Target selection & prioritisation
SkillAI & modelsChoose where to spend effort for the best return, which program, which asset, which surface. Load at the start of bug-bounty work or when a scope is broad and time is limited, on "which program", "where should I hunt", "prioritize these targets". Signals: a big scope list, many in-scope domains, a new program, limited time.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Target selection & prioritisation skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/tradecraft/tradecraft-target-selection/SKILL.md and read by ahel’s review.
When it applies
You have more scope than time. Whether picking a bug-bounty program or ordering assets inside one authorized engagement, the choice of where to look usually matters more than how hard you look.
Why it works
Vulnerabilities cluster where code is new, complex, or neglected, and payout/impact clusters where the asset is important. Spending your first hours choosing well beats grinding a hardened, picked-over target — most reports come from a minority of assets.
Method
- Size the attack surface: prefer programs/assets with lots of subdomains, APIs, and functionality over a single static site — more surface, more bugs.
- Favour freshness: newly added scope, a recent acquisition, a just-launched feature, or a product the crowd hasn't saturated. Watch changelogs and scope-change feeds.
- Match your strengths: pick tech you know (a stack, a language, a vuln class) — depth compounds.
- Weigh the economics (bounty): payout table, response/triage speed, resolution rate, and how crowded the program is. A fast, fair program at medium bounty often beats a slow flagship.
- Prioritise assets inside scope: rank by likely impact (auth, payments, admin, PII) × likely softness (obscure subdomain, legacy app, thin JS) and start at the top.
- Timebox and re-evaluate: if an asset yields nothing after a set budget, rotate — don't sink.
Gotchas
- Big brand ≠ easy: flagship domains are the most hunted. The soft spots are usually the
forgotten subdomains and new features, not
www. - Confirm the asset is actually in scope before investing (load
tradecraft-scope-roe). - Don't chase payout alone — a program that never triages wastes more time than a lower bounty.
Verify success
You can state, in one line each, why you picked this program/asset and what the highest-value surface is — and you're working that surface, not a random one.
References
Bug-bounty program statistics/leaderboards; disclosed-report patterns; the tradecraft-attack-scenarios skill.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
tradecraft-target-selection- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptanalyzing-ethereum-smart-contract-vulnerabilities
Skill · mukul975
The pick for Vulnerabilitiescode-quality-analyzer
Skill · alibaba
The pick for Vulnerabilitiesskill-creator
Skill · anthropics
More in AI & modelswayfinder
Skill · mattpocock
More in AI & models