# Mikacr1138

> Open-source publisher. Listings imported from github.com/Mikacr1138 — credited to the original author with their license.

- **Listings:** 7
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/mikacr1138
- **Website:** https://github.com/Mikacr1138

## Published listings

- [Report Writing](https://agentstack.voostack.com/l/skill-mikacr1138-claude-bug-bounty-report-writing) — Skill · Free · security-reviewed — `agentstack add skill-mikacr1138-claude-bug-bounty-report-writing`
  Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.
- [Security Arsenal](https://agentstack.voostack.com/l/skill-mikacr1138-claude-bug-bounty-security-arsenal) — Skill · Free — `agentstack add skill-mikacr1138-claude-bug-bounty-security-arsenal`
  Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/IDOR/path-traversal, bypass techniques, or to check if a finding is submittable. Also use when asked about what NOT to submit.
- [Web2 Vuln Classes](https://agentstack.voostack.com/l/skill-mikacr1138-claude-bug-bounty-web2-vuln-classes) — Skill · Free — `agentstack add skill-mikacr1138-claude-bug-bounty-web2-vuln-classes`
  Complete reference for 18 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic, race conditions, OAuth/OIDC, file upload (10 bypass techniques), GraphQL, LLM/AI (ASI01-ASI10 agentic framework), API misconfig, ATO taxonomy, SSTI, subdomain takeover, cloud…
- [Web2 Recon](https://agentstack.voostack.com/l/skill-mikacr1138-claude-bug-bounty-web2-recon) — Skill · Free · security-reviewed — `agentstack add skill-mikacr1138-claude-bug-bounty-web2-recon`
  Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch). Use when starting recon on any web2 target or when asked about asset discovery, subdomai…
- [Web3 Audit](https://agentstack.voostack.com/l/skill-mikacr1138-claude-bug-bounty-web3-audit) — Skill · Free · security-reviewed — `agentstack add skill-mikacr1138-claude-bug-bounty-web3-audit`
  Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for any Solidity/Rust contract audit or when deciding whether a DeFi target is worth…
- [Triage Validation](https://agentstack.voostack.com/l/skill-mikacr1138-claude-bug-bounty-triage-validation) — Skill · Free · security-reviewed — `agentstack add skill-mikacr1138-claude-bug-bounty-triage-validation`
  Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio.
- [Bug Bounty](https://agentstack.voostack.com/l/skill-mikacr1138-claude-bug-bounty-claude-bug-bounty) — Skill · Free — `agentstack add skill-mikacr1138-claude-bug-bounty-claude-bug-bounty`
  Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-cha…

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
