← all repositories
mdpsec/bug-bounty-hunting-prompts

A bug bounty workflow, minus the workflow's engine

A hunter open-sources the LLM prompt chain behind an evidence-first bounty process — but leaves the infrastructure as an exercise for you.

Collecting fresh signals — velocity needs a few days of history.
collecting data…
star history

What it does

This is a pack of 15 prompt files that walk an AI agent through a structured web bug bounty hunt: recon, authenticated access, a broad vulnerability sweep, critical-impact hunting, then triage, validation, and duplicate checking. Each phase is a separate markdown file, and the sequence is designed so the agent hands off evidence artifacts between phases rather than freestyle-hunting its way to hallucinated findings.

The interesting bit

The author is explicit that this is half a system. The prompts were extracted from a private workflow that ran on a browser fleet, proxy, PoC runtime, and RAG corpus — none of which are included. Every private integration is a YOUR_* variable catalogued in ADAPTATION.md, so the repo is less a tool and more a blueprint of how to decompose bounty hunting into phases an agent can actually execute.

Key highlights

  • Full phase sequence from phase-00-recon.md through phase-10-self-duplicate-check.md, with optional browser-walk and critical-hunt branches.
  • Evidence-first design: phases pass artifacts to each other, with independent verification and triage gates before escalation.
  • Modular — an unauthenticated workflow can drop account setup, email, and browser phases while keeping recon, sweep, and triage.
  • Strong safety framing: authorized targets only, bounded non-destructive proofs, no bulk collection, secrets kept out of the repo.

Caveats

  • Explicitly not runnable as-is — the prompts reference private helpers and infrastructure that will not be provided, and maintainers offer no setup or debugging support.
  • Two branches from the original workflow (a second critical pass and second escalation pass) were omitted from the public release.

Verdict

Worth a look if you’re building your own agent-driven hunting pipeline and want a mature phase decomposition to steal ideas from. Skip it if you expected a turnkey bounty bot — this is the map, not the vehicle.

Frequently asked

What is mdpsec/bug-bounty-hunting-prompts?
A hunter open-sources the LLM prompt chain behind an evidence-first bounty process — but leaves the infrastructure as an exercise for you.
Is bug-bounty-hunting-prompts open source?
Yes — mdpsec/bug-bounty-hunting-prompts is open source, released under the MIT license.
How popular is bug-bounty-hunting-prompts?
mdpsec/bug-bounty-hunting-prompts has 500 stars on GitHub.
Where can I find bug-bounty-hunting-prompts?
mdpsec/bug-bounty-hunting-prompts is on GitHub at https://github.com/mdpsec/bug-bounty-hunting-prompts.

heatdrop uses Google Analytics to see which pages get read — nothing else. Your call. How we handle data.