report-writing

Convert vulnerability findings into standardized reports for bug bounty platforms.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/chatbotkit/rook --skill report-writing-chatbotkit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/chatbotkit/rook/tree/main/skills/report-writing
Command: npx skills add https://github.com/chatbotkit/rook --skill report-writing-chatbotkit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty programs and security teams rely on precise, standardized reports to communicate risk, justify fixes, and accelerate impact. This skill provides structured templates, tone guidelines, and best practices to ensure reports are clear, credible, and submission-ready.

Core Features & Use Cases

  • Templated report generation for HackerOne, Bugcrowd, Intigriti, Immunefi.
  • Impact-first language guidelines and tone coaching to improve clarity, reduce ambiguity, and increase triage speed.
  • Comprehensive sections: vulnerability description, reproduction steps, impact assessment, CVSS framing, remediation guidance, and evidence handling.

Quick Start

Provide a validated finding and let the skill generate a standardized report using the chosen template.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for HackerOne or Bugcrowd?

To write a bug bounty report for HackerOne or Bugcrowd, structure your findings with vulnerability descriptions, reproduction steps, impact assessments, CVSS framing, and remediation guidance. This skill applies platform-specific templates to ensure your report meets triage requirements and passes template checks.

What is the standard format for a vulnerability report submission?

The standard format for a vulnerability report includes exact reproduction steps, affected assets, CVSS scoring guidance, downgrade options, and evidence requirements. Applying a standardized template ensures your submission is clear, credible, and satisfies platform-specific triage checks for quick investigation.

How do I improve my security report to speed up triage?

Improve your security report to speed up triage by using impact-first language and following tone guidelines that reduce ambiguity. Structured templates with clear vulnerability descriptions and exact reproduction steps help investigators quickly validate findings and assess risk.

Does this report-writing skill work with Intigriti and Immunefi programs?

Yes, this report-writing skill works with Intigriti and Immunefi programs. It provides templated report generation across multiple bug bounty platforms, ensuring consistent formatting, CVSS framing, and evidence handling that meet each platform's specific submission and template compliance checks.

What should I include in a bug bounty report for compliance?

For compliance, a bug bounty report should include exact steps to reproduce, affected assets, CVSS scoring guidance, downgrade options, and evidence requirements. Using structured templates ensures all mandatory compliance sections are present and formatted for platform-ready submission.

How do I add CVSS scoring and remediation guidance to a security report?

Add CVSS scoring and remediation guidance to a security report by applying a standardized template that includes dedicated sections for vulnerability impact assessment and fix recommendations. This ensures your report provides clear downgrade options and satisfies platform template checks.