report-writing

Generate impact-first bug bounty reports with CVSS 3.1 scoring and pre-submit checklists.

2|1|Updated Mar 20, 2026
One-click install
npx skills add https://github.com/Mikacr1138/claude-bug-bounty --skill report-writing-mikacr1138
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/Mikacr1138/claude-bug-bounty/tree/main/skills/report-writing
Command: npx skills add https://github.com/Mikacr1138/claude-bug-bounty --skill report-writing-mikacr1138

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.

Core Features & Use Cases

  • Templates & Guidelines: Pre-filled report structures for major programs to ensure consistency and clarity.
  • Severity Scoring & Formulas: Guidance for CVSS 3.1 scoring, title formula, impact statements, and downgrade counters.
  • Pre-submit Checklist: A comprehensive readiness checklist to avoid common submission errors.

Quick Start

Generate a complete, impact-first bug bounty report using the HackerOne template for your latest finding.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for HackerOne or Bugcrowd?

To write a bug bounty report, use pre-filled report templates for major platforms like HackerOne and Bugcrowd to ensure structure, clarity, and consistent impact-first communication.

What is the best way to calculate CVSS 3.1 severity for a vulnerability report?

The best way to calculate CVSS 3.1 severity is using dedicated scoring guidance and severity decision guides that help formulate impact statements and apply accurate downgrade counters.

How do I stop my security reports from getting downgraded during triage?

To stop security reports from getting downgraded during triage, apply specific downgrade counters, formulate precise titles, and strictly avoid speculative language like 'could potentially'.

Can I use a pre-submit checklist for vulnerability triage on Immunefi?

Yes, you can use a comprehensive pre-submit checklist for vulnerability triage on Immunefi to verify findings, avoid common submission errors, and ensure reports are impact-first.

What should I include in an impact statement for a verified security finding?

An impact statement for a verified security finding should include a proven, impact-first explanation of the vulnerability using a specific formula, avoiding speculative language entirely.

Does this report-writing approach work for Web3 and smart contract bug bounties?

Yes, this report-writing approach works for Web3 bug bounties by applying program-specific templates and severity scoring guidance designed for platforms like Immunefi.