report-writing

Generate structured bug bounty reports with CVSS scoring and severity assessment.

7|1|Updated Apr 14, 2026
One-click install
npx skills add https://github.com/ArianHobson333/claude-bug-bounty-stack --skill report-writing-arianhobson333
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/ArianHobson333/claude-bug-bounty-stack/tree/main/vendor/claude-bug-bounty/skills/report-writing
Command: npx skills add https://github.com/ArianHobson333/claude-bug-bounty-stack --skill report-writing-arianhobson333

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill addresses the challenge of writing comprehensive and impactful bug bounty reports, providing structured templates and guidelines to streamline the reporting process.

Core Features & Use Cases

  • Structured Report Templates: Offers ready-to-use templates for HackerOne, Bugcrowd, Intigriti, and ImmuniFi platforms.
  • Impact-First Writing: Emphasizes clear and concise communication of the impact of a vulnerability.
  • CVSS Scoring: Includes a guide for CVSS 3.1 and CVSS 4.0 scoring to ensure accurate severity assessment.
  • Severity Decision Guide: Helps in determining the severity of a vulnerability based on its impact.

Quick Start

Use the report-writing skill to generate a HackerOne report template for a discovered IDOR vulnerability.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that clearly communicates vulnerability impact?

A bug bounty report template provides a structured format for documenting vulnerabilities. It standardizes sections like summary, impact, and reproduction steps, ensuring consistent and comprehensive vulnerability communication across different reports.

How do I calculate CVSS 3.1 and CVSS 4.0 scores for security assessments?

Calculating CVSS scores for security assessments involves evaluating base metrics like attack vector and impact. This skill includes guidelines for CVSS 3.1 and CVSS 4.0 scoring to ensure accurate and consistent severity assessment for vulnerabilities.

Does this bug bounty reporting tool support HackerOne, Bugcrowd, Intigriti, and ImmuniFi?

Yes, this bug bounty reporting tool supports HackerOne, Bugcrowd, Intigriti, and ImmuniFi. It provides ready-to-use structured report templates tailored specifically for these platforms to streamline your submission process.

What is the best way to determine vulnerability severity for a bug bounty submission?

The best way to determine vulnerability severity is using a dedicated severity decision guide. By combining impact assessment guidelines with CVSS scoring, you can accurately evaluate the vulnerability's real-world impact and assign an appropriate severity rating.