bugcrowd-reporting

Generate Bugcrowd severity-request paragraphs and OOS rebuttal templates.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill bugcrowd-reporting-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: bugcrowd-reporting
Source: https://github.com/pdparchitect/rook/tree/main/skills/bugcrowd-reporting
Command: npx skills add https://github.com/pdparchitect/rook --skill bugcrowd-reporting-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the friction of Bugcrowd-specific submission processes, helping researchers navigate VRT mapping, justify severity overrides, and successfully rebut OOS (Out-of-Scope) objections.

Core Features & Use Cases

  • VRT Strategy: Provides a search-and-fallback hierarchy for accurate Vulnerability Rating Taxonomy selection.
  • Severity Justification: Offers templates for manual severity overrides and pre-emptive severity-request paragraphs to prevent auto-closing.
  • OOS Rebuttals: Contains pre-written templates to defend findings against common OOS-clause objections like rate-limiting or debug-info disclosure.
  • Use Case: Use this when you have a high-impact finding that the VRT defaults to P4, but you need to argue for a P2 based on the program's specific Focus Areas and chained impact.

Quick Start

Use the bugcrowd-reporting skill to generate a severity-request paragraph for my current submission that justifies a P2 rating based on the program focus areas.

Frequently Asked Questions about bugcrowd-reporting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map a vulnerability submission to the correct Bugcrowd VRT category?

Mapping a vulnerability submission to the Bugcrowd VRT requires a search-and-fallback hierarchy strategy to select the most accurate Vulnerability Rating Taxonomy node. This ensures precise impact representation and aligns your finding with triager expectations for proper severity assessment.

How do I justify a severity override for a Bugcrowd finding that defaults to P4?

Justifying a severity override for a Bugcrowd finding involves applying manual override templates and pre-emptive severity-request paragraphs. This prevents auto-closing by arguing for a higher rating like P2 based on the program's specific Focus Areas and chained impact.

What is the best way to rebut an Out-of-Scope objection on a Bugcrowd report?

Rebutting an Out-of-Scope (OOS) objection on a Bugcrowd report utilizes pre-written templates to defend findings against common OOS-clause objections like rate-limiting or debug-info disclosure. This ensures professional, evidence-based communication that adheres to platform submission rules.

Can I argue for a higher severity rating based on a program's specific Focus Areas?

Yes, you can argue for a higher severity rating by leveraging a program's specific Focus Areas and demonstrating chained impact. This involves using severity-request paragraphs to align your submission with the program's priorities and prevent auto-closing.

Why does my Bugcrowd submission get auto-closed before triager review?

Bugcrowd submissions often get auto-closed before triager review due to insufficient severity justification or inaccurate VRT mapping. Providing pre-emptive severity-request paragraphs and evidence-based communication aligned with program rules prevents this automated rejection.