report-writing

Draft bug bounty reports with program-specific templates and CVSS 3.1 scoring.

1|Updated Apr 18, 2026
One-click install
npx skills add https://github.com/jellaharshith/SWIFT --skill report-writing-jellaharshith
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/jellaharshith/SWIFT/tree/main/swift/skills/cbh/skills/report-writing
Command: npx skills add https://github.com/jellaharshith/SWIFT --skill report-writing-jellaharshith

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates weak, vague, or theoretical vulnerability writeups by enforcing impact-first, human-readable bug bounty reporting standards that triagers can quickly validate and trust.

Core Features & Use Cases

  • Impact-first templates by program: Generates structured report bodies for HackerOne, Bugcrowd, Intigriti, and Immunefi with the right tone and required sections.
  • Evidence-to-claim discipline: Enforces the rule of avoiding qualifying language like "could potentially" and requires proof-aligned statements.
  • Consistent severity & scoring guidance: Provides CVSS 3.1 quick scoring cues, a severity decision guide, and downgrade counters to keep claimed impact aligned with demonstrated results.
  • Triager-optimized structure: Includes title formula guidance, severity-request style patterns, and a 60-second pre-submit checklist to reduce back-and-forth.

Quick Start

Use the report-writing skill after validating a finding, and write your submission with an impact-first summary and a copy-paste-ready reproduction request.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that gets validated quickly on HackerOne or Bugcrowd?

To write a bug bounty report that gets validated quickly, use an impact-first structure with clear reproduction steps, demonstrated impact, and remediation suggestions. Triagers prioritize submissions with explicit, proof-aligned language over theoretical vulnerabilities.

What is the best way to calculate CVSS 3.1 severity for a vulnerability report?

Calculating CVSS 3.1 severity for a vulnerability report requires aligning your score with demonstrated impact. Apply severity decision rules and downgrade counters to ensure your claimed severity matches the actual proof, avoiding inflated scores that cause triager pushback.

Does this report writing approach support submissions for Intigriti and Immunefi?

Yes, this report writing approach supports submissions for Intigriti and Immunefi. It generates structured report bodies with the specific tone and required sections tailored to each program, ensuring your vulnerability writeup meets platform-specific formatting standards.

How do I avoid severity downgrades when submitting bug bounty findings?

To avoid severity downgrades when submitting bug bounty findings, eliminate qualifying language like 'could potentially' and use proof-aligned statements. A pre-submit checklist and enforced impact-first rules keep demonstrated results aligned with your claimed severity.

Why do my bug bounty reports keep getting closed as informational or low severity?

Bug bounty reports often get closed as informational or low severity when they lack demonstrated impact. Drafting submissions with impact-first summaries, explicit proof-aligned reproduction steps, and accurate CVSS 3.1 scoring prevents weak, vague, or theoretical writeups.

What should be included in a triager-friendly bug bounty submission?

A triager-friendly bug bounty submission should include a clear title, impact-first summary, step-by-step reproduction instructions, demonstrated impact, and remediation advice. Applying a 60-second pre-submit checklist reduces back-and-forth by ensuring all required sections are present.