report-template

Converts security findings into formatted bug bounty submissions and client engagement reports.

4|Updated Apr 29, 2026
One-click install
npx skills add https://github.com/Ap6pack/outrider-recon --skill report-template-ap6pack
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-template
Source: https://github.com/Ap6pack/outrider-recon/tree/main/skills/report-template
Command: npx skills add https://github.com/Ap6pack/outrider-recon --skill report-template-ap6pack

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill transforms collected, evidence-backed security findings into clear bug bounty submissions, client deliverables, and vulnerability reports without losing severity, confidence, reproduction, or remediation context.

Core Features & Use Cases

  • Bug Bounty Reports: Structure individual findings with vulnerability type, reproduction steps, proof of concept, impact, CVSS scoring, remediation, and supporting evidence.
  • Client Deliverables: Assemble engagement summaries with aggregate metrics, prioritized findings, business impact, recommended next steps, and reproduction packages.
  • Evidence and Safety Controls: Preserve URLs, UTC timestamps, tool details, and SHA-256 hashes while truncating credentials and redacting personally identifiable information.
  • Use Case: After an authorized recon engagement, use this Skill to convert reviewed findings and registered evidence into sanitized HackerOne-ready submissions or a complete client report.

Quick Start

Use the report-template skill to generate sanitized bug bounty submissions for all reviewed findings in the current engagement.

Frequently Asked Questions about report-template

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I convert security findings into bug bounty reports?

To convert security findings into bug bounty reports, the skill transforms collected evidence into structured submissions. It includes vulnerability types, reproduction steps, proof of concept, impact, CVSS scoring, and remediation guidance.

What is the best way to generate client deliverables for penetration testing?

The best way to generate client deliverables for penetration testing is to assemble engagement summaries. These include aggregate metrics, prioritized findings, business impact, recommended next steps, and reproduction packages.

How does evidence management handle PII and credentials in vulnerability reports?

Evidence management in vulnerability reports preserves URLs, UTC timestamps, tool details, and SHA-256 hashes. It truncates credentials and redacts personally identifiable information for submission-ready reports.

Do I need registered evidence IDs to document security findings?

Yes, you need registered evidence IDs to document security findings. The process requires the shared Outrider run contract, finding schemas, severity and confidence metadata, and append-only promoted-finding records.

Can I use this for HackerOne-ready submissions after authorized recon?

Yes, you can use this for HackerOne-ready submissions after authorized recon. It converts reviewed findings and registered evidence into sanitized bug bounty submissions or a complete client report.