report-writing

Generate bug bounty reports with impact-first language and CVSS scoring templates.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/venkatas/obsidian --skill report-writing-venkatas
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/venkatas/obsidian/tree/main/skills/report-writing
Command: npx skills add https://github.com/venkatas/obsidian --skill report-writing-venkatas

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty programs often suffer from inconsistent reporting, delays, and ambiguity. This Skill provides templates, tone guidelines, scoring methods, and pre-submit checklists to help researchers craft clear, impact-focused reports that maximize triage efficiency.

Core Features & Use Cases

  • Templates for HackerOne, Bugcrowd, Intigriti, and Immunefi reports.
  • Impact-first language guidelines, CVSS 3.1 scoring, and a clear severity framework.
  • Downgrade counters and a comprehensive pre-submit checklist to accelerate approvals.

Quick Start

Draft a concise, impact-first vulnerability report using the provided templates and ensure it validates with a demonstration or PoC.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that passes triage quickly?

A bug bounty report passes triage faster when it uses impact-first language, explicit steps to reproduce, PoC evidence, and a pre-submit checklist to eliminate ambiguity and accelerate validation.

What is CVSS 3.1 scoring and how does it affect vulnerability severity?

CVSS 3.1 scoring calculates vulnerability severity using a standardized framework. It determines triage priority by providing objective metrics to justify impact ratings and counter downgrade disputes.

Does this report-writing approach work for HackerOne, Bugcrowd, and Immunefi programs?

Yes, this approach applies platform-specific templates and structured narratives for HackerOne, Bugcrowd, Intigriti, and Immunefi programs to validate findings and ensure compliance before submission.

How do I format a proof-of-concept for a vulnerability report?

Format a proof-of-concept by providing explicit steps to reproduce, evidence-driven guidance, and a structured narrative demonstrating the vulnerability's actual impact to the triage team.

Why does my bug bounty report keep getting downgraded?

Bug bounty reports get downgraded due to ambiguous impact statements or missing evidence. Applying impact-first language, CVSS 3.1 scoring, and downgrade counters helps justify the original severity rating.

What should be included in a vulnerability report pre-submit checklist?

A vulnerability report pre-submit checklist includes verified steps to reproduce, a validated proof-of-concept, accurate CVSS 3.1 scoring, impact-first language, and a clear remediation path.