--- name: nuclei-suggest description: Browse the nuclei-templates library, recommend a scoped template set for a given stack, target, or CVE, then run it against an authorized target and report findings. compatibility: nuclei-templates, nuclei binary --- Use nuclei and templates to empower a bug bounty or authorized assessment engagement hunt to the full capabilities of crowdsourced security. see `./references/install.md` for first installation of nuclei on the environment # Methodology 1. Index once into id, path, severity, tags, tier, replicable; rebuild only when the templates tree mtime changes. See `references/browsing.md` for traversal. 2. Confirm scope before any run: in-scope hosts, desired posture (e.g. passive v.s. active scan), and whether OAST callbacks are workable within the enivronment. 3. Tier by blast radius from template contents: `file/`, `dns/`, `ssl/` and single benign GETs are safe; `intrusive`, `brute`, `fuzz`, `unsafe: true` and `interactsh` require extra user consideration; `code/` executes on your own host and should almost never be used. Honor `.nuclei-ignore` and never exceed the confirmed ceiling. # Run preferences Run the scoped set with `-duc` (disable the update check, which otherwise stalls scripted runs), `-jsonl -irr -store-resp -srd