bugcrowd-reporting

Map vulnerabilities to VRT categories and adjust Bugcrowd report severities.

Updated Jun 24, 2026
One-click install
npx skills add https://github.com/Skobyn/talon --skill bugcrowd-reporting-skobyn
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: bugcrowd-reporting
Source: https://github.com/Skobyn/talon/tree/main/skills/bugcrowd-reporting
Command: npx skills add https://github.com/Skobyn/talon --skill bugcrowd-reporting-skobyn

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires , and includes scripts (resource) and references (resource) components.

What problem does it solve?

Bugcrowd reporting often faces challenges due to platform-specific rules and requirements. This Skill streamlines and improves Bugcrowd report quality and outcomes by offering precise mapping to VRT, effective severity overriding, OOS-clause rebuttals, chained finding cross-referencing, target selection for QA vs. prod programs, and more.

Core Features & Use Cases

  • VRT Mapping and Search Strategy: Precisely select the highest-severity match from VRT, offering fallback strategies if an exact match doesn't exist.
  • Manual Severity Override: Manually adjust technical severity when the VRT default underrates the impact.
  • OOS-Clause Rebuttals: Templates to preemptively handle triager closures with Out-of-Scope or downgraded severity claims.
  • Chained Findings Strategy: Efficiently file complex, multi-part security vulnerabilities across chained findings.
  • Target Selection for QA/Prod: Distinguishing testing environments accurately.
  • Researcher-Side Hygiene: Guidelines to maintain a professional demeanor while submitting Bugcrowd reports.

Quick Start

To start filing a Bugcrowd submission using the bugcrowd-reporting skill, describe your test and request evaluation. Example: "Evaluate Bugcrowd submission #XXXXXX using bugcrowd-reporting."

Frequently Asked Questions about bugcrowd-reporting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map vulnerability findings to the correct Bugcrowd VRT category?▼

Bugcrowd VRT mapping is performed by precisely selecting the highest-severity category match, with fallback strategies provided if an exact match does not exist for your vulnerability analysis.

What is the best way to handle out-of-scope closures in Bugcrowd reports?▼

Handling out-of-scope closures involves using OOS-clause rebuttal templates to preemptively address triager closures and downgraded severity claims in your Bugcrowd submission.

Can I manually adjust severity ratings when the Bugcrowd VRT default underrates impact?▼

Manual severity override allows you to adjust technical severity when the Bugcrowd VRT default underrates the actual impact of your security research findings.

How do I file chained findings across multi-part security vulnerabilities on Bugcrowd?▼

Filing chained findings requires cross-referencing complex, multi-part security vulnerabilities efficiently to ensure the full impact is understood during Bugcrowd triage.

Does Bugcrowd reporting distinguish between QA and production testing environments?▼

Bugcrowd reporting includes target selection strategies to accurately distinguish between QA and production testing environments for your security research submissions.