bugcrowd-reporting

Guide Bugcrowd submissions with VRT selection, severity overrides, and OOS rebuttals.

3|Updated Nov 12, 2025
One-click install
npx skills add https://github.com/cmndcntrlcyber/rtpi --skill bugcrowd-reporting-cmndcntrlcyber
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bugcrowd-reporting
Source: https://github.com/cmndcntrlcyber/rtpi/tree/main/knowledge_seed/bug_hunter_skills/bugcrowd-reporting
Command: npx skills add https://github.com/cmndcntrlcyber/rtpi --skill bugcrowd-reporting-cmndcntrlcyber

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines Bugcrowd submissions by guiding the selection of Vulnerability Rating Taxonomy (VRT) categories, providing severity override strategies, and offering rebuttal templates for out-of-scope (OOS) claims.

Core Features & Use Cases

  • VRT Category Selection: Offers a search-and-fallback strategy for VRT selection to ensure accurate impact representation.
  • Manual Severity Override: Instructs on when and how to override default VRT severity ratings.
  • OOS-Clause Rebuttals: Provides templates for rebutting common OOS claims made by Bugcrowd triagers.
  • Chained Findings: Outlines a strategy for reporting chained vulnerabilities and cross-referencing related submissions.
  • Target Selection: Offers guidance on selecting the appropriate target environment (QA vs. production) for submissions.
  • Researcher-Side Hygiene: Details best practices for maintaining a positive researcher reputation on Bugcrowd.
  • Submission-Order Strategy: Recommends an order for submitting multiple findings from a single engagement.

Quick Start

Use the bugcrowd-reporting skill to analyze your Bugcrowd submission and ensure it adheres to best practices for VRT selection and severity overrides.

Frequently Asked Questions about bugcrowd-reporting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I select the correct VRT category for a Bugcrowd submission?

To override default VRT severity ratings, follow specific instructions on when and how to apply manual severity overrides during your Bugcrowd submission. This ensures the assigned severity accurately reflects the true impact of the vulnerability.

How do I write a rebuttal for an out-of-scope claim on Bugcrowd?

To write a rebuttal for an out-of-scope claim on Bugcrowd, use provided OOS clause rebuttal templates designed to counter common triager claims. These templates help structure your argument to demonstrate why a finding falls within the program's scope.

What is the best way to report chained vulnerabilities on Bugcrowd?

The best way to report chained vulnerabilities on Bugcrowd is to follow a specific submission strategy that cross-references related findings. This approach outlines how to link individual submissions together to demonstrate the combined impact.

When should I choose a QA target environment versus production for Bugcrowd submissions?

You should choose between QA and production target environments based on specific guidance for selecting the appropriate target environment for submissions. This ensures your testing aligns with program rules and targets the correct infrastructure.

Do I need to understand the Bugcrowd workflow to use severity overrides?

To maintain a positive Bugcrowd researcher reputation, follow researcher-side hygiene best practices and a recommended submission-order strategy for multiple findings. This ensures your submissions are well-structured and professionally managed.