bugcrowd-reporting

Implement Bugcrowd reporting strategies for VRT selection, severity overrides, and OOS rebuttals.

Updated Jul 1, 2026
One-click install
npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill bugcrowd-reporting-bpnrockstar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bugcrowd-reporting
Source: https://github.com/bpnrockstar/UnifiedBugHunter/tree/main/skills/bugcrowd-reporting
Command: npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill bugcrowd-reporting-bpnrockstar

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill empowers researchers to excel at Bugcrowd reporting by offering targeted strategies for VRT category selection, manual severity override, and rebuttals for out-of-scope (OOS) clauses.

Core Features & Use Cases

  • VRT Category Selection: A robust search-and-fallback strategy for selecting the correct VRT category for Bugcrowd submissions.
  • Manual Severity Override: Guidance on overriding the default severity rating to better reflect the actual impact.
  • OOS-Clause Rebuttals: Pre-formatted templates to rebut OOS claims from Bugcrowd triagers.
  • Chained Findings: Instructions on how to effectively report chained findings in a structured manner.
  • Target Selection: Guidance on choosing the appropriate target (QA vs. Production) for Bugcrowd submissions.
  • Researcher-Side Hygiene: Best practices for maintaining the quality and credibility of submissions.

Quick Start

Apply the bugcrowd-reporting skill when drafting a Bugcrowd submission to enhance your VRT category selection and severity arguments.

Frequently Asked Questions about bugcrowd-reporting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I select the correct VRT category for a Bugcrowd submission?

Selecting the correct VRT category for Bugcrowd submissions involves a robust search-and-fallback strategy to match the vulnerability impact. This approach ensures accurate categorization, reducing triage friction and improving submission clarity.

What is the best way to report chained findings on Bugcrowd?

Reporting chained findings on Bugcrowd requires a structured format that clearly links individual vulnerabilities to demonstrate the combined impact. This structure helps triagers understand the full exploit chain and assign appropriate severity.

How do I override default severity ratings for Bugcrowd vulnerability reports?

Overriding default severity ratings for Bugcrowd vulnerability reports involves providing manual guidance that better reflects the actual impact. This ensures the assigned severity accurately represents the risk rather than relying on automated scoring.

Can I rebut an out-of-scope OOS clause decision from a Bugcrowd triager?

Rebutting an out-of-scope OOS clause decision from a Bugcrowd triager is possible using pre-formatted templates. These templates help structure arguments clearly to challenge OOS claims and demonstrate legitimate impact within program boundaries.

How do I choose between QA and Production targets when submitting to Bugcrowd?

Choosing between QA and Production targets for Bugcrowd submissions requires evaluating the program scope and target environment. Selecting the appropriate target ensures the vulnerability is valid and actionable within the program's defined testing boundaries.

Related Skills