report-writing

Standardize vulnerability reports with structured sections and CVSS scoring.

Updated May 31, 2026
One-click install
npx skills add https://github.com/grivera82/pi-bughunter --skill report-writing-grivera82
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/grivera82/pi-bughunter/tree/main/skills/report-writing
Command: npx skills add https://github.com/grivera82/pi-bughunter --skill report-writing-grivera82

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug-bounty reports often suffer from inconsistent structure and unclear language. This skill provides standardized templates and guidance to craft clear, evidence-backed submissions that triagers can act on quickly.

Core Features & Use Cases

  • Templates & structure: Platform-compliant report sections (Summary, Vulnerability Details, Steps to Reproduce, Impact, Remediation) for HackerOne, Bugcrowd, Intigriti, Immunefi.
  • Impact-first writing rules: Encourages precise, actionable language to avoid vague claims.
  • CVSS scoring & formatting: Includes CVSS 3.1 guidance, title formulas, and pre-submit checklists.
  • Governance & downgrades: Guidance on risk framing and escalation when appropriate.

Quick Start

Provide a complete, submission-ready vulnerability report using the templates in this skill.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a bug bounty report for triage and submission?

To structure a bug bounty report for triage, include standardized sections: title, summary, vulnerability details, reproduction steps, impact, remediation, and CVSS scoring. This structured output ensures triagers can quickly understand and act on your findings.

What is the best way to write impact and remediation sections for vulnerability reports?

The best way to write impact and remediation sections for vulnerability reports is using impact-first writing rules. This encourages precise, actionable language to avoid vague claims, ensuring your submission clearly communicates the risk and suggested fixes.

Does this report-writing approach work for HackerOne, Bugcrowd, and Intigriti submissions?

Yes, this report-writing approach works for HackerOne, Bugcrowd, Intigriti, and Immunefi submissions. It provides platform-compliant report sections tailored to the specific requirements of multiple bug-bounty programs.

How do I calculate and format CVSS scores for a vulnerability submission?

To calculate and format CVSS scores for a vulnerability submission, apply the included CVSS 3.1 guidance. This provides specific formatting rules and title formulas to ensure your scoring is accurate and consistently presented.

What should be included in a pre-submit checklist for bug bounty reports?

A pre-submit checklist for bug bounty reports should verify that all standardized sections are complete, impact-first language is used, and CVSS 3.1 scoring is accurate. This ensures your writeup is evidence-backed and ready for triage.

How do I handle risk framing and escalation for downgraded vulnerability reports?

To handle risk framing and escalation for downgraded vulnerability reports, follow the provided governance guidance. This helps you appropriately frame the risk and escalate the issue when necessary during the triage process.