# Bug Bounty Disclosure

> Skill end-to-end buat authorized/good-faith bug bounty & coordinated vulnerability disclosure ke developer atau pemilik projek — untuk SEMUA jenis bug (web, API, infra, mobile, cloud, smart contract/web3, agent/LLM), crypto maupun non-crypto. Pakai skill ini setiap kali user mau triase & verifikasi temuan, bikin PoC, NYARI kontak dev/owner (security.txt, SECURITY.md, GitHub, WHOIS, on-chain, sosm…

- **Type:** Skill
- **Install:** `agentstack add skill-sekolah76-syadagentic-bug-bounty-disclosure`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Sekolah76](https://agentstack.voostack.com/s/sekolah76)
- **Installs:** 0
- **Category:** [Developer Tools](https://agentstack.voostack.com/c/developer-tools)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Sekolah76](https://github.com/Sekolah76)
- **Source:** https://github.com/Sekolah76/syadagentic/tree/main/arsenal-skills/skills-lengkap/bug-bounty/bug-bounty-disclosure
- **Website:** https://github.com/Sekolah76/syadagentic

## Install

```sh
agentstack add skill-sekolah76-syadagentic-bug-bounty-disclosure
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Bug Bounty & Coordinated Disclosure

Skill buat ngerapihin seluruh alur dari **temuan → verifikasi → cari kontak → lapor ke dev via email → koordinasi fix**. Serba-guna: crypto & non-crypto, target dengan program resmi maupun tanpa program. Fokusnya bikin laporan yang **valid, reproducible, dan diterima dev** — bukan AI-slop yang di-ignore.

## ⚠️ Dasar good-faith (baca dulu, singkat)

Skill ini buat **good-faith security research + coordinated disclosure**. Lapor kerentanan ke pemilik projek itu sah & etis **entah mereka punya program resmi atau enggak** — justru itu tujuannya.

Yang harus dijaga: **dasar pengetesan harus sah.** Bug ditemukan lewat cara legit:
- Sistem/infra milik sendiri, akun sendiri, atau testnet.
- Review kode open-source / artefak publik (repo, package, image).
- Analisis smart contract on-chain (bytecode/source publik).
- Target yang punya program bug bounty / VDP / `security.txt` yang mengundang laporan.
- Ada izin tertulis dari owner.

Jangan pakai skill ini buat **membenarkan intrusi tanpa izin** ke sistem produksi pihak ketiga (mancing kredensial, nembus akses yang bukan hak lo, lanjut nge-drill setelah dapat akses). Kalau ragu apakah suatu langkah pengetesan sah: **stop, jangan eskalasi akses**, laporkan hanya yang lo temukan lewat cara legit. Untuk bug crypto yang dananya live & exploitable: **jangan exploit, jangan publikasikan dulu** — disclosure privat ke tim adalah langkah yang benar.

## Prinsip inti

Sebuah temuan layak dikirim ke dev kalau: **(1) valid & reproducible dengan PoC**, **(2) impact-nya nyata**, **(3) dikirim ke pihak yang benar lewat kanal yang tepat**, dengan **(4) nada good-faith, tanpa ancaman/ransom.**

## Alur pakai skill

1. **Jalanin `workflow.md`** — pipeline 6 fase: Triase → Verifikasi/PoC → Impact → Cari Kontak → Kirim Email → Koordinasi & Follow-up.
2. **Fase Cari Kontak** → buka `references/contact-discovery.md` (metode nyari dev/owner, crypto & non-crypto, + verifikasi pihak & enkripsi).
3. **Fase Kirim Email** → buka `references/report-templates.md` (template email disclosure + laporan teknis, ID/EN).
4. **Butuh klasifikasi bug** (fase Triase/Impact) → `references/vuln-classes.md` (recognition cepat: web/API/infra/cloud, smart contract/web3, agent/LLM info-flow).

## Aturan anti-slop (non-negotiable)

1. **No PoC, no report.** Tiap klaim reproducible dengan bukti (log/screenshot/tx hash).
2. **Impact ditunjukin, bukan diklaim.** Demokan minimal & non-destruktif; jangan bikin kerusakan buat "ngebuktiin".
3. **Ulang ≥3×**, isolasi variabel, minimize payload/PoC.
4. **Ga bisa reproduce → buang.** Jangan overclaim severity, jangan filler.
5. **Satu report = satu bug** yang jelas. Jangan gabung 10 "temuan" variasi teks.
6. **Kirim ke pihak & kanal yang benar.** Verifikasi dulu, pakai kanal security khusus, enkripsi detail sensitif.

## Output

Deliverable: temuan tervalidasi → kontak dev/owner terverifikasi → email disclosure + laporan teknis (bahasa ngikutin target, ID/EN, nada natural & teknis) → catatan koordinasi/timeline.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Sekolah76](https://github.com/Sekolah76)
- **Source:** [Sekolah76/syadagentic](https://github.com/Sekolah76/syadagentic)
- **License:** MIT
- **Homepage:** https://github.com/Sekolah76/syadagentic

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-sekolah76-syadagentic-bug-bounty-disclosure
- Seller: https://agentstack.voostack.com/s/sekolah76
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
