researcher-assistant

Organize security engagement details, track findings, and draft vulnerability writeups.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/noname300989/Security-Claw --skill researcher-assistant
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: researcher-assistant
Source: https://github.com/noname300989/Security-Claw/tree/main/skills/researcher-assistant
Command: npx skills add https://github.com/noname300989/Security-Claw --skill researcher-assistant

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the process of managing security engagements and drafting vulnerability writeups, reducing manual organization and writing time.

Core Features & Use Cases

  • Engagement Management: Organizes targets, scope, and findings for bug bounty and penetration testing.
  • Finding Tracking: Logs, updates status, and provides dashboards for discovered vulnerabilities.
  • Writeup Drafting: Auto-populates detailed vulnerability reports with evidence.
  • Use Case: When starting a new bug bounty program, use this Skill to set up the engagement scope, log new findings as you discover them, and then draft a submission-ready writeup for each confirmed vulnerability.

Quick Start

Set up a new engagement for HackerOne program: shopify.com.

Frequently Asked Questions about researcher-assistant

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I organize bug bounty engagement scope and track findings?

Organize bug bounty engagement scope by defining targets, logging discovered vulnerabilities with evidence, and tracking finding statuses. This approach maintains session continuity and generates comprehensive vulnerability reports.

What is the best way to draft vulnerability writeups for penetration testing?

Draft vulnerability writeups by auto-populating detailed reports with logged evidence and engagement details. This ensures submission-ready documentation for penetration testing and bug bounty programs.

Can I use this for managing security research data across multiple sessions?

Yes, you can manage security research data across sessions using structured data storage for engagements and findings. This ensures session continuity and comprehensive reporting throughout the engagement lifecycle.

Does this support setting up a new engagement for a specific bug bounty program?

Yes, it supports setting up new engagements for specific bug bounty programs by organizing target scope, tracking discovered vulnerabilities, and drafting writeups for confirmed findings.

How do I track vulnerability status and evidence during security testing?

Track vulnerability status and evidence by logging findings into a dashboard that updates statuses and stores evidence. This structured tracking ensures comprehensive reporting for security testing engagements.