What problem does it solve?
It prevents mis-scoped Bugcrowd submissions by guiding you to choose the right VRT mapping, request accurate technical severity, and preempt common OOS auto-close objections.
Core Features & Use Cases
- VRT category selection with fallback logic: Select the most specific accurate VRT using a search hierarchy, and use “VRT mapping note” framing when no exact node fits.
- Manual severity override strategy: When Bugcrowd’s suggested severity underrates impact, request the correct technical severity and place a severity-request paragraph first.
- OOS-clause rebuttal templates: Add targeted “In-scope justification” sections for rate-limiting-within-auth-endpoints, debug/info disclosures that are actually control-bypass, user enumeration with meaningful PII, and theoretical vs exploitable findings.
- Chained findings cross-references: File the chain consumer first and then link primitives with explicit UUID cross-references so the chain is understood without bundling multiple fixes into one report.
- QA vs production target selection and researcher hygiene: Pick the correct QA/production target, document QA notes, and follow Bugcrowd-friendly-tester hygiene (Bugcrowdninja alias, account-state restoration, session/cookie rotation, and lock handling).
Quick Start
Use the bugcrowd-reporting skill while drafting your Bugcrowd submission to select the correct VRT, decide whether to override severity, and insert the severity request and any required in-scope justification into the description.