report-agent

Generate HackerOne-format vulnerability reports from validated security findings.

54|5|Updated May 9, 2026
One-click install
npx skills add https://github.com/jinyimeng01/mastermind-bug-bounty --skill report-agent
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-agent
Source: https://github.com/jinyimeng01/mastermind-bug-bounty/tree/main/agents/report
Command: npx skills add https://github.com/jinyimeng01/mastermind-bug-bounty --skill report-agent

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill solves the challenge of turning validated security findings into clear, professional vulnerability reports that meet bug bounty platform expectations and communicate impact effectively.

Core Features & Use Cases

  • HackerOne-Style Reporting: Converts triage-approved findings into structured reports with summaries, reproduction steps, proof of concept evidence, impact analysis, and remediation guidance.
  • Security Assessment Documentation: Produces CVSS 3.1 scoring details, vulnerability titles, CWE references, and actionable mitigation recommendations for offensive security workflows.
  • Use Case: A security researcher with an approved IDOR finding can use this Skill to transform raw evidence into a complete submission-ready report for a bug bounty program.

Quick Start

Use the report-agent skill to generate a complete HackerOne-format report from the approved vulnerability finding and evidence provided.

Frequently Asked Questions about report-agent

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for HackerOne submissions?

To write a bug bounty report for HackerOne, structure your validated findings with summaries, reproduction steps, proof of concept evidence, impact analysis, and remediation guidance to meet platform submission expectations.

How do I calculate CVSS 3.1 scores for security assessment documentation?

Security assessment documentation requires calculating CVSS 3.1 scores by evaluating validated vulnerability findings, aligning them with CWE references, and generating actionable mitigation recommendations for offensive security workflows.

Can I generate vulnerability reports from raw IDOR evidence?

Yes, you can generate vulnerability reports from raw IDOR evidence by transforming triage-approved security findings into complete, structured submissions with documented proof of concept and impact analysis for bug bounty programs.

What is the best way to document proof of concept for penetration testing findings?

The best way to document proof of concept for penetration testing is to format validated security findings into structured reports that include detailed reproduction steps, evidence, and CWE-aligned mitigation recommendations.

Does bug bounty report formatting require CWE-aligned mitigation recommendations?

Yes, professional bug bounty report formatting requires CWE-aligned mitigation recommendations to provide actionable remediation guidance alongside CVSS scoring and structured vulnerability impact analysis.