report-writing

Generate impact-first bug bounty reports with CVSS 3.1 scoring and pre-submit checklists.

2|1|Updated Mar 20, 2026
One-click install
npx skills add https://github.com/Mikacr1138/claude-bug-bounty --skill report-writing-mikacr1138
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/Mikacr1138/claude-bug-bounty/tree/main/skills/report-writing
Command: npx skills add https://github.com/Mikacr1138/claude-bug-bounty --skill report-writing-mikacr1138

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.

Core Features & Use Cases

  • Templates & Guidelines: Pre-filled report structures for major programs to ensure consistency and clarity.
  • Severity Scoring & Formulas: Guidance for CVSS 3.1 scoring, title formula, impact statements, and downgrade counters.
  • Pre-submit Checklist: A comprehensive readiness checklist to avoid common submission errors.

Quick Start

Generate a complete, impact-first bug bounty report using the HackerOne template for your latest finding.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report for HackerOne or Bugcrowd?▼

To write a bug bounty report, use pre-filled report templates for major platforms like HackerOne and Bugcrowd to ensure structure, clarity, and consistent impact-first communication.

What is the best way to calculate CVSS 3.1 severity for a vulnerability report?▼

The best way to calculate CVSS 3.1 severity is using dedicated scoring guidance and severity decision guides that help formulate impact statements and apply accurate downgrade counters.

How do I stop my security reports from getting downgraded during triage?▼

To stop security reports from getting downgraded during triage, apply specific downgrade counters, formulate precise titles, and strictly avoid speculative language like 'could potentially'.

Can I use a pre-submit checklist for vulnerability triage on Immunefi?▼

Yes, you can use a comprehensive pre-submit checklist for vulnerability triage on Immunefi to verify findings, avoid common submission errors, and ensure reports are impact-first.

What should I include in an impact statement for a verified security finding?▼

An impact statement for a verified security finding should include a proven, impact-first explanation of the vulnerability using a specific formula, avoiding speculative language entirely.

Does this report-writing approach work for Web3 and smart contract bug bounties?▼

Yes, this report-writing approach works for Web3 bug bounties by applying program-specific templates and severity scoring guidance designed for platforms like Immunefi.