What problem does it solve?
This Skill helps you craft higher-quality Bugcrowd submissions by choosing the right VRT node, requesting correct technical severity when the default underrates impact, and pre-empting common OOS auto-close reasons with targeted rebuttals.
Core Features & Use Cases
- VRT category selection with search & fallback: Guides a disciplined lookup order (bug class, data category, control bypass, endpoint type, then parent node) and advises what to do when no accurate VRT exists.
- Manual severity override workflow: Explains when and how to override Bugcrowd’s VRT-derived technical severity without over-claiming.
- Severity-request paragraph for the first body section: Provides an “always first” template to request review before triagers act on the form-default severity.
- OOS-clause rebuttal templates: Supplies ready-to-adapt justifications for rate-limiting non-auth endpoints, “debug info” framing, user enumeration, and “theoretical issues” objections.
- Chain filing cross-reference strategy: Recommends filing the chain consumer first and cross-referencing primitive submissions by submission UUID.
- QA vs production target selection guidance and researcher hygiene: Adds notes for Bugcrowd-friendly targeting (including QA-testing disclosures) and account/session restoration practices.
Quick Start
Use the bugcrowd-reporting skill to draft a Bugcrowd submission description by selecting the closest VRT node, adding a first-section severity request when needed, and including the appropriate in-scope justification section for likely OOS objections.