web3-triage-report

Triage smart-contract bug reports and format Immunefi-style vulnerability reports.

121|32|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/shuvonsec/web3-bug-bounty-hunting-ai-skills --skill web3-triage-report
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web3-triage-report
Source: https://github.com/shuvonsec/web3-bug-bounty-hunting-ai-skills/tree/main/web3-triage-report
Command: npx skills add https://github.com/shuvonsec/web3-bug-bounty-hunting-ai-skills --skill web3-triage-report

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams and researchers triage smart-contract bug submissions, validate findings, and produce Immunefi-compliant reports, reducing wasted time and increasing report quality.

Core Features & Use Cases

  • 7-question triage gate: ensures issues are evaluated in a standard, repeatable sequence.
  • Impact & severity guidance: aligns submissions with Immunefi's payout tiers and program scope.
  • Template-driven reporting: provides a structured Immunefi report format and common evidence patterns.
  • Real-world examples: dissects 20 paid bounty cases to illustrate patterns and writing style.
  • Use cases: validate a finding before submission, write an Immunefi report, study real bug examples.

Quick Start

Apply the 7-question triage gate to a suspected bug and draft a complete Immunefi-style report.

Frequently Asked Questions about web3-triage-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write an Immunefi bug bounty report for a smart contract vulnerability?

To write an Immunefi bug bounty report, use a template-driven structure that includes root-cause identification, impact quantification, comparison evidence, and proof of concept guidance. A 7-question triage gate helps validate the smart contract vulnerability before submission.

What is the best way to triage smart contract security findings before submitting a bug bounty?

The best way to triage smart contract security findings is applying a standard 7-question validation gate. This process evaluates the suspected bug's root cause, quantifies its impact against payout tiers, and ensures the finding aligns with the bug bounty program scope.

How do I determine the correct severity level for an Immunefi vulnerability submission?

To determine the correct severity for an Immunefi vulnerability submission, evaluate the finding against Immunefi's payout tiers and program scope. The triage process provides impact and severity guidance to align your smart contract bug report with the correct reward category.

Can I use a structured triage process for internal audit findings and real-world bug submissions?

Yes, you can use a structured triage process for internal audit findings, real-world bug submissions, and case studies. The 7-question validation gate and template-driven reporting format apply to any smart contract vulnerability analysis requiring standardized evaluation and documentation.

How does a 7-question triage gate improve vulnerability report writing?

A 7-question triage gate improves vulnerability report writing by ensuring issues are evaluated in a standard, repeatable sequence. This structured approach guides you from initial validation through a complete report, reducing wasted time and increasing report quality.

What evidence patterns are needed for a compliant Immunefi smart contract vulnerability report?

A compliant Immunefi smart contract vulnerability report requires root-cause identification, impact quantification, comparison evidence, and proof of concept guidance. Reviewing 20 paid bounty case studies illustrates the common evidence patterns and writing style needed for successful submissions.