report-bug-bounty

Draft structured vulnerability disclosure reports with CVSS v4.0 scoring and CWE mapping.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill report-bug-bounty
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-bug-bounty
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/report-bug-bounty
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill report-bug-bounty

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the challenge of translating raw, technical security findings into structured, high-quality bug bounty reports that meet the rigorous standards of platforms like HackerOne and Bugcrowd.

Core Features & Use Cases

  • Structured Reporting: Automatically formats findings into platform-compliant templates including CVSS scoring, CWE mapping, and remediation guidance.
  • Evidence Management: Integrates with existing finding stores and redacted evidence to ensure reports are reproducible and clear without exposing sensitive data.
  • Use Case: After identifying an IDOR vulnerability, use this skill to generate a submission-ready report that includes the CVSS vector, reproduction steps, and impact analysis, ensuring the triager can validate the finding quickly.

Quick Start

Use the report-bug-bounty skill to draft a submission for the confirmed IDOR finding in the current engagement.

Frequently Asked Questions about report-bug-bounty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I format a bug bounty report for HackerOne or Bugcrowd submissions?

To format a bug bounty report, draft structured vulnerability disclosures with CVSS v4.0 scoring, CWE mapping, and platform-specific templates to meet HackerOne, Bugcrowd, or Intigriti submission standards. This ensures triagers can quickly validate findings.

What is the best way to map CWE and calculate CVSS v4.0 scores for vulnerability disclosure?

Mapping CWE and calculating CVSS v4.0 scores for vulnerability disclosure involves structuring verified findings with precise remediation guidance and impact analysis. This translates raw technical security data into standardized, reproducible reports.

How do I include redacted evidence in a vulnerability disclosure report?

To include redacted evidence in a vulnerability disclosure report, integrate with existing local finding inventories while enforcing strict redaction policies. This ensures reports remain reproducible without exposing sensitive data.

Can I draft platform-ready bug reports directly from raw pentesting findings?

Yes, you can draft platform-ready bug reports directly from raw pentesting findings by structuring verified vulnerabilities into compliant templates. This automatically generates reproduction steps and impact analysis for triagers.

Does generating bug bounty reports require a local finding inventory?

Generating bug bounty reports requires integration with a local finding inventory to pull verified findings and redacted evidence. This prerequisite ensures the structured disclosure accurately reflects the current engagement's security vulnerabilities.