report-writing

Generate platform-specific security vulnerability reports with CVSS scoring logic.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill report-writing-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/pdparchitect/rook/tree/main/skills/report-writing
Command: npx skills add https://github.com/pdparchitect/rook --skill report-writing-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the problem of inconsistent, vague, or poorly structured security reports that lead to delayed payouts or rejected findings by triagers.

Core Features & Use Cases

  • Standardized Templates: Provides battle-tested templates for HackerOne, Bugcrowd, Intigriti, and Immunefi.
  • Impact-First Writing: Enforces a strict, professional tone that prioritizes clear impact statements over theoretical speculation.
  • CVSS & Severity Guidance: Includes quick-reference calculators and decision guides to ensure your severity claims are grounded in data and platform-specific logic.

Quick Start

Use the report-writing skill to generate a structured HackerOne report template for an IDOR vulnerability found on the user profile endpoint.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that passes triage on HackerOne or Bugcrowd?

To write a bug bounty report that passes triage, use standardized platform templates and enforce evidence-based reporting to eliminate speculative language. This ensures your submission meets rigorous triage standards by prioritizing clear impact statements over theoretical findings.

What is impact-first vulnerability reporting and why does it matter?

Impact-first vulnerability reporting prioritizes clear impact statements over theoretical speculation in security findings. This professional communication style matters because vague or poorly structured reports often lead to delayed payouts or rejected findings by triagers.

How do I calculate CVSS scores for a pentesting report?

You calculate CVSS scores for a pentesting report using quick-reference calculators and decision guides. This ensures your severity claims are grounded in data and platform-specific logic rather than subjective estimates.

Can I use standardized security templates for Intigriti and Immunefi platforms?

Yes, you can use standardized security templates for Intigriti and Immunefi platforms. The skill provides battle-tested, platform-specific templates for these and other major bug bounty platforms to ensure consistent formatting.

What is the best way to structure an IDOR vulnerability report?

The best way to structure an IDOR vulnerability report is using a standardized template that enforces professional tone, evidence-based findings, and accurate CVSS scoring. This impact-first approach ensures technical findings meet rigorous triage standards.

Why does my security vulnerability report keep getting rejected by triagers?

Your security vulnerability report keeps getting rejected due to inconsistent structure, vague descriptions, or theoretical speculation. Eliminating speculative language and enforcing evidence-based reporting with clear impact statements resolves these triage issues.