report-writing

Generate impact-first bug bounty reports with standardized templates and CVSS 3.1 scoring.

1|Updated Mar 19, 2026
One-click install
npx skills add https://github.com/zer0xhamid/LogicHunter_v2 --skill report-writing-zer0xhamid
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/zer0xhamid/LogicHunter_v2/tree/main/skills/report-writing
Command: npx skills add https://github.com/zer0xhamid/LogicHunter_v2 --skill report-writing-zer0xhamid

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Writing bug bounty reports that are clear, persuasive, and publication-ready is time-consuming and error-prone without a standardized framework. This Skill provides templates, tone guidelines, and a structured approach to produce consistent, high-quality reports for multiple programs.

Core Features & Use Cases

  • Templates for HackerOne, Bugcrowd, Intigriti, Immunefi to ensure consistent structure across programs
  • Guidance on impact-first writing, CVSS 3.1 scoring, title formulas, severity decision guide, and downgrade counters
  • Pre-submit checklist to validate content, evidence, and reproducibility before submission

Quick Start

Draft a complete vulnerability report following the templates and tone guidelines after validating a finding, focusing on precise impact and reproducible steps.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that passes triage on HackerOne or Bugcrowd?

To write a bug bounty report that passes triage, use impact-first templates with strict language rules, CVSS 3.1 scoring, and pre-submit checklists to ensure your findings are reproducible and publish-ready across platforms like HackerOne and Bugcrowd.

What's the best way to calculate CVSS 3.1 severity for a security report?

The best way to calculate CVSS 3.1 severity for a security report is to use a severity decision guide and downgrade counters, ensuring your impact-first scoring aligns with standardized triage policies before submission.

Does this report-writing approach work for both Bugcrowd and Immunefi submissions?

Yes, this report-writing approach works for Bugcrowd and Immunefi submissions by providing standardized templates and tone guidelines tailored for multiple platforms to ensure consistent structure and clear, actionable triage.

How do I format vulnerability report titles to prevent severity downgrades?

To format vulnerability report titles and prevent severity downgrades, apply standardized title formulas and utilize downgrade policies that enforce strict language rules, ensuring the impact is communicated clearly to triage teams.

What needs to be included in a pre-submit checklist for bug bounty reports?

A pre-submit checklist for bug bounty reports must include validation of required proofs, content accuracy, and reproducible steps, ensuring the final document meets strict language rules and platform standards before submission.

Why do my security reports keep getting closed as informational during triage?

Security reports often get closed as informational during triage if they lack impact-first writing, standardized title formulas, or required proofs, failing to demonstrate clear, reproducible impact to the validation team.