hackerone-report

Generate HackerOne-format vulnerability reports with CVSS scoring.

5|3|Updated Apr 10, 2026
One-click install
npx skills add https://github.com/zebbern/termstack --skill hackerone-report
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hackerone-report
Source: https://github.com/zebbern/termstack/tree/main/.github/skills/hackerone-report
Command: npx skills add https://github.com/zebbern/termstack --skill hackerone-report

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Vulnerability disclosure and reporting can be time-consuming and inconsistently formatted. This Skill standardizes the creation of professional HackerOne-format reports with CVSS scoring, ensuring clear articulation of impact, steps to reproduce, remediation, and references.

Core Features & Use Cases

  • HackerOne-format reports with CVSS scoring and structured sections for executive summary, impact, PoC, remediation, and references.
  • Reproducible documentation: converts technical findings into a consistent, auditable report suitable for disclosure and bounty submissions.
  • Templates and guidance for common vulnerability types to accelerate reporting and reduce oversight.

Quick Start

Generate a HackerOne-format vulnerability report for a confirmed finding.

Frequently Asked Questions about hackerone-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a vulnerability report for HackerOne bug bounty submissions?

A HackerOne vulnerability report must include a title, executive summary, CVSS vector, proof of concept, remediation steps, and references. This Skill formats confirmed security findings into this standardized structure for bounty submission.

How do I calculate and include CVSS scoring in a security vulnerability report?

CVSS scoring is included by generating the formal CVSS vector alongside impact analyses and executive summaries. This Skill produces HackerOne-style reports integrating CVSS scoring to articulate vulnerability severity clearly for triagers.

What sections are required for a HackerOne disclosure report?

HackerOne disclosure reports require a title, executive summary, CVSS vector, proof of concept (PoC), remediation, and references. This Skill ensures vulnerability documentation meets these formal reporting standards with professional language.

Can I generate proof of concept and remediation steps for bug bounty findings automatically?

Generate proof of concept and remediation steps by converting technical security findings into consistent, auditable reports. This Skill structures confirmed vulnerability data into reproducible documentation suitable for bug bounty disclosure workflows.

Does generating HackerOne reports require redacting sensitive data in the vulnerability disclosure?

Generating HackerOne reports requires professional language with redacted sensitive data to ensure safe vulnerability disclosure. This Skill applies data redaction standards when documenting executive summaries and impact analyses for security assessments.