report-writing

Generate bug bounty reports with templates for HackerOne, Bugcrowd, Intigriti, and Immunefi.

3|Updated Nov 12, 2025
One-click install
npx skills add https://github.com/cmndcntrlcyber/rtpi --skill report-writing-cmndcntrlcyber
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/cmndcntrlcyber/rtpi/tree/main/knowledge_seed/bug_hunter_skills/report-writing
Command: npx skills add https://github.com/cmndcntrlcyber/rtpi --skill report-writing-cmndcntrlcyber

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill streamlines the process of writing detailed bug bounty reports, providing templates and guidelines to ensure clarity, impact, and adherence to best practices.

Core Features & Use Cases

  • Impact-First Writing: Promotes clear and concise reporting that focuses on the impact of vulnerabilities.
  • Structured Templates: Offers standardized templates for HackerOne, Bugcrowd, Intigriti, and Immunefi platforms.
  • CVSS Scoring: Provides a guide for scoring vulnerabilities using CVSS 3.1 and 4.0.
  • Severity Decision Guide: Assists in determining the severity of vulnerabilities based on their impact.
  • Human Tone Guidelines: Offers advice on writing reports in a human tone that resonates with triagers.

Quick Start

Generate a report for a discovered IDOR vulnerability in the '/api/v2/invoices/{id}' endpoint by using the report-writing skill.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for HackerOne or Bugcrowd?

To write a bug bounty report for HackerOne or Bugcrowd, use structured templates that emphasize impact-first writing, ensuring your vulnerability report clearly communicates severity and resonates with triagers.

What is impact-first writing for vulnerability reporting?

Impact-first writing for vulnerability reporting prioritizes the clear communication of a vulnerability's impact, using a human tone and structured guidelines to ensure triagers understand the severity.

How do I score vulnerabilities using CVSS 4.0 for a bug bounty report?

To score vulnerabilities using CVSS 4.0 for a bug bounty report, follow guidelines that assist in calculating the score and determining the severity based on the vulnerability's impact.

Can I use structured templates for Intigriti and Immunefi vulnerability reports?

Yes, you can use structured templates tailored for Intigriti and Immunefi vulnerability reports, which provide standardized formats to ensure clarity and adherence to best practices on these platforms.

What is the best way to determine vulnerability severity for a bug bounty submission?

The best way to determine vulnerability severity for a bug bounty submission is to assess the impact using a severity decision guide alongside CVSS 3.1 and 4.0 scoring methodologies.