report-writing

Generate structured security vulnerability reports with CVSS scoring for bug bounty platforms.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill report-writing-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/report-writing
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill report-writing-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill eliminates vague, theoretical, or poorly structured bug reports that lead to rejected submissions or delayed payouts by providing a standardized, impact-driven framework for security researchers.

Core Features & Use Cases

  • Platform-Specific Templates: Includes optimized templates for HackerOne, Bugcrowd, Intigriti, and Immunefi.
  • Impact-First Methodology: Enforces a strict no-theoretical-language policy to ensure triagers immediately understand the severity and business risk.
  • CVSS & Severity Guidance: Provides quick-reference formulas and decision guides to ensure your claimed severity matches the demonstrated impact.

Quick Start

Use the report-writing skill to generate a structured HackerOne report template for an IDOR vulnerability I just validated.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that clearly demonstrates business impact?

To write an impact-driven bug bounty report, you must document findings using structured templates and evidence-based impact statements, avoiding theoretical language so triagers immediately understand the demonstrated business risk and severity.

Does this reporting framework support templates for HackerOne and Bugcrowd?

Yes, the reporting framework supports platform-specific templates optimized for HackerOne, Bugcrowd, Intigriti, and Immunefi, ensuring your vulnerability submissions meet the distinct formatting and communication standards of each bug bounty platform.

How do I calculate CVSS scores to match the severity of my vulnerability findings?

You calculate CVSS scores by applying quick-reference formulas and decision guides provided by the framework, ensuring your claimed severity accurately aligns with the demonstrated impact and complies with platform-specific security reporting requirements.

What is the best way to structure a pentesting report to avoid rejected bug bounty submissions?

The best way to structure a pentesting report is through an impact-first methodology that enforces a strict no-theoretical-language policy, standardizing vulnerability documentation with structured templates and evidence to prevent delayed payouts or rejected submissions.

Why does my security vulnerability report get flagged for using theoretical risk language?

Security vulnerability reports get flagged because they lack an impact-first methodology, which enforces a strict no-theoretical-language policy to ensure triagers immediately understand the actual business risk rather than speculative security threats.

Can I use this structured reporting approach for an IDOR vulnerability submission?

Yes, you can use this structured reporting approach for an IDOR vulnerability by generating a standardized, impact-driven template that documents the finding with appropriate CVSS scoring and professional communication for security triagers.