report-writing

Write impact-first bug bounty reports for HackerOne, Bugcrowd, Intigriti, and Immunefi.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill report-writing-uphiago
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/report-writing
Command: npx skills add https://github.com/uphiago/recon-skills --skill report-writing-uphiago

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty researchers often face triage delays or report rejections due to vague language, poor structure, and weak impact statements that fail to convince triagers of a vulnerability's real-world risk.

Core Features & Use Cases

  • Platform-Specific Templates: Pre-built structures for HackerOne, Bugcrowd, Intigriti, and Immunefi that match each platform's triager expectations.
  • Impact-First Writing Guidelines: Rules to eliminate theoretical language, enforce concrete proof of impact, and structure reports to highlight risk in the first 15 seconds of review.
  • Scoring & Severity Tools: CVSS 3.1/4.0 quick reference, severity decision guides, and downgrade counters to push back against unfair severity reductions.
  • Use Case: If you find an IDOR vulnerability exposing user PII, this skill guides you to write a report with exact reproduction steps, quantified mass impact, and a concrete fix to maximize payout speed and reduce back-and-forth.

Quick Start

Use the report-writing skill to draft a structured HackerOne report for the IDOR vulnerability you discovered on the /api/users/{id}/orders endpoint that exposes full user order history and PII to any authenticated attacker.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that avoids triage delays?

To prevent bug bounty report rejections, eliminate vague language and theoretical risk statements, replacing them with concrete proof of impact, exact reproduction steps, and severity justification frameworks that triagers can quickly verify across platforms like HackerOne, Bugcrowd, Intigriti, and Immunefi.

How do I calculate CVSS 3.1 and 4.0 scores for vulnerability disclosures?

Calculate CVSS 3.1 and 4.0 scores for vulnerability disclosures using quick reference guides and severity decision frameworks to justify your rating. This ensures accurate severity assignment and provides structured arguments to counter unfair severity downgrades during triage.

Does this report writing approach support HackerOne, Bugcrowd, Intigriti, and Immunefi?

Yes, this report writing approach supports HackerOne, Bugcrowd, Intigriti, and Immunefi by providing platform-specific templates. These pre-built structures match each platform's unique triager expectations for reproducible, high-quality vulnerability submissions across all common vulnerability classes.

What is the best way to structure an IDOR vulnerability report for fast triage?

The best way to structure an IDOR vulnerability report for fast triage is to highlight real-world risk within the first 15 seconds of review. Include exact reproduction steps, quantified mass impact for exposed PII, and a concrete fix to maximize payout speed and reduce triager back-and-forth.

How do I push back against unfair severity reductions on my bug bounty submissions?

Push back against unfair severity reductions on bug bounty submissions by using built-in downgrade counters and severity justification frameworks. These tools help you present concrete proof of impact and standardized CVSS scoring evidence to defend your original severity assessment during triage.