report-writing

Create standardized vulnerability reports for HackerOne, Bugcrowd, Intigriti, and Immunefi.

1|1|Updated Mar 24, 2026
One-click install
npx skills add https://github.com/guib1/red-team-docker --skill report-writing-guib1
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/guib1/red-team-docker/tree/main/pentest-lab/.agents/skills/bug-bounty/skills/report-writing
Command: npx skills add https://github.com/guib1/red-team-docker --skill report-writing-guib1

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty programs demand clear, structured vulnerability reports. This skill provides templates, tone guidance, scoring conventions, and pre-submit checklists to produce high-quality submissions for programs like HackerOne, Bugcrowd, Intigriti, and Immunefi.

Core Features & Use Cases

  • Standardized templates for vulnerability reports across major bug bounty programs
  • Impact-first writing guidance, human-tone guidelines, and downgrade counters
  • Title formulas, impact statements, CVSS scoring, severity guidance, and pre-submit checklists
  • Use Case: Convert validated findings into publication-ready reports that maximize acceptance and payouts

Quick Start

Draft a complete bug-bounty report for a validated finding using the provided templates and guidelines.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty vulnerability report that gets accepted?

A bug bounty vulnerability report gets accepted when it uses impact-first writing, precise reproduction steps, and correct CVSS severity scoring. Standardized templates conform to program-specific requirements, ensuring clarity and reproducibility for timely submission.

What is the best way to format a HackerOne or Bugcrowd vulnerability report?

The best way to format a HackerOne or Bugcrowd vulnerability report is using standardized templates with structured title formulas, clear impact statements, and accurate CVSS scoring. This conforms to program-specific checklists to maximize acceptance and payouts.

Does this report-writing approach work for all major bug bounty programs?

Yes, this report-writing approach works for major bug bounty programs including HackerOne, Bugcrowd, Intigriti, and Immunefi. It applies standardized templates and language guidelines across diverse vulnerability classes to ensure publication-ready submissions.

How do I calculate and include CVSS severity scoring in a vulnerability report?

To calculate and include CVSS severity scoring in a vulnerability report, apply the provided scoring conventions and severity guidance templates. These standardized rules ensure accurate impact-first reporting that aligns with bug bounty program requirements.

Why does my bug bounty submission keep getting downgraded or rejected?

Bug bounty submissions get downgraded or rejected when reports lack clear impact statements, precise reproduction steps, or correct CVSS scoring. Using pre-submit checklists and standardized templates ensures publication-ready reports that maximize acceptance.