AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Bug Bounty Disclosure

skill-sekolah76-syadagentic-bug-bounty-disclosure · by Sekolah76

Skill end-to-end buat authorized/good-faith bug bounty & coordinated vulnerability disclosure ke developer atau pemilik projek — untuk SEMUA jenis bug (web, API, infra, mobile, cloud, smart contract/web3, agent/LLM), crypto maupun non-crypto. Pakai skill ini setiap kali user mau triase & verifikasi temuan, bikin PoC, NYARI kontak dev/owner (security.txt, SECURITY.md, GitHub, WHOIS, on-chain, sosm…

— No reviews yet
0 installs
0 views
— view→install

Install

$ agentstack add skill-sekolah76-syadagentic-bug-bounty-disclosure

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-sekolah76-syadagentic-bug-bounty-disclosure)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Bug Bounty Disclosure? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Bug Bounty & Coordinated Disclosure

Skill buat ngerapihin seluruh alur dari temuan → verifikasi → cari kontak → lapor ke dev via email → koordinasi fix. Serba-guna: crypto & non-crypto, target dengan program resmi maupun tanpa program. Fokusnya bikin laporan yang valid, reproducible, dan diterima dev — bukan AI-slop yang di-ignore.

⚠️ Dasar good-faith (baca dulu, singkat)

Skill ini buat good-faith security research + coordinated disclosure. Lapor kerentanan ke pemilik projek itu sah & etis entah mereka punya program resmi atau enggak — justru itu tujuannya.

Yang harus dijaga: dasar pengetesan harus sah. Bug ditemukan lewat cara legit:

  • Sistem/infra milik sendiri, akun sendiri, atau testnet.
  • Review kode open-source / artefak publik (repo, package, image).
  • Analisis smart contract on-chain (bytecode/source publik).
  • Target yang punya program bug bounty / VDP / security.txt yang mengundang laporan.
  • Ada izin tertulis dari owner.

Jangan pakai skill ini buat membenarkan intrusi tanpa izin ke sistem produksi pihak ketiga (mancing kredensial, nembus akses yang bukan hak lo, lanjut nge-drill setelah dapat akses). Kalau ragu apakah suatu langkah pengetesan sah: stop, jangan eskalasi akses, laporkan hanya yang lo temukan lewat cara legit. Untuk bug crypto yang dananya live & exploitable: jangan exploit, jangan publikasikan dulu — disclosure privat ke tim adalah langkah yang benar.

Prinsip inti

Sebuah temuan layak dikirim ke dev kalau: (1) valid & reproducible dengan PoC, (2) impact-nya nyata, (3) dikirim ke pihak yang benar lewat kanal yang tepat, dengan (4) nada good-faith, tanpa ancaman/ransom.

Alur pakai skill

  1. Jalanin workflow.md — pipeline 6 fase: Triase → Verifikasi/PoC → Impact → Cari Kontak → Kirim Email → Koordinasi & Follow-up.
  2. Fase Cari Kontak → buka references/contact-discovery.md (metode nyari dev/owner, crypto & non-crypto, + verifikasi pihak & enkripsi).
  3. Fase Kirim Email → buka references/report-templates.md (template email disclosure + laporan teknis, ID/EN).
  4. Butuh klasifikasi bug (fase Triase/Impact) → references/vuln-classes.md (recognition cepat: web/API/infra/cloud, smart contract/web3, agent/LLM info-flow).

Aturan anti-slop (non-negotiable)

  1. No PoC, no report. Tiap klaim reproducible dengan bukti (log/screenshot/tx hash).
  2. Impact ditunjukin, bukan diklaim. Demokan minimal & non-destruktif; jangan bikin kerusakan buat "ngebuktiin".
  3. Ulang ≥3×, isolasi variabel, minimize payload/PoC.
  4. Ga bisa reproduce → buang. Jangan overclaim severity, jangan filler.
  5. Satu report = satu bug yang jelas. Jangan gabung 10 "temuan" variasi teks.
  6. Kirim ke pihak & kanal yang benar. Verifikasi dulu, pakai kanal security khusus, enkripsi detail sensitif.

Output

Deliverable: temuan tervalidasi → kontak dev/owner terverifikasi → email disclosure + laporan teknis (bahasa ngikutin target, ID/EN, nada natural & teknis) → catatan koordinasi/timeline.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.