A bug bounty workflow, minus the workflow's engine
A hunter open-sources the LLM prompt chain behind an evidence-first bounty process — but leaves the infrastructure as an exercise for you.
What it does
This is a pack of 15 prompt files that walk an AI agent through a structured web bug bounty hunt: recon, authenticated access, a broad vulnerability sweep, critical-impact hunting, then triage, validation, and duplicate checking. Each phase is a separate markdown file, and the sequence is designed so the agent hands off evidence artifacts between phases rather than freestyle-hunting its way to hallucinated findings.
The interesting bit
The author is explicit that this is half a system. The prompts were extracted from a private workflow that ran on a browser fleet, proxy, PoC runtime, and RAG corpus — none of which are included. Every private integration is a YOUR_* variable catalogued in ADAPTATION.md, so the repo is less a tool and more a blueprint of how to decompose bounty hunting into phases an agent can actually execute.
Key highlights
- Full phase sequence from
phase-00-recon.mdthroughphase-10-self-duplicate-check.md, with optional browser-walk and critical-hunt branches. - Evidence-first design: phases pass artifacts to each other, with independent verification and triage gates before escalation.
- Modular — an unauthenticated workflow can drop account setup, email, and browser phases while keeping recon, sweep, and triage.
- Strong safety framing: authorized targets only, bounded non-destructive proofs, no bulk collection, secrets kept out of the repo.
Caveats
- Explicitly not runnable as-is — the prompts reference private helpers and infrastructure that will not be provided, and maintainers offer no setup or debugging support.
- Two branches from the original workflow (a second critical pass and second escalation pass) were omitted from the public release.
Verdict
Worth a look if you’re building your own agent-driven hunting pipeline and want a mature phase decomposition to steal ideas from. Skip it if you expected a turnkey bounty bot — this is the map, not the vehicle.
Frequently asked
- What is mdpsec/bug-bounty-hunting-prompts?
- A hunter open-sources the LLM prompt chain behind an evidence-first bounty process — but leaves the infrastructure as an exercise for you.
- Is bug-bounty-hunting-prompts open source?
- Yes — mdpsec/bug-bounty-hunting-prompts is open source, released under the MIT license.
- How popular is bug-bounty-hunting-prompts?
- mdpsec/bug-bounty-hunting-prompts has 500 stars on GitHub.
- Where can I find bug-bounty-hunting-prompts?
- mdpsec/bug-bounty-hunting-prompts is on GitHub at https://github.com/mdpsec/bug-bounty-hunting-prompts.