report-writing

Create standardized vulnerability reports for HackerOne, Bugcrowd, Intigriti, and Immunefi.

1|1|Updated Mar 24, 2026
One-click install
npx skills add https://github.com/guib1/red-team-docker --skill report-writing-guib1
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/guib1/red-team-docker/tree/main/pentest-lab/.agents/skills/bug-bounty/skills/report-writing
Command: npx skills add https://github.com/guib1/red-team-docker --skill report-writing-guib1

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty programs demand clear, structured vulnerability reports. This skill provides templates, tone guidance, scoring conventions, and pre-submit checklists to produce high-quality submissions for programs like HackerOne, Bugcrowd, Intigriti, and Immunefi.

Core Features & Use Cases

  • Standardized templates for vulnerability reports across major bug bounty programs
  • Impact-first writing guidance, human-tone guidelines, and downgrade counters
  • Title formulas, impact statements, CVSS scoring, severity guidance, and pre-submit checklists
  • Use Case: Convert validated findings into publication-ready reports that maximize acceptance and payouts

Quick Start

Draft a complete bug-bounty report for a validated finding using the provided templates and guidelines.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty vulnerability report that gets accepted?▼

A bug bounty vulnerability report gets accepted when it uses impact-first writing, precise reproduction steps, and correct CVSS severity scoring. Standardized templates conform to program-specific requirements, ensuring clarity and reproducibility for timely submission.

What is the best way to format a HackerOne or Bugcrowd vulnerability report?▼

The best way to format a HackerOne or Bugcrowd vulnerability report is using standardized templates with structured title formulas, clear impact statements, and accurate CVSS scoring. This conforms to program-specific checklists to maximize acceptance and payouts.

Does this report-writing approach work for all major bug bounty programs?▼

Yes, this report-writing approach works for major bug bounty programs including HackerOne, Bugcrowd, Intigriti, and Immunefi. It applies standardized templates and language guidelines across diverse vulnerability classes to ensure publication-ready submissions.

How do I calculate and include CVSS severity scoring in a vulnerability report?▼

To calculate and include CVSS severity scoring in a vulnerability report, apply the provided scoring conventions and severity guidance templates. These standardized rules ensure accurate impact-first reporting that aligns with bug bounty program requirements.

Why does my bug bounty submission keep getting downgraded or rejected?▼

Bug bounty submissions get downgraded or rejected when reports lack clear impact statements, precise reproduction steps, or correct CVSS scoring. Using pre-submit checklists and standardized templates ensures publication-ready reports that maximize acceptance.