report-writing

Generate bug bounty reports for HackerOne, Bugcrowd, Intigriti, and ImmuniFi platforms.

3|Updated Jul 6, 2026
One-click install
npx skills add https://github.com/hataiit9x/Bbkit-AI --skill report-writing-hataiit9x
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/hataiit9x/Bbkit-AI/tree/main/ref/claude-bug-bounty/skills/report-writing
Command: npx skills add https://github.com/hataiit9x/Bbkit-AI --skill report-writing-hataiit9x

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill simplifies and improves the process of writing detailed bug bounty reports, ensuring a consistent, high-quality output that meets industry standards.

Core Features & Use Cases

  • Structured Report Templates: Offers templates for HackerOne, Bugcrowd, Intigriti, and ImmuniFi platforms.
  • Impact-first Approach: Encourages a clear and concise reporting style, emphasizing the impact of the vulnerability.
  • CVSS Scoring: Provides guidelines and quick reference for assigning CVSS 3.1 and 4.0 scores.
  • Severity Assessment: Offers a decision guide for severity level determination.
  • Human Tone Guidelines: Promotes effective communication with triagers.

Quick Start

Activate the report-writing skill after validating a finding to create a comprehensive report template that adheres to best practices.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for HackerOne and Bugcrowd?

Bug bounty reports for HackerOne and Bugcrowd use structured templates with an impact-first reporting approach to clearly communicate vulnerability analysis and severity. This ensures consistent, high-quality output that meets industry standards.

How does CVSS scoring guidance work for vulnerability analysis?

CVSS scoring guidance provides quick reference metrics for assigning accurate CVSS 3.1 and 4.0 scores during vulnerability analysis. It includes a severity assessment decision guide to help determine the correct impact level of reported bugs.

Can I use this approach for Intigriti and ImmuniFi platforms?

Yes, this approach provides structured report templates specifically designed for Intigriti and ImmuniFi platforms alongside HackerOne and Bugcrowd. It requires no additional software and integrates directly into existing bug bounty workflows.

What is the best way to communicate severity in security reporting?

The best way to communicate severity in security reporting is using an impact-first approach combined with human tone guidelines. This promotes effective communication with triagers by emphasizing the vulnerability's actual impact over technical jargon.

Do I need additional software to generate vulnerability reports?

No, you do not need additional software to generate vulnerability reports. This process operates seamlessly within your existing bug bounty workflows after you have validated a finding and are ready to create a comprehensive report.