report-draft

Convert validated bug bounty proof of concepts into platform-ready vulnerability reports.

Updated May 14, 2026
One-click install
npx skills add https://github.com/cuongnguyen-git/bug-bounty --skill report-draft
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-draft
Source: https://github.com/cuongnguyen-git/bug-bounty/tree/main/.claude/skills/report-draft
Command: npx skills add https://github.com/cuongnguyen-git/bug-bounty --skill report-draft

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Drafts a high-quality, platform-ready bug bounty report from a validated end-to-end proof of concept, so you can submit efficiently without wasting triager time on weak or speculative claims.

Core Features & Use Cases

  • Hard-stop validation: Blocks drafting when required evidence (PoC, non-Informational severity, non-public data, and real-world impact) is missing.
  • Platform-specific formatting: Enforces HackerOne, Bugcrowd, or Intigriti report structures and required fields, including CVSS requirements for Intigriti.
  • Impact and remediation rigor: Requires concrete, non-speculative impact plus actionable remediation steps aligned to the demonstrated behavior.

Quick Start

Ask your AI to draft a HackerOne or Bugcrowd report for a validated finding using your working PoC steps and confirmed impact evidence.

Frequently Asked Questions about report-draft

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for HackerOne or Bugcrowd?

Bug bounty report drafting requires a validated end-to-end proof of concept with confirmed, non-speculative impact. The system formats your PoC steps into a platform-ready submission with exact fields required by HackerOne or Bugcrowd.

What is needed to submit a vulnerability report to Intigriti?

Vulnerability report submission to Intigriti requires a validated PoC and a CVSS score. The drafting process enforces Intigriti-specific report structures and mandates concrete, non-speculative impact evidence before generating the submission.

Can I use a proof of concept to draft a vulnerability report for an informational finding?

No, you cannot draft a vulnerability report for an informational finding. A hard-stop validation gate blocks drafting unless the PoC evidence demonstrates non-informational severity and real-world impact.

How do I format remediation steps in a Bugcrowd vulnerability report?

To format remediation steps in a Bugcrowd vulnerability report, they must be actionable and aligned to the demonstrated behavior. The drafting process requires concrete impact wording to generate appropriate remediation guidance.

What is the best way to turn a validated PoC into a triager-friendly bug bounty submission?

The best way to turn a validated PoC into a triager-friendly submission is to format exact reproduction steps and confirmed impact according to platform-specific rules. This prevents wasting triager time on weak or speculative claims.