# mdpsec/bug-bounty-hunting-prompts > A pack of reusable prompts for a structured bug bounty hunting workflow, covering phases from recon and authenticated access to triage, validation, and escalation of findings. Requires adapting to your own tools and infrastructure. - Magnitude: 5.0 out of 10 — Early signal - Stars: 70 total · +61 stars today, ≈ 95 by evening - Star trust: star growth looks organic - Category: Security · License: MIT · Created: 2026-09-30 · Last push: 2026-10-03 - GitHub: https://github.com/mdpsec/bug-bounty-hunting-prompts · Homepage: https://mdpsec.com · Page: https://gitnova.dev/en/r/mdpsec/bug-bounty-hunting-prompts ## Useful for - Assemble a step-by-step bug bounty workflow for your agent - Run attack surface recon and a broad endpoint sweep - Set up triage, deduplication, and independent validation of findings ## Why it’s here - 61 stars so far today, about 95 expected by the end of the day. - The spike has held for 2 days in a row — not a one-off blip. - The repository is 3 days old and already has 70 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - Top new repositories this week: #171. - About 103 forks a day — people are taking the code. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 24 - Issues and pull requests: 0 - Watchers: 0 - Average over the last week: 27 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 8 ## Stars per day, last 7 days (oldest → newest, today is partial) 2026-09-27 … 2026-10-03: 0, 0, 0, 0, 0, 11, 61 ## Spotted in now - Top new repositories this week: #171 ## More in this category 1. **OffGridPete/Fieldwatch** — 6.9 · Breakout · Security · Kotlin · +66 stars today, ≈ 241 by evening Receive-only Wi-Fi and Bluetooth LE observer for Android: passive scanning of nearby access points and BLE advertisements with filters, signatures and reports, no backend or account. Full card: https://gitnova.dev/en/r/OffGridPete/Fieldwatch.md 2. **HunxByts/GhostTrack** — 5.2 · Breakout · Security · Python · +18 stars today, ≈ 84 by evening Python OSINT tool for information gathering: tracking IP addresses, phone numbers and usernames on social media. Full card: https://gitnova.dev/en/r/HunxByts/GhostTrack.md 3. **ntfargo/Relapse-Exploit** — 4.9 · Peaking · Security · JavaScript · +13 stars today, ≈ 45 by evening Exploit chain for PS5 firmware 7.00–13.60: a WebKit/JSC browser stage and a kernel stage that achieves kernel read/write. Aimed at security researchers and console owners studying PS5 vulnerabilities. Full card: https://gitnova.dev/en/r/ntfargo/Relapse-Exploit.md 4. **usestrix/strix** — 3.6 · Steady · Security · Python · +32 stars today, ≈ 117 by evening Open-source AI pentesting tool: autonomous agents run your code, find vulnerabilities, and validate them with working PoCs. For developers and security teams needing fast testing without manual pentests or static-analysis false positives. Full card: https://gitnova.dev/en/r/usestrix/strix.md 5. **Soulringen/aegis-claude** — 3.5 · Early signal · Security · PowerShell · +0 stars today, ≈ 15 by evening A PowerShell script for Windows (plus a macOS counterpart) that wipes the local identifiers Claude Desktop and Claude Code keep on disk — machineID, userID, ant-did, cookies, and saved login — so the next launch registers as a new device.… Full card: https://gitnova.dev/en/r/Soulringen/aegis-claude.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-03 11:38 UTC, updated every 30 minutes.