report-writing

Generate standardized bug bounty reports with CVSS 3.1 scoring for HackerOne, Bugcrowd, Intigriti, and Immunefi.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill report-writing-sseshachala
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/sseshachala/Claude-BugHunter-archive/tree/main/skills/report-writing
Command: npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill report-writing-sseshachala

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty report writing streamlines creating consistent, impact-focused reports across platforms by providing templates, tone guidance, and scoring guidance to accelerate submission and reduce rework.

Core Features & Use Cases

  • Templates for major platforms: HackerOne, Bugcrowd, Intigriti, Immunefi report structures with standardized sections.
  • Impact-first writing guidelines: Emphasize concrete impact and avoid speculative language.
  • CVSS and severity guidance: Provide scoring and downgrade counters to align with program requirements.
  • Pre-submit checklists: Ensure completeness and evidence hygiene before submission.

Quick Start

Provide a completed bug bounty report outline for a given finding by applying the templates and guidelines described, including CVSS scoring and title formula.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a standardized bug bounty report for HackerOne or Bugcrowd?

To write a standardized bug bounty report, use pre-built templates for platforms like HackerOne and Bugcrowd that enforce consistent sections, impact-first writing guidelines, and CVSS 3.1 severity scoring to improve triage outcomes.

What is the best way to calculate CVSS 3.1 scores for vulnerability submissions?

Calculating CVSS 3.1 scores for vulnerability submissions is guided by severity scoring rules and downgrade counters, ensuring your bug bounty reports align with specific program requirements and accurately reflect impact.

Does this report-writing approach support Intigriti and Immunefi templates?

Yes, this report-writing approach supports Intigriti and Immunefi by providing standardized report structures tailored to each platform, ensuring consistent quality and formatting across all major bug bounty engagements.

How do I ensure evidence hygiene before submitting a bug bounty report?

To ensure evidence hygiene before submitting a bug bounty report, follow pre-submit checklists that verify completeness, validate impact-first language, and confirm all required documentation and scoring are correctly attached.

Why does my bug bounty report get downgraded during triage?

Bug bounty reports often get downgraded during triage due to speculative language or misaligned severity, which impact-first writing guidelines and CVSS downgrade counters are designed to prevent by emphasizing concrete impact.

Can I use a title formula to standardize vulnerability report titles?

Yes, you can use specific title formulae to standardize vulnerability report titles, which helps triage teams quickly identify the issue and aligns the submission with professional bug bounty writing guidelines.