report-writing

Generate standardized bug bounty vulnerability reports with CVSS scoring.

Updated Jun 23, 2024
One-click install
npx skills add https://github.com/n4igme/randscript --skill report-writing-n4igme
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/n4igme/randscript/tree/main/llm/skills/claude-hunter/skills/report-writing
Command: npx skills add https://github.com/n4igme/randscript --skill report-writing-n4igme

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Vulnerability reports are often inconsistent, lengthy, and hard to action. This skill standardizes writing for bug-bounty submissions, ensuring clear impact statements, repeatable templates, and defensible CVSS scoring.

Core Features & Use Cases

  • Impact-first templates for H1/Bugcrowd/Intigriti/Immunefi submissions.
  • Guidelines for tone and structure to improve triage speed and clarity.
  • Pre-submit checklist and downgrade counters to defend report quality and consistency.

Quick Start

Provide a complete bug bounty report following the templates with clear impact and reproducible steps.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty vulnerability report that gets triaged faster?

Vulnerability reports get triaged faster when they use an impact-first structure with clear reproduction steps and defensible CVSS 3.1 scoring. Standardized templates ensure consistent submission quality across platforms like HackerOne and Bugcrowd.

What is the best way to structure vulnerability reproduction steps for a disclosure report?

The best way to structure vulnerability reproduction steps is using standardized, impact-first templates that enforce clear tone and structure. This ensures your disclosure report is consistent and easy for triage teams to action.

Does this report writing approach work for submissions on platforms like Intigriti and Immunefi?

Yes, this report writing approach applies across major bug bounty programs including Intigriti and Immunefi. It enforces platform-ready templates and pre-submit checklists tailored to ensure consistent submission quality for each platform.

How do I prevent severity downgrades when submitting bug bounty reports?

You can prevent severity downgrades by using pre-submit checklists and downgrade counters to defend your report quality. Establishing defensible CVSS 3.1 scoring and impact-first language strengthens your vulnerability submission against downgrades.

Why are my vulnerability submissions considered inconsistent by bug bounty platforms?

Vulnerability submissions are often inconsistent due to lengthy, unstructured writing that lacks clear impact statements. Applying standardized templates and guidelines for tone ensures your bug bounty reports are consistent and easy to action.