1. Verify project's viability
2. Verify core team's identity
3. Check if they have a working MVP already
4. Check repository / Github activity
5. Ask the team on related questions on the project's social media channels, etc...
What should hunter do, if the projects passes all the 5 points you wrote, or simply dont have some the points. For example, bounty campaign of an exchange. Do you often see they put their team on public or post a lot in github?
Or MVP - often the team is in a processes of collecting funds, decides to run a bounty campaign. They wont have a MVP.
"5. Ask the team on related questions on the project's social media channels, etc..." - I've tried asking CZ questions about Binance in twitter, but he ignore me. If he ever run a bounty campaign, I'd better skip it. They seems shady, except CZ I dont know any representative from Binance.