bugcrowd-reporting

Map Bugcrowd submissions to VRT categories and triage workflows.

3.3k|507|Updated May 5, 2026
One-click install
npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bugcrowd-reporting-elementalsouls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bugcrowd-reporting
Source: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/bugcrowd-reporting
Command: npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill bugcrowd-reporting-elementalsouls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This set of program-specific tactics helps researchers map Bugcrowd submissions to the right VRT categories, apply appropriate severity overrides when needed, and craft effective rebuttals and cross-reference narratives to improve triage outcomes.

Core Features & Use Cases

  • VRT mapping guidance for Bugcrowd submissions to minimize misclassification.
  • Manual severity override workflows with severity-requests and clearly structured description bodies.
  • OOS-clause rebuttal templates and in-scope justification to pre-empt triage auto-close.
  • Chained findings guidance with cross-reference templates for multi-prong impact.
  • QA-vs-Production target selection guidance and notes for tester hygiene.
  • Hygiene practices for Bugcrowd submissions (alias usage, state restoration, cookie rotation).

Quick Start

Describe a Bugcrowd submission using the program-specific tactics to guide VRT mapping and triage decisions.

Frequently Asked Questions about bugcrowd-reporting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map Bugcrowd vulnerability submissions to the correct VRT category?

VRT mapping for Bugcrowd submissions involves matching vulnerability characteristics to specific Vector categories to minimize misclassification during triage. Proper VRT selection ensures accurate risk signaling and reduces the chance of downgraded severity.

How do I write an OOS rebuttal to prevent my Bugcrowd report from being auto-closed?

OOS rebuttals require explicit in-scope justification using program-specific clauses to pre-empt triage auto-close. Using structured templates helps demonstrate exactly how the finding aligns with the program's defined scope boundaries.

What is the best way to document chained findings for Bugcrowd triage?

Documenting chained findings requires cross-reference templates that link multi-prong impacts into a single narrative for Bugcrowd triage. This approach clarifies the compounded risk and ensures testers understand the full attack chain context.

When should I request a manual severity override for a Bugcrowd submission?

Manual severity overrides are triggered when standard VRT mapping fails to capture the true risk of a Bugcrowd submission. Submit a severity-request with a clearly structured description body explaining the contextual impact to validate the override.

Does Bugcrowd triage require specific tester hygiene practices for QA vs Production targets?

Bugcrowd triage expects strict tester hygiene including QA-vs-Production target selection, alias usage, state restoration, and cookie rotation. These practices ensure testing environments remain isolated and do not interfere with production systems.

Can I use Bugcrowd reporting tactics for end-to-end bug bounty submissions?

Bugcrowd reporting tactics support end-to-end bug bounty submissions by pairing VRT mapping and triage validation with report-writing workflows. This integration covers target selection, severity overrides, and cross-referencing for complete submission packages.