writing-vdp-and-coordinated-disclosure

Draft vulnerability disclosure policies and coordinated-disclosure materials with RFC 9116 security.txt output.

2|Updated May 23, 2026
One-click install
npx skills add https://github.com/rocklambros/rcs --skill writing-vdp-and-coordinated-disclosure
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: writing-vdp-and-coordinated-disclosure
Source: https://github.com/rocklambros/rcs/tree/main/skills/security/writing-vdp-and-coordinated-disclosure
Command: npx skills add https://github.com/rocklambros/rcs --skill writing-vdp-and-coordinated-disclosure

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps organizations publish a defensible public vulnerability disclosure policy and response process when researchers need a clear place to report bugs.

Core Features & Use Cases

  • Drafts a VDP page with scope, safe harbor, submission channels, response SLAs, severity rubric, and credit policy.
  • Produces a coordinated-disclosure runbook and security.txt pointer for SaaS, APIs, mobile apps, hardware, and bug-bounty-adjacent programs.
  • Refuses to create a public-facing VDP for purely internal tools and redirects to internal reporting channels instead.

Quick Start

Ask for a public VDP package for your externally shipped product, including scope, safe harbor, the reporting channel, SLAs, coordinated-disclosure timing, and a security.txt record.

Frequently Asked Questions about writing-vdp-and-coordinated-disclosure

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I draft a vulnerability disclosure policy for a SaaS application?

Draft a public vulnerability disclosure policy by defining explicit scope lists, verified submission channels, response SLAs, and a severity rubric. The policy package also includes counsel-reviewable safe-harbor language and a coordinated disclosure runbook tailored for SaaS APIs and mobile apps.

What should be included in a coordinated disclosure runbook for external products?

A coordinated disclosure runbook must include explicit scope lists, embargo and credit policies, response SLAs, and severity rubrics. It defines the intake process for externally shipped products like SaaS, APIs, mobile apps, or hardware, ensuring researchers have a clear reporting channel.

How do I set up a security.txt file for bug bounty submissions?

Generate an RFC 9116 compliant security.txt record to point researchers to your verified submission channels. This file acts as a pointer alongside your public vulnerability disclosure policy, defining scope and safe-harbor language for bug bounty adjacent programs.

Can I create a public vulnerability disclosure policy for internal tools?

You cannot create a public vulnerability disclosure policy for purely internal tools. The process explicitly refuses public-facing VDPs for internal systems and instead redirects security reporting to internal channels to prevent exposing sensitive infrastructure.

What is safe harbor language in a bug bounty program?

Safe harbor language in a vulnerability disclosure policy protects security researchers from legal action when they follow the defined scope and submission rules. It is designed to be counsel-reviewable, ensuring organizations provide clear legal protections for compliant bug reporting.

How do I define severity rubrics and SLAs for a VDP?

Define severity rubrics and SLAs within the vulnerability disclosure policy by establishing clear response timelines based on vulnerability impact. The VDP package integrates these rubrics directly with the coordinated disclosure runbook to standardize handling across SaaS, APIs, and hardware.