report-writing

Generate structured security vulnerability reports with CVSS scoring for bug bounty platforms.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill report-writing-entrovyx
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/report-writing
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill report-writing-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill eliminates vague, theoretical, or poorly structured bug reports that lead to rejected submissions or delayed payouts by providing a standardized, impact-driven framework for security researchers.

Core Features & Use Cases

  • Platform-Specific Templates: Includes optimized templates for HackerOne, Bugcrowd, Intigriti, and Immunefi.
  • Impact-First Methodology: Enforces a strict no-theoretical-language policy to ensure triagers immediately understand the severity and business risk.
  • CVSS & Severity Guidance: Provides quick-reference formulas and decision guides to ensure your claimed severity matches the demonstrated impact.

Quick Start

Use the report-writing skill to generate a structured HackerOne report template for an IDOR vulnerability I just validated.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that clearly demonstrates business impact?▼

To write an impact-driven bug bounty report, you must document findings using structured templates and evidence-based impact statements, avoiding theoretical language so triagers immediately understand the demonstrated business risk and severity.

Does this reporting framework support templates for HackerOne and Bugcrowd?▼

Yes, the reporting framework supports platform-specific templates optimized for HackerOne, Bugcrowd, Intigriti, and Immunefi, ensuring your vulnerability submissions meet the distinct formatting and communication standards of each bug bounty platform.

How do I calculate CVSS scores to match the severity of my vulnerability findings?▼

You calculate CVSS scores by applying quick-reference formulas and decision guides provided by the framework, ensuring your claimed severity accurately aligns with the demonstrated impact and complies with platform-specific security reporting requirements.

What is the best way to structure a pentesting report to avoid rejected bug bounty submissions?▼

The best way to structure a pentesting report is through an impact-first methodology that enforces a strict no-theoretical-language policy, standardizing vulnerability documentation with structured templates and evidence to prevent delayed payouts or rejected submissions.

Why does my security vulnerability report get flagged for using theoretical risk language?▼

Security vulnerability reports get flagged because they lack an impact-first methodology, which enforces a strict no-theoretical-language policy to ensure triagers immediately understand the actual business risk rather than speculative security threats.

Can I use this structured reporting approach for an IDOR vulnerability submission?▼

Yes, you can use this structured reporting approach for an IDOR vulnerability by generating a standardized, impact-driven template that documents the finding with appropriate CVSS scoring and professional communication for security triagers.