report-writing

Convert validated security findings into submission-ready bug bounty reports.

2|Updated Apr 11, 2025
One-click install
npx skills add https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda --skill report-writing-carlos-reyes-utp
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda/tree/main/.agent/skills/report-writing
Command: npx skills add https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda --skill report-writing-carlos-reyes-utp

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you produce clear, triager-friendly vulnerability reports with impact-first writing and platform-appropriate templates, so your findings are understood quickly and evaluated on evidence instead of theory.

Core Features & Use Cases

  • Impact-first report structure: Generates human-tone summaries, title formulas, and severity framing that lead with what an attacker can do and why it matters.
  • Platform-specific templates: Provides HackerOne, Bugcrowd, Intigriti, and Immunefi report bodies so the submission matches each program’s expectations and fields.
  • Scoring and quality guardrails: Guides CVSS 3.1 quick scoring, severity decision logic, downgrade counters, and a pre-submit checklist that prevents vague or qualifying language.

Quick Start

Use the report-writing skill to draft a complete submission for HackerOne, Bugcrowd, Intigriti, or Immunefi after you have validated a finding and captured the exact reproduction request/response evidence.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that gets accepted on HackerOne?

Write a bug bounty report using impact-first human language and a triager-optimized structure that leads with what an attacker can do. Use platform-specific HackerOne templates with copy-paste reproduction steps and evidence placeholders for consistent evaluation.

What is the best way to format vulnerability reports for Bugcrowd and Intigriti?

Format vulnerability reports using platform-specific templates tailored for Bugcrowd and Intigriti expectations. Apply impact-first summaries, title formulas, and CVSS 3.1 severity decisioning to match each program's required fields and evaluation criteria.

How do I calculate CVSS 3.1 scores for security triage submissions?

Calculate CVSS 3.1 scores for security triage submissions using built-in quick scoring guidance and severity decision logic. This includes downgrade counters and pre-submit quality checks to prevent vague or qualifying phrasing in the final report.

Does this bug bounty report writing approach work for Immunefi submissions?

Yes, the bug bounty report writing approach works for Immunefi submissions by providing platform-specific template sections. It generates submission-ready bodies that align with Immunefi's evaluation fields and impact-first framing requirements.

Why do my bug bounty reports get downgraded or rejected during triage?

Bug bounty reports get downgraded when they use qualifying phrasing, lack clear reproduction steps, or miss evidence placeholders. Apply pre-submit quality checks, impact-first summaries, and CVSS 3.1 severity framing to ensure triagers evaluate evidence instead of theory.