report-writing

Generate bug bounty reports with impact-first language and CVSS scoring templates.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/venkatas/obsidian --skill report-writing-venkatas
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: report-writing
Source: https://github.com/venkatas/obsidian/tree/main/skills/report-writing
Command: npx skills add https://github.com/venkatas/obsidian --skill report-writing-venkatas

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Bug bounty programs often suffer from inconsistent reporting, delays, and ambiguity. This Skill provides templates, tone guidelines, scoring methods, and pre-submit checklists to help researchers craft clear, impact-focused reports that maximize triage efficiency.

Core Features & Use Cases

  • Templates for HackerOne, Bugcrowd, Intigriti, and Immunefi reports.
  • Impact-first language guidelines, CVSS 3.1 scoring, and a clear severity framework.
  • Downgrade counters and a comprehensive pre-submit checklist to accelerate approvals.

Quick Start

Draft a concise, impact-first vulnerability report using the provided templates and ensure it validates with a demonstration or PoC.

Frequently Asked Questions about report-writing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a bug bounty report that passes triage quickly?▼

A bug bounty report passes triage faster when it uses impact-first language, explicit steps to reproduce, PoC evidence, and a pre-submit checklist to eliminate ambiguity and accelerate validation.

What is CVSS 3.1 scoring and how does it affect vulnerability severity?▼

CVSS 3.1 scoring calculates vulnerability severity using a standardized framework. It determines triage priority by providing objective metrics to justify impact ratings and counter downgrade disputes.

Does this report-writing approach work for HackerOne, Bugcrowd, and Immunefi programs?▼

Yes, this approach applies platform-specific templates and structured narratives for HackerOne, Bugcrowd, Intigriti, and Immunefi programs to validate findings and ensure compliance before submission.

How do I format a proof-of-concept for a vulnerability report?▼

Format a proof-of-concept by providing explicit steps to reproduce, evidence-driven guidance, and a structured narrative demonstrating the vulnerability's actual impact to the triage team.

Why does my bug bounty report keep getting downgraded?▼

Bug bounty reports get downgraded due to ambiguous impact statements or missing evidence. Applying impact-first language, CVSS 3.1 scoring, and downgrade counters helps justify the original severity rating.

What should be included in a vulnerability report pre-submit checklist?▼

A vulnerability report pre-submit checklist includes verified steps to reproduce, a validated proof-of-concept, accurate CVSS 3.1 scoring, impact-first language, and a clear remediation path.