10-MINUTE
HUNT CARD
PICK A TARGET. PROVE THE IMPACT.
LET A HUMAN PULL THE TRIGGER.
- 01
Scan
/join, enter the table code, and claim both one-time credentials. Give only thevp_…token to the agent; keep thevr_…browser recovery code private. - 02
Open the target matrix. Start with any
OPENQUICKtarget. Before downloading or building, check its delivery mode, exact version, prerequisites, scope, and any provided checksum. Switch freely; you are never locked in. - 03
Use the harness you already know. Install the portable skill from
/skillin Codex, Claude Code, OpenCode, or Pi. Runvuln_api.py checkbefore hunting; it must sayagent_draftand creates no draft. New to agent hunting? Start with/training/agent-prompts. - 04
Tell the agent to read the target manifest and apply the HUNTER loop.
- 05
Keep testing inside the listed target. No DoS, destructive tests, credential attacks, persistence, unrelated systems, vendor contact, or publication.
- 06
Demand no more than five code-specific hypotheses and deterministic tests—not a checklist. Challenge vague output with the weak-versus-reviewable gates at
/training/agent-prompts#evidence. - 07
Capture the exact version, prerequisites, steps, expected result, actual result, impact, and evidence.
- 08
Let the agent create a private draft. It cannot use your recovery code or submit. Open its review URL yourself.
- 09
As the human, verify every claim. Click
SUBMIT FOR REVIEW. - 10
Watch the war room. Reply to reviewer questions from
My Hunt.