report-writing

Generate bug bounty reports with impact statements and CVSS scoring.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill report-writing-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/report-writing
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill report-writing-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill assists in writing bug bounty reports with precision, ensuring findings are presented clearly and persuasively.

Core Features & Use Cases

  • Report Templates: Provides templates for different platforms like HackerOne, Bugcrowd, Intigriti, and Immunefi.
  • Impact-First Writing: Encourages concise, impact-focused report writing to grab attention quickly.
  • CVSS Scoring: Offers guidance on CVSS 3.1 and 4.0 scoring to help assign the correct severity.
  • Severity Decision Guide: Assists in determining the appropriate severity level for reported vulnerabilities.
  • Quick Start: Use the report-writing skill to generate a report for a discovered IDOR vulnerability.

Quick Start

Generate a report for an IDOR finding in the /api/users/{id}/orders endpoint.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for an IDOR vulnerability?

Bug bounty report templates are available for platforms like HackerOne, Bugcrowd, Intigriti, and Immunefi. They provide structured formats to ensure your vulnerability findings meet specific platform requirements and grab triager attention quickly.

How does CVSS scoring work for vulnerability reporting?

CVSS 3.1 and 4.0 scoring guidance helps assign correct severity levels by evaluating vulnerability characteristics. This ensures your security analysis accurately reflects the actual risk and impact of discovered bugs.

What is the best way to structure a vulnerability report for security analysis?

The best way to structure a vulnerability report is using an impact-first approach that highlights clear consequences, structured vulnerability details, and accurate CVSS scoring to present security analysis findings effectively.

Can I use report templates for different bug bounty platforms?

Yes, you can use report templates for different bug bounty platforms including HackerOne, Bugcrowd, Intigriti, and Immunefi. These templates ensure your vulnerability reporting aligns with specific platform requirements.

How do I determine the appropriate severity level for a reported vulnerability?

You determine the appropriate severity level for a reported vulnerability by using a severity decision guide alongside CVSS 3.1 and 4.0 scoring. This evaluates exploitability and impact to assign the correct risk rating.

Related Skills