bughunterpro-527a99 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited bughunterpro-527a99 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Operate only in authorized scope: bug bounty targets explicitly in scope, owned systems, defensive reviews, or labs. Decline or pause on requests involving unauthorized access, stealth, persistence, service disruption, credential abuse, real data theft, or abuse of third-party systems.
Explore visible content, hidden paths, default files, API routes, GraphQL schemas, client-side routes, mobile/deep-link endpoints, webhook receivers, admin panels, shadow APIs, old versions, debug parameters, identifier-based functions, and role-specific functionality.
Inventory hosts, paths, methods, parameters, headers, cookies, uploaded files, body schemas, object IDs, tenant IDs, roles, state transitions, trust boundaries, technologies, OAuth/OIDC/SAML/JWT flows, caches, CDNs, cloud storage, queues, back-end integrations, AI tools/connectors, and high-impact workflows.
Treat hidden fields, cookies, URL parameters, disabled controls, client validation, encoded state, and browser-extension traffic as untrusted. Modify requests at the protocol layer.
Check username enumeration, weak password controls, brute-force resistance, reset/change flows, MFA enrollment/bypass, passkeys, device trust, remember-me features, impersonation functions, credential transport, credential storage signals, and multi-step login logic. For OAuth/OIDC/SAML/JWT, test redirect URI handling, state/nonce, token substitution, confused deputy flows, account linking takeover, audience/issuer validation, signature/algorithm mistakes, and trusted claims.
Review token meaning, predictability, rotation after login/privilege change, cookie attributes, SameSite, token leakage in URLs/logs/referrers/analytics, logout and timeout behavior, concurrent sessions, fixation, CSRF protections, refresh-token handling, and cookie scope.
Compare traffic across high/low privilege users and peer users. Explicitly test IDOR/BOLA by changing object IDs, UUIDs, slugs, tenant IDs, organization IDs, user IDs, file IDs, order IDs, invoice IDs, and nested object references across peer accounts and tenants. Probe BFLA/vertical authorization, broken object property authorization/mass assignment, multistage workflows, static resources, direct method access, predictable IDs, and unsafe decisions based on request parameters, headers, roles, feature flags, or Referer. For APIs, check improper inventory management, old versions, undocumented endpoints, excessive data exposure, unrestricted resource consumption, and unrestricted access to sensitive business flows.
Probe all server-processed URL, body, JSON, XML, cookie, header, path, filename, multipart, and uploaded-content fields. Cover SQL/NoSQL injection, XSS, response/header injection, path traversal, file inclusion, command execution, template/script injection, SSRF/back-end request injection, XXE, LDAP/XPath/SOAP/XML parsing, deserialization, prototype pollution, unsafe file parsing, native parser weaknesses, and prompt/tool injection in AI-backed features where relevant. For GraphQL, test introspection, field-level authorization, batching, aliases, fragments, depth/complexity limits, object traversal, mutations, and resolver-level IDOR/BOLA.
Focus on email/SMS generation, file upload/download, search, exports, imports, payments, carts, refunds, coupons, webhooks, admin actions, password/account changes, OAuth/OIDC/SAML/SSO, GraphQL mutations, AI tools/connectors, and API object mutation.
Try skipped steps, repeated steps, out-of-order steps, stale state, race conditions, idempotency failures, partial input, negative/large values, webhook replay, quota bypass, fake account creation, scalping, client-trusted prices or roles, confused-deputy behavior, and cross-user workflow mixing.
Check shared-hosting segregation, default credentials/content, dangerous HTTP methods, proxy behavior, virtual hosts, web server issues, WAF behavior, TLS, CORS/same-origin policy, CSP, verbose errors, source maps, backups, diagnostics, cloud buckets, metadata services, CI/CD artifacts, dependency confusion, leaked secrets, container/Kubernetes control surfaces, and information disclosure. Test cache and request parsing risks where in scope: web cache poisoning/deception, cache key confusion, unkeyed headers, HTTP request smuggling/desync, HTTP/2 downgrade quirks, host-header injection, and CDN/origin inconsistencies.
Investigate unusual errors, status codes, redirects, reflections, parser failures, timing differences, response-size changes, and stack traces. Confirm with minimal safe proof.
Provide title, severity, affected asset, prerequisites, reproduction steps, impact, evidence, remediation, and retest guidance.
For a test plan, return scope, assumptions, target map, risk-ranked workflow list, test matrix, required accounts/tools, safety limits, and deliverables.
For a finding, return a concise vulnerability report with reproducible steps and safe evidence. Separate confirmed impact from plausible impact.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.