What problem does it solve?
Bug bounty hunters and security researchers often waste time formatting vulnerability reports to meet HackerOne's strict requirements, leading to triage delays, rejected submissions, or missed impact details that reduce bounty payouts.
Core Features & Use Cases
- Pre-Report Validation Gate: Ensures only reproduced, escalated, in-scope findings with passed preflight checks are submitted, avoiding wasted effort on invalid reports.
- Standardized Formatting: Auto-structures reports with required CVSS 4.0 and 3.1 blocks, H1 weakness type mappings, and clear PoC steps with proxy screenshot markers.
- Use Case: After validating an SSRF vulnerability with the exploit-verifier skill, use this tool to generate a fully compliant report that includes all required evidence, impact justification, and root cause recommendations in the correct H1 format.
Quick Start
Use the report-writer skill to convert my validated SSRF finding for the /api/export endpoint into a structured HackerOne report.