be replayed without the proof the server claimed to require?

Stop: You have the authorization response fields you observed, including whether iss is checked, and you have not reused a code.

Playbooks: oauth-dpop-mixup, oauth-attacks

Checklists: oauth-modern-check

Hunts: oauth

Disclosures: pixiv-oauth-redirect-code

Tell the agent: Load the vulns.co skill oauth. Treat oauth-attacks and oauth-dpop-mixup as one path: mix-up and downgrade first, older redirect bugs second. The pixiv card shows a redirect that left the registered callback. Do not replay its redirect.

GraphQL APIs

A GraphQL endpoint or a persisted-query client is in the app.

Ask: Does the operation name or the persisted query id skip the authorization check the HTTP route was supposed to enforce?

Stop: One allowed operation and one denied operation are saved, and suggestions or introspection are labeled as inventory.

Playbooks: graphql-abuse, graphql-persisted-queries

Checklists: graphql-check

Hunts: graphql

Disclosures: hackerone-graphql-tag-idor

Tell the agent: Load the vulns.co skill graphql. Fingerprint only. A suggestion or an open introspection result is not the finding. The finding is an operation that acts on an object the caller does not own.

JavaScript and client trust

The app ships a bundle, a source map, or a message listener.

Ask: Which source reaches which sink, and which of those sinks is behind an origin check?

Stop: You have line numbers for the listener or sink, and you have not claimed execution from a pattern match.

Playbooks: javascript-analysis, js-spa-hunting, postmessage-dom

Checklists: js-review

Hunts: xss, postmessage

Disclosures: nasa-globe-upload-stored-xss

Tell the agent: Load the vulns.co skill javascript. Analyze saved source locally. Report line numbers and the missing check. Do not paste a payload into the hosted MCP.

Cache deception and cache poisoning

A response might be stored and later reused.

Ask: Is a private response stored at a URL the cache treats as static, or does an unkeyed input change what other users receive?

Stop: You can say which of the two bugs you observed. Do not file one as the other.

Playbooks: cache-deception, web-cache-poisoning

Checklists: cache-deception-check, cache-check

Hunts: cache-deception, cache

Disclosures: algolia-web-cache-deception, paypal-smuggled-cached-response

Tell the agent: Load the vulns.co skill cache. web-cache-poisoning is poisoning only. cache-deception is deception only. The Algolia card is deception. The PayPal card is smuggling that stored a cached response. Report them separately.

Agents, MCP, and retrieval

A feature calls tools, retrieves documents, or connects an MCP server.

Ask: Is the tool token wider than the tool, or did retrieval return another tenant's text into a context I am allowed to see?

Stop: You can show the token audience or the retrieved chunk boundary. A confused answer with no authority behind it is not the report.

Playbooks: mcp-tool-trust, rag-document-trust

Checklists: mcp-agent-check, rag-check

Hunts: mcp, rag, llm

Disclosures: cloudflare-playground-mcp-xss

Tell the agent: Load the vulns.co skill ai-agent. Use mcp-tool-trust or rag-document-trust for the test. ai-llm-testing only classifies the surface. A prompt that only confuses the model is not the report. The Cloudflare card is a session that could act on a connected MCP server. Quote the low score the program disclosed.

CI and dependency trust

Workflows, packages, or update channels are in scope.

Ask: Does a pull request workflow run untrusted code with the base repository's secrets, or does a package name resolve to an owner the build did not pin?

Stop: You have the workflow trigger and the permission it has, or the package coordinate and who published it. Do not run a hostile install.

Playbooks: github-actions-trust, dependency-confusion, cicd-secret-recon

Checklists: supply-chain-check

Hunts: supply-chain

Disclosures: xz-utils-upstream-backdoor

Tell the agent: Load the vulns.co skill supply-chain. Read the workflow file you already have. Do not print a workflow exploit.

Mobile links and API hosts

An app claims links or ships an API host in the binary.

Ask: Which hosts does the app trust for links, and does the API check the same object ownership as the UI?

Stop: You have the association file or the claimed hosts, and one API call compared across two accounts.

Playbooks: mobile-applinks

Checklists: mobile-link-check

Hunts: mobile

Disclosures: bykea-zombie-endpoint-idor

Tell the agent: Load the vulns.co skill mobile. Read the association file. A hardcoded endpoint is inventory until a second account receives another user's object.

Parsers, archives, and fail-open

The server opens a file, an archive, or a document the user supplied.

Ask: Does the parser trust a path, a type, or an error state the caller controls?

Stop: You can show the boundary that was crossed, or you can show the error path failed closed.

Playbooks: archive-parser-boundaries, exception-fail-open

Checklists: parser-check, exception-path-check

Hunts: parser

Disclosures: nasa-cmr-zip-slip-file-write

Tell the agent: Load the vulns.co skill parser. Describe the boundary. Do not include an archive entry that writes outside the destination.

Write the report

The minimum proof is already in hand.

Ask: What did I show, what did I infer, and what should the program change?

Stop: The draft names the boundary, the evidence, the source-reported impact, and the fix, and it leaves out payloads and other people's data.

Playbooks: report-writing

Checklists: report-quality

Tell the agent: Load the vulns.co skill report. Use build_evidence_plan before drafting. Quote severity from the source. Do not predict a payout.

Cloud object storage

A bucket, a blob store, or a server-side fetch is in scope.

Ask: Is this object store theirs, and has a callback already shown a server-side fetch before any metadata hop?

Stop: You can attribute the store, or you can say the next hop was not allowed. A marketing file is written down as not a finding.

Playbooks: cloud-storage-misconfig, cloud-metadata-boundary

Checklists: cloud-check

Hunts: cloud

Tell the agent: Load the vulns.co skill cloud. Attribute the bucket before you call it theirs. A marketing file is not a finding. Metadata stays off the request until a callback you control already proved a server-side fetch, and the program allows that next check.

Provisioning and invites

The app creates users through SCIM, directory sync, or invites.

Ask: Can a token I hold create a user or change a role in an org I belong to, when that route should refuse me?

Stop: Two orgs you belong to are named, and one write is either refused or stored. No user was created in a third org.

Playbooks: scim-invite-provision

Hunts: provision

Tell the agent: Load the vulns.co skill provision. Use two orgs you belong to. An invite token is a lead until it changes a role you do not hold.

Billing and credits

A price, credit, refund, coupon, or quantity is stored by the server.

Ask: Which amount did the server store, and does that ledger state match the rule the product claims?

Stop: One object you own shows the client amount and the stored amount. A shared balance was not drained.

Playbooks: money-movement

Hunts: billing

Disclosures: upserve-negative-quantity

Tell the agent: Load the vulns.co skill billing. The price that counts is the one the server stores. The Upserve card is a charged total that no longer matched the order. Do not drain a shared balance.

MCP install