bugcrowd-reporting

Select VRT categories and override severity levels for Bugcrowd reports.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill bugcrowd-reporting-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bugcrowd-reporting
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/bugcrowd-reporting
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill bugcrowd-reporting-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the complexities of filing Bugcrowd reports by providing precise VRT selection, severity overrides, and strategic tactics to improve report acceptance and bounty awards.

Core Features & Use Cases

  • VRT Category Selection: Offers a search-and-fallback strategy for selecting the most accurate VRT category.
  • Manual Severity Override: Guides on when and how to override default severity levels.
  • OOS-Clause Rebuttals: Provides templates for rebutting out-of-scope objections.
  • Chained Findings Strategy: Explains how to file and cross-reference chained findings effectively.
  • Target Selection: Offers guidance on selecting the correct target for QA vs. production environments.
  • Researcher-Side Hygiene: Details best practices for maintaining a professional researcher profile on Bugcrowd.
  • Submission-Order Strategy: Suggests an order for submitting multiple findings to maximize impact.

Quick Start

Use the bugcrowd-reporting skill to optimize your next Bugcrowd report with tailored tactics for VRT selection and severity justification.

Frequently Asked Questions about bugcrowd-reporting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I select the correct VRT category for a Bugcrowd report?

To select the correct VRT category for a Bugcrowd report, use a search-and-fallback strategy to find the most accurate Vulnerability Rating Taxonomy classification. This ensures triagers can quickly validate the finding's impact and severity.

When should I use a manual severity override in Bugcrowd triage?

A manual severity override in Bugcrowd triage is used when the default VRT rating does not accurately reflect the business impact. It guides you on when and how to justify overriding default severity levels for appropriate bounty awards.

How do I rebut out-of-scope objections on my Bugcrowd submission?

Rebut out-of-scope objections on Bugcrowd submissions by using structured OOS-Clause rebuttal templates. These templates help you clearly demonstrate why a finding falls within the program's intended scope despite initial triager rejection.

What is the best way to file chained findings on Bugcrowd?

The best way to file chained findings on Bugcrowd involves a specific submission-order strategy that cross-references related vulnerabilities effectively. This maximizes impact and helps triagers understand the combined severity of the exploit chain.

Can this skill help me choose the correct target for QA vs production environments?

Yes, this skill offers target selection guidance to help you correctly identify and report vulnerabilities in QA versus production environments. This ensures your reports align with the program's specific testing scope and rules.

How do I maintain a professional researcher profile on Bugcrowd?

Maintain a professional researcher profile on Bugcrowd by following researcher-side hygiene best practices. This includes clear communication, proper report formatting, and strategic submission ordering to build trust with triagers.