Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 166: Rez0’s Top Claude Skill Secrets

March 19, 2026·53 min·3 clips
Alex says the best skills cover large solution spaces and secret knowledge, not everything Claude can already do.
1. Critical Thinking - Bug Bounty Podcast episode 166 focuses on Rez0's Claude skill workflow for bug bounty hacking. 2. Justin and Alex host the discussion, and Rez0 matters because he says he is using Claude to find bugs across multiple programs. 3. The episode asks when a Claude skill adds leverage versus when the model should just be told to do the task. 4. Alex says skills are useful when Claude lacks information about a custom VPS, a private technique, or a program-specific setup. 5. He gives the example of telling Claude where to connect, where to save files, and how to use a user account on a server. 6. He also cites techniques from past Defcon talks and other unpublished bug bounty workflows as material that can be bundled into a skill. 7. Justin raises the opposite concern that too many skills could blunt Claude's flexibility. 8. Alex answers that a one-line Claude MD instruction can tell the model to invoke the skill first and keep exploring if it fails. 9. He compares the steering rule to 'POC or GTFO' and 'try harder,' which he says belong in his own Claude MD. 10. Alex also says poorly written agent files and skills can reduce quality rather than improve it. 11. He recommends building a fallback structure where Claude tries one method, then another, then another if the earlier path fails. 12. He says this kind of layered approach works well in Kaido mode, where the model can use scripts, the client JS library, or GraphQL. 13. Alex says large solution spaces are another good place for skills, such as requests that could be made with curl, Python, Wget, Playwright, or Chrome dev tools. 14. He argues that a skill is especially valuable when the output location should stay consistent across sessions, such as notes, findings, or screenshots. 15. He and Justin discuss running two parallel agents on 'site.com,' one with a full workflow and one with minimal guidance, then comparing the gaps. 16. Alex recommends asking each agent to keep notes on what it tried so that a third pass can compare the context, outputs, and missing steps. 17. The tone is technical and argumentative, with Justin pressing for practical boundaries and Alex answering in workflow terms. 18. The format stays conversational and iterative, with frequent back-and-forth on Claude MD, Kaido mode, and session search. 19. People building Claude workflows for bug bounty reconnaissance would get the most from this episode. 20. Listeners looking for beginner AI hype or broad product news may skip it.

As heard by us

A grounded look at when an AI tool's freedom helps a hacker, and when structure keeps the work honest.

The episode treats AI-assisted hacking less as a novelty than as a workflow design problem: how much freedom a tool should have while mapping a client-side attack surface.

Read the full review in PlayNext →

Why you'd press play

You get a front-row look at turning AI-assisted hacking into a more repeatable bug-hunting workflow.

Read the full recommendation in PlayNext →
Listen to the show on