Install
$ agentstack add skill-sekolah76-syadagentic-bug-bounty-disclosure ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Bug Bounty & Coordinated Disclosure
Skill buat ngerapihin seluruh alur dari temuan → verifikasi → cari kontak → lapor ke dev via email → koordinasi fix. Serba-guna: crypto & non-crypto, target dengan program resmi maupun tanpa program. Fokusnya bikin laporan yang valid, reproducible, dan diterima dev — bukan AI-slop yang di-ignore.
⚠️ Dasar good-faith (baca dulu, singkat)
Skill ini buat good-faith security research + coordinated disclosure. Lapor kerentanan ke pemilik projek itu sah & etis entah mereka punya program resmi atau enggak — justru itu tujuannya.
Yang harus dijaga: dasar pengetesan harus sah. Bug ditemukan lewat cara legit:
- Sistem/infra milik sendiri, akun sendiri, atau testnet.
- Review kode open-source / artefak publik (repo, package, image).
- Analisis smart contract on-chain (bytecode/source publik).
- Target yang punya program bug bounty / VDP /
security.txtyang mengundang laporan. - Ada izin tertulis dari owner.
Jangan pakai skill ini buat membenarkan intrusi tanpa izin ke sistem produksi pihak ketiga (mancing kredensial, nembus akses yang bukan hak lo, lanjut nge-drill setelah dapat akses). Kalau ragu apakah suatu langkah pengetesan sah: stop, jangan eskalasi akses, laporkan hanya yang lo temukan lewat cara legit. Untuk bug crypto yang dananya live & exploitable: jangan exploit, jangan publikasikan dulu — disclosure privat ke tim adalah langkah yang benar.
Prinsip inti
Sebuah temuan layak dikirim ke dev kalau: (1) valid & reproducible dengan PoC, (2) impact-nya nyata, (3) dikirim ke pihak yang benar lewat kanal yang tepat, dengan (4) nada good-faith, tanpa ancaman/ransom.
Alur pakai skill
- Jalanin
workflow.md— pipeline 6 fase: Triase → Verifikasi/PoC → Impact → Cari Kontak → Kirim Email → Koordinasi & Follow-up. - Fase Cari Kontak → buka
references/contact-discovery.md(metode nyari dev/owner, crypto & non-crypto, + verifikasi pihak & enkripsi). - Fase Kirim Email → buka
references/report-templates.md(template email disclosure + laporan teknis, ID/EN). - Butuh klasifikasi bug (fase Triase/Impact) →
references/vuln-classes.md(recognition cepat: web/API/infra/cloud, smart contract/web3, agent/LLM info-flow).
Aturan anti-slop (non-negotiable)
- No PoC, no report. Tiap klaim reproducible dengan bukti (log/screenshot/tx hash).
- Impact ditunjukin, bukan diklaim. Demokan minimal & non-destruktif; jangan bikin kerusakan buat "ngebuktiin".
- Ulang ≥3×, isolasi variabel, minimize payload/PoC.
- Ga bisa reproduce → buang. Jangan overclaim severity, jangan filler.
- Satu report = satu bug yang jelas. Jangan gabung 10 "temuan" variasi teks.
- Kirim ke pihak & kanal yang benar. Verifikasi dulu, pakai kanal security khusus, enkripsi detail sensitif.
Output
Deliverable: temuan tervalidasi → kontak dev/owner terverifikasi → email disclosure + laporan teknis (bahasa ngikutin target, ID/EN, nada natural & teknis) → catatan koordinasi/timeline.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Sekolah76
- Source: Sekolah76/syadagentic
- License: MIT
- Homepage: https://github.com/Sekolah76/syadagentic
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.