skills/pfp/SKILL.md
Route profile-picture, avatar, and image-profile workflows into focused upload, SSRF, XSS, IDOR, WAF, race, and storage testing lanes.
npx skillsauth add ghostonbutterbread/bug-bounty-harness pfpInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use for profile-picture, avatar, profile-image, account-photo, and image URL import workflows.
/pfp is a coordinator skill. It maps the profile-picture workflow, creates a queue of focused child lanes, and runs those child agents one at a time through a shared browser/live-testing slot. Child lanes should test bounded mutation families and return evidence, not just decide from the parent scout that a branch is impossible.
/pfp <program> [goal/context]
/pfp <program> --no-ledger [goal/context]
/pfp canva profile-picture
/pfp superdrug avatar-upload
$HARNESS_ROOT/prompts/pfp-playbook.md.$HARNESS_ROOT/prompts/pfp-context-pack.md to load the focused branch map and local-note sources.$HARNESS_ROOT/prompts/pfp-research-terms.md only when a branch needs expansion.--no-ledger, do not read prior findings or write durable ledger/coverage state./ssrf/xss/idor/waf/raceWrite notes under $HARNESS_SHARED_BASE/{program}/ghost/pfp/.
Record:
testing
Route account takeover testing across password reset, recovery, SSO/OAuth, account linking, MFA, email change, session, invite, and identity-binding flows.
testing
Use when importing, indexing, filtering, queueing, checking, or marking recon URLs in the SQLite-backed per-lane URL review tracker.
testing
Route checkout, billing, subscriptions, coupons, credits, gift cards, invoices, refunds, payment authorization, and paid-entitlement testing into safe zero-dollar-first workflows.
data-ai
Launch scoped browsers through the correct Caido proxy, enable live intercept or Tamper one lane at a time, modify selected requests, forward them, then disable intercept.