Estimate the severity of a vulnerability finding and produce a CVSS 3.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus.

No licenceAuto-check passedSecurity

Install Severity

skills CLI
$ npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill severity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bugbountywithmarco/bugbounty-disclosed-reports severity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bugbountywithmarco/bugbounty-disclosed-reports.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/severity .claude/skills/severity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
severity
GitHub stars
122
Token cost
~478 tokens
SKILL.md length
184 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
None found

At a glance

Estimate the severity of a vulnerability finding and produce a CVSS 3.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus.

  • Works in 4 steps: Understand the finding: vuln class,… → Calibrate against precedent. Pull… → Score with CVSS 3.1. Build the vector… → …
  • The user asks how severe is this
  • SKILL.md covers Workflow and Rules
  • Calls python3

What it does

Severity is an agent skill from bugbountywithmarco/bugbounty-disclosed-reports. Estimate the severity of a vulnerability finding and produce a CVSS 3.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus. Use when the user asks "how severe is this", "what CVSS score", "how should I rate this", or needs an impact statement for a report.

Its SKILL.md is about 480 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Public Disclosed Bug Bounty Reports formated in markdown.

When your agent uses it

  • The user asks how severe is this
  • What CVSS score
  • How should I rate this
  • Needs an impact statement for a report

Example prompts

  • “how severe is this”
  • “what CVSS score”
  • “how should I rate this”
  • “/severity”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Understand the finding: vuln class, pre-conditions (auth required? user
  2. Calibrate against precedent. Pull similar reports and see how they were rated
  3. Score with CVSS 3.1. Build the vector explicitly
  4. Output

What it can do on your machine

Read from SKILL.md and the folder at commit b6c76d1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Severity loads about 478 tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 184 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~478

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 184 words (~478 tokens).

“Rate a finding and justify it, anchored to how comparable disclosed reports were scored.”

— opening of SKILL.md by bugbountywithmarco
name
severity

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/severity of bugbountywithmarco/bugbounty-disclosed-reports.

Open the folder on GitHubat commit b6c76d1

Compare with similar skills

Severity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Severity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Severity this skillbugbountywithmarco/bugbounty-disclosed-reports122—~478Automated safety check: PassNone
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from bugbountywithmarco/bugbounty-disclosed-reports

  • Program Intel

    bugbountywithmarco/bugbounty-disclosed-reports

    Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

    122 GitHub stars~524 tokensUpdated 2 mo ago
    Auto-check passed
  • Recon Playbook

    bugbountywithmarco/bugbounty-disclosed-reports

    Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

    122 GitHub stars~550 tokensUpdated 2 mo ago
    Auto-check passed
  • Write Report

    bugbountywithmarco/bugbounty-disclosed-reports

    Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus.

    122 GitHub stars~585 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Severity

What does Severity do?

Estimate the severity of a vulnerability finding and produce a CVSS 3.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus. Severity is an agent skill from bugbountywithmarco/bugbounty-disclosed-reports.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus.

When should I use Severity?

Severity fits situations like: the user asks how severe is this; what CVSS score; how should I rate this; needs an impact statement for a report.

How do I install Severity in Claude Code?

Run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill severity -a claude-code`. Or copy the skill folder (.claude/skills/severity in bugbountywithmarco/bugbounty-disclosed-reports) into .claude/skills/severity in your project. Claude Code loads it when a task matches its description.

How do I install Severity in Codex?

Run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill severity -a codex`. Or copy the skill folder (.claude/skills/severity in bugbountywithmarco/bugbounty-disclosed-reports) into .agents/skills/severity in your project. Codex loads it when a task matches its description.

Can I use Severity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill severity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/severity, .gemini/skills/severity, .github/skills/severity and .opencode/skills/severity in your project.

What does Severity need to run?

Going by SKILL.md and its folder, Severity needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Severity access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Severity safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Severity use?

No licence was found for Severity or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Severity use?

About 478 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Severity?

Skills that share tags, products or a category with Severity: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Severity?

bugbountywithmarco (a GitHub user) maintains it in bugbountywithmarco/bugbounty-disclosed-reports, which has 122 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on July 14, 2026.

Source: bugbountywithmarco/bugbounty-disclosed-reports on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.