What problem does it solve?
Bug bounty researchers often face triage delays or report rejections due to vague language, poor structure, and weak impact statements that fail to convince triagers of a vulnerability's real-world risk.
Core Features & Use Cases
- Platform-Specific Templates: Pre-built structures for HackerOne, Bugcrowd, Intigriti, and Immunefi that match each platform's triager expectations.
- Impact-First Writing Guidelines: Rules to eliminate theoretical language, enforce concrete proof of impact, and structure reports to highlight risk in the first 15 seconds of review.
- Scoring & Severity Tools: CVSS 3.1/4.0 quick reference, severity decision guides, and downgrade counters to push back against unfair severity reductions.
- Use Case: If you find an IDOR vulnerability exposing user PII, this skill guides you to write a report with exact reproduction steps, quantified mass impact, and a concrete fix to maximize payout speed and reduce back-and-forth.
Quick Start
Use the report-writing skill to draft a structured HackerOne report for the IDOR vulnerability you discovered on the /api/users/{id}/orders endpoint that exposes full user order history and PII to any authenticated attacker.