report-writing

Generate triager-ready bug bounty reports with CVSS scoring for HackerOne, Bugcrowd, Intigriti, and Immunefi.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/AKasem1/claude-bug-bounty --skill report-writing-akasem1
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/AKasem1/claude-bug-bounty/tree/main/skills/report-writing
Command: npx skills add https://github.com/AKasem1/claude-bug-bounty --skill report-writing-akasem1

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Converts validated security findings into clear, impact-first reports that triagers can quickly approve without theoretical language or weak claims.

Core Features & Use Cases

  • Impact-first, human tone guidance: Enforces direct language (no “could/may” phrasing) so the report reads like a real triage decision, not a guess.
  • Platform-specific report templates: Provides HackerOne, Bugcrowd, Intigriti, and Immunefi-ready structures so submissions match each program’s expectations.
  • Severity and scoring support: Covers CVSS 3.1 quick scoring, CVSS 4.0 referencing, title formulas, impact statements, and severity decision/downgrade counters.
  • Pre-submit quality gate: Includes a 60-second checklist focused on reproducibility, correct endpoints/parameters, quantified impact, and evidence readiness.

Quick Start

Use the report-writing skill after you have a working reproduction on test accounts to draft your final triager submission for HackerOne, Bugcrowd, Intigriti, or Immunefi.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write bug bounty reports that get approved quickly on HackerOne and Bugcrowd?

Writing triager-ready bug bounty reports requires structuring validated findings using impact-first language, deterministic reproduction steps, and platform-specific templates for HackerOne or Bugcrowd to ensure quick triage approval.

What is the best way to format reproduction steps for a bug bounty submission?

Formatting reproduction steps for a bug bounty submission requires deterministic, step-by-step instructions that eliminate theoretical phrasing and precisely document endpoints and parameters to guarantee triagers can reproduce the vulnerability.

How do I calculate and justify CVSS 3.1 severity for a vulnerability report?

Calculating CVSS 3.1 severity for a vulnerability report involves applying standard scoring metrics, using CVSS 4.0 referencing, and writing impact statements with severity downgrade counters to justify the rating to triagers.

Does this report writing approach work for web, API, and protocol bug classes?

Yes, this report writing approach works for web, API, and protocol bug classes by generating platform-specific submissions across HackerOne, Bugcrowd, Intigriti, and Immunefi tailored to each program's distinct vulnerability class expectations.

What should a pre-submit checklist include for bug bounty reports?

A pre-submit checklist for bug bounty reports should verify reproducibility, confirm correct endpoints and parameters, quantify impact statements, and ensure evidence readiness through a 60-second quality gate before final submission.

Why do triagers downgrade bug bounty report severities?

Triagers downgrade bug bounty report severities when submissions contain theoretical phrasing, weak impact claims, or ambiguous reproduction steps, which is why impact-first writing and severity justification counters are required.