report-writing

Generate bug bounty reports with structured templates and CVSS scoring.

1|Updated Jun 22, 2026
One-click install
npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill report-writing-0xhaaz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/0xhaaz/bug-bounty-toolkit/tree/main/skills/report-writing
Command: npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill report-writing-0xhaaz

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the complexities of writing detailed and impactful bug bounty reports, offering templates, guidelines, and scoring assistance.

Core Features & Use Cases

  • Report Templates: Provides templates for HackerOne, Bugcrowd, Intigriti, and Immunefi.
  • Guidelines: Offers human tone guidelines, impact-first writing, CVSS scoring, and severity decision guides.
  • Use Case: After validating a bug, use this Skill to generate a report with the appropriate format and content.

Quick Start

Generate a report for a validated bug using the report-writing skill.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for HackerOne or Bugcrowd?

To write a bug bounty report for HackerOne or Bugcrowd, use structured templates that follow impact-first writing principles to clearly communicate vulnerability details and severity to triagers.

What is CVSS scoring and how does it affect bug bounty severity assessment?

CVSS scoring is a standardized framework for assessing vulnerability severity. Accurate CVSS scoring directly determines bug bounty severity, helping platforms and triagers prioritize remediation based on technical impact.

Can I use report writing guidelines for Web3 bug bounties on Immunefi?

Yes, report writing guidelines support Immunefi. You can generate structured reports using specific templates tailored for Web3 bug bounties, ensuring smart contract vulnerabilities are documented effectively.

What is the best way to structure a bug bounty report to ensure maximum payout?

The best way to structure a bug bounty report is to apply impact-first writing principles. Clearly demonstrate business impact, use human tone guidelines, and provide accurate CVSS scoring to justify maximum payout.

Does this report writing approach work for Intigriti submissions?

Yes, this approach works for Intigriti submissions. It provides report templates specifically designed for the Intigriti platform, ensuring your validated bugs meet their formatting and severity assessment requirements.

Why does my bug bounty report keep getting duplicates or closed as informative?

Bug bounty reports often get closed as informative due to poor impact-first writing. Without clear human tone guidelines and accurate CVSS scoring, triagers may misunderstand the technical severity and business impact.