report-writing

Convert validated security findings into submission-ready bug bounty reports.

2|Updated Apr 11, 2025
One-click install
npx skills add https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda --skill report-writing-carlos-reyes-utp
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda/tree/main/.agent/skills/report-writing
Command: npx skills add https://github.com/Carlos-Reyes-UTP/Desarrollo-de-Sistema-de-Ventas-Empresas-de-Moda --skill report-writing-carlos-reyes-utp

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you produce clear, triager-friendly vulnerability reports with impact-first writing and platform-appropriate templates, so your findings are understood quickly and evaluated on evidence instead of theory.

Core Features & Use Cases

  • Impact-first report structure: Generates human-tone summaries, title formulas, and severity framing that lead with what an attacker can do and why it matters.
  • Platform-specific templates: Provides HackerOne, Bugcrowd, Intigriti, and Immunefi report bodies so the submission matches each program’s expectations and fields.
  • Scoring and quality guardrails: Guides CVSS 3.1 quick scoring, severity decision logic, downgrade counters, and a pre-submit checklist that prevents vague or qualifying language.

Quick Start

Use the report-writing skill to draft a complete submission for HackerOne, Bugcrowd, Intigriti, or Immunefi after you have validated a finding and captured the exact reproduction request/response evidence.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that gets accepted on HackerOne?▼

Write a bug bounty report using impact-first human language and a triager-optimized structure that leads with what an attacker can do. Use platform-specific HackerOne templates with copy-paste reproduction steps and evidence placeholders for consistent evaluation.

What is the best way to format vulnerability reports for Bugcrowd and Intigriti?▼

Format vulnerability reports using platform-specific templates tailored for Bugcrowd and Intigriti expectations. Apply impact-first summaries, title formulas, and CVSS 3.1 severity decisioning to match each program's required fields and evaluation criteria.

How do I calculate CVSS 3.1 scores for security triage submissions?▼

Calculate CVSS 3.1 scores for security triage submissions using built-in quick scoring guidance and severity decision logic. This includes downgrade counters and pre-submit quality checks to prevent vague or qualifying phrasing in the final report.

Does this bug bounty report writing approach work for Immunefi submissions?▼

Yes, the bug bounty report writing approach works for Immunefi submissions by providing platform-specific template sections. It generates submission-ready bodies that align with Immunefi's evaluation fields and impact-first framing requirements.

Why do my bug bounty reports get downgraded or rejected during triage?▼

Bug bounty reports get downgraded when they use qualifying phrasing, lack clear reproduction steps, or miss evidence placeholders. Apply pre-submit quality checks, impact-first summaries, and CVSS 3.1 severity framing to ensure triagers evaluate evidence instead of theory.