What problem does it solve? Writing bug bounty reports that triagers accept and pay out on is hard: vague titles, theoretical impact claims, and wrong severity ratings get reports closed as N/A or downgraded. This Skill provides proven report templates, scoring formulas, and tone guidelines for HackerOne, Bugcrowd, Intigriti, and Immunefi. ## Core Features & Use Cases - Platform-Specific Templates: Ready-to-use report structures for HackerOne, Bugcrowd, Intigriti, and Immunefi, each matching that platform's triager expectations and severity mechanisms. - CVSS 3.1 and 4.0 Scoring: Quick-reference scoring tables, typical scores by bug class, and a severity decision guide mapping findings to Critical/High/Medium/Low. - Impact-First Writing Rules: Title formulas, downgrade counters for disputing triager pushback, a 60-second pre-submit checklist, and a strict ban on theoretical language like "could potentially". - Use Case: After validating an IDOR finding on a HackerOne program, use this Skill to produce a complete report with a specific title, copy-paste-ready reproduction steps, a justified CVSS score, and a concrete remediation suggestion. ## Quick Start Write a HackerOne report for my validated IDOR finding on the /api/users/{id}/orders endpoint using the report-writing skill.