cyberneticlibrary

Redact evidence for bug bounty submissions

evidence-hygieneskillsetup L11,791
elementalsouls/Claude-BugHunter
What it does

Redact session cookies and PII from PoC evidence without losing triager metadata

Best for

Bug-bounty submissions when cookie leakage and unauthorized PII exposure risks matter.

Inputs
  • · screenshot/HAR/console transcript
  • · cookie names to mask
  • · PII fields in cross-account payload
Outputs
  • · redacted artifact with review-safe metadata visible
  • · redaction checklist
  • · post-submission credential rotation
Requires
  • · jq for HAR sanitization
  • · DevTools console capture
  • · Burp panel hiding
Preconditions

PoC captures cookies or other-user data

Failure modes

Redacting triager-useful trace IDs; leaving session cookies unmasked

Trust signals
  • · Cookie/PII categorization table (mask vs leave visible)
  • · Burp-specific screenshot hygiene (hide request body, show Results table)