This bounty-hunting skill is mostly coherent as GitHub workflow guidance, but it also directs sensitive credential handling, mailbox access, security-tool workarounds, and ungated public write actions.
Review carefully before installing. Use only the read-only bounty search parts unless you explicitly want the agent to act through your GitHub account. Do not allow it to read local credential files, store tokens in /tmp, use a Gmail app password, delete mail, bypass security scanner blocks, or post any session/system context publicly. Require confirmation before any fork, commit, PR, comment, or local note write.