bugcrowd-reporting

Map VRT categories and override severity for Bugcrowd submissions.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill bugcrowd-reporting-kisilev13
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bugcrowd-reporting
Source: https://github.com/Kisilev13/Hermes-Agent-Workspace/tree/main/skills/bugcrowd-reporting
Command: npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill bugcrowd-reporting-kisilev13

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the complexities of Bugcrowd submissions, providing precise VRT mapping and severity override strategies to enhance the accuracy and impact of bug reports.

Core Features & Use Cases

  • VRT Category Selection: Offers a search-and-fallback strategy for selecting the most accurate VRT category for Bugcrowd submissions.
  • Manual Severity Override: Instructs on when and how to manually override VRT defaults to reflect the true impact of a bug.
  • OOS-Clause Rebuttals: Provides templates to justify findings that do not fit standard Out-of-Scope clauses.
  • Chained Findings: Explains how to file and cross-reference chained findings for maximum impact.
  • Target Selection: Guides the selection between QA and production targets for accurate impact assessment.
  • Researcher-Side Hygiene: Offers best practices for maintaining a good researcher reputation and following program rules.

Quick Start

Use the bugcrowd-reporting skill to file a Bugcrowd submission with a VRT mapping note and severity request paragraph.

Frequently Asked Questions about bugcrowd-reporting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map a vulnerability to the correct Bugcrowd VRT category?

To map a vulnerability for Bugcrowd VRT, use a search-and-fallback strategy to select the most accurate category. This ensures your submission reflects the precise nature of the bug within the Bugcrowd framework.

When should I manually override severity on a Bugcrowd submission?

You should manually override VRT default severity when the standard rating does not reflect the true impact of your bug. This Skill provides strategies to justify your severity request and accurately represent the vulnerability's actual risk.

How do I justify a finding that falls under a Bugcrowd Out-of-Scope clause?

To justify a finding against an Out-of-Scope (OOS) clause on Bugcrowd, use provided OOS-Clause rebuttal templates. These templates help you articulate why the vulnerability should be accepted despite initially appearing out of scope.

What is the best way to file chained findings on Bugcrowd?

The best way to file chained findings is to submit them individually and cross-reference the related reports. This Skill explains how to manage chained findings to maximize the overall impact and clarity of your submission.

Do I need prior bug bounty experience to use Bugcrowd severity override strategies?

Yes, you need a solid understanding of Bugcrowd submission processes and vulnerability assessment. This Skill is designed for users who already know how to file reports and need advanced tactics for VRT mapping and severity overrides.