What problem does it solve?
This Skill eliminates the wasted effort of submitting bug bounty findings that are universally ineligible or lack demonstrated real-world impact, which often leads to instant rejection and wasted researcher time.
Core Features & Use Cases
- Three-Tier Eligibility Classification: Automatically maps findings against hard ineligible (universally rejected), soft ineligible (AI/scanner false positives), and program-specific exclusion tiers to quickly determine report viability.
- False Positive Pattern Detection: Identifies common over-inflated patterns from AI scanners and automated tools that lack proof of actual security impact.
- Impact Justification Generation: Creates tailored, evidence-based justification blocks for borderline findings to prevent instant triage as informational during program review.
- Use Case: A bug bounty researcher finds a potential open redirect during a web application test. This skill quickly checks if the redirect lacks additional security impact (like OAuth token theft) and flags it as ineligible, saving the researcher from submitting a low-value finding that will be rejected.
Quick Start
Use the report-preflight skill to check if your potential bug bounty finding for the target you are currently testing is eligible for submission before you invest time writing the full report.