report-psychology

Generate structured H1 vulnerability reports with CVSS 3.1 scoring.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/AshtonVaughan/bountyhound --skill report-psychology
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-psychology
Source: https://github.com/AshtonVaughan/bountyhound/tree/main/bountyhound/skills/report-psychology
Command: npx skills add https://github.com/AshtonVaughan/bountyhound --skill report-psychology

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Manual report drafting for bug bounty programs is time-consuming and prone to inconsistency. This protocol provides a clear, repeatable framework with templates, checklists, and guidelines to produce triage-ready H1 reports that pass first review.

Core Features & Use Cases

  • Templates for title, summary, steps to reproduce, impact, evidence, and remediation to ensure consistency.
  • Checklists to guarantee all required sections are present and clearly articulated.
  • Guidelines & Decision Trees to help writers determine the appropriate level of detail, severity framing, and evidence selection.
  • Use cases include web applications, mobile apps, and API findings to generate reproducible, evidence-backed reports.

Quick Start

Write a complete H1 report for a recent finding using the templates and guidelines provided.

Frequently Asked Questions about report-psychology

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that passes triage on the first review?

To write a bug bounty report that passes triage, use a structured protocol with templates and checklists covering title, summary, expected vs actual behavior, reproduction steps, impact, evidence, and remediation with CVSS 3.1 scoring.

What sections are required in an H1 vulnerability report?

Required H1 vulnerability report sections include title, summary, expected vs actual behavior, steps to reproduce, impact, supporting material, severity justification, and recommended fixes, along with a CVSS 3.1 score.

How do I format vulnerability findings for consistent reporting across different bug bounty clients?

Format vulnerability findings consistently by applying repeatable templates and checklists across web, mobile, and API engagements, ensuring clear reproduction steps, impact framing, evidence, and remediation are present for every client report.

What's the best way to justify severity and select evidence for a vulnerability report?

The best way to justify severity and select evidence is to follow structured guidelines and decision trees that determine appropriate detail levels, severity framing, and evidence selection for reproducible, evidence-backed reports.

Can I use a single report-writing protocol for web, mobile, and API bug bounty findings?

Yes, you can use a single report-writing protocol for web, mobile, and API bug bounty findings, as it provides templates, checklists, and guidelines ensuring consistent, triage-ready reporting across all application types.

Why do my bug bounty reports get rejected during triage?

Bug bounty reports often get rejected during triage due to missing required sections, unclear reproduction steps, inadequate impact framing, or incomplete evidence, which structured templates and checklists are designed to prevent.