Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus.

No licenceAuto-check passedSecurity

Install Write Report

skills CLI
$ npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill write-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bugbountywithmarco/bugbounty-disclosed-reports write-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bugbountywithmarco/bugbounty-disclosed-reports.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/write-report .claude/skills/write-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
write-report
GitHub stars
122
Token cost
~585 tokens
SKILL.md length
147 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
None found

At a glance

Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus.

  • Works in 3 steps: Collect the finding details from the… → Find a style/structure exemplar. Pull… → Write the report in this structure…
  • The user has a vulnerability and wants it written up — write a report for this
  • SKILL.md covers Workflow and Rules
  • Calls python3

What it does

Write Report is an agent skill from bugbountywithmarco/bugbounty-disclosed-reports. Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus. Use when the user has a vulnerability and wants it written up — "write a report for this", "draft a HackerOne submission", "turn this finding into a report". Produces title, summary, steps to reproduce, impact, severity, and remediation, few-shot styled on real disclosed reports.

Its SKILL.md is about 590 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Bug bounty, Prompt engineering and Report writing. The repository describes itself as: Public Disclosed Bug Bounty Reports formated in markdown.

When your agent uses it

  • The user has a vulnerability and wants it written up — write a report for this
  • Draft a HackerOne submission
  • Turn this finding into a report

Example prompts

  • “write a report for this”
  • “draft a HackerOne submission”
  • “turn this finding into a report”
  • “/write-report”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Collect the finding details from the user / conversation: target asset, vuln
  2. Find a style/structure exemplar. Pull 2–3 strong same-class reports to match
  3. Write the report in this structure (Markdown)

What it can do on your machine

Read from SKILL.md and the folder at commit b6c76d1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Write Report loads about 585 tokens when it runs. Until then it costs about 105 tokens; SKILL.md has 147 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~585

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 147 words (~585 tokens).

“Draft a clear, triager-friendly bug bounty report that matches the structure of the disclosed reports in reports/.”

— opening of SKILL.md by bugbountywithmarco
name
write-report

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .claude/skills/write-report of bugbountywithmarco/bugbounty-disclosed-reports.

Open the folder on GitHubat commit b6c76d1

Compare with similar skills

Write Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Write Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Write Report this skillbugbountywithmarco/bugbounty-disclosed-reports122—~585Automated safety check: PassNone
Web3 Triage and Report Examplestradecatlabs/vibe-coding-cn17k2 repos~7.7kAutomated safety check: PassMIT
Bug Bounty Report Writingawarexone/Agentic-Bug-Hunter5.3k2 repos~3.9kAutomated safety check: PassMIT
Report Writingsickn33/agentic-awesome-skills47k1 repos~3.2kAutomated safety check: PassMIT
Bugcrowd Reportingsickn33/agentic-awesome-skills47k1 repos~5.9kAutomated safety check: PassMIT
Report Writingelementalsouls/Claude-BugHunter4.8k—~5.2kAutomated safety check: PassMIT

Similar skills

  • Web3 Triage and Report Examples

    tradecatlabs/vibe-coding-cn

    Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting.

    17k GitHub starsUsed in 2 repos~7.7k tokens
    SecurityAuto-check passed
  • Bug Bounty Report Writing

    awarexone/Agentic-Bug-Hunter

    Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.

    5.3k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check passed
  • Report Writing

    sickn33/agentic-awesome-skills

    Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi

    47k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check passed
  • Bugcrowd Reporting

    sickn33/agentic-awesome-skills

    Bugcrowd-specific reporting tactics complementing report-writing

    47k GitHub starsUsed in 1 repo~5.9k tokens
    SecurityAuto-check passed
  • Report Writing

    elementalsouls/Claude-BugHunter

    Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity…

    4.8k GitHub stars~5.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed

More from bugbountywithmarco/bugbounty-disclosed-reports

  • Program Intel

    bugbountywithmarco/bugbounty-disclosed-reports

    Summarize the historical bug patterns for a specific bug bounty program/team using the local disclosed-report corpus.

    122 GitHub stars~524 tokensUpdated 2 mo ago
    Auto-check passed
  • Recon Playbook

    bugbountywithmarco/bugbounty-disclosed-reports

    Build a hunting checklist / methodology for a vulnerability class or target tech stack, distilled from the local disclosed-report corpus.

    122 GitHub stars~550 tokensUpdated 2 mo ago
    Auto-check passed
  • Severity

    bugbountywithmarco/bugbounty-disclosed-reports

    Estimate the severity of a vulnerability finding and produce a CVSS 3.1 vector + impact framing, calibrated against how similar findings were rated in the local disclosed-report corpus.

    122 GitHub stars~478 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Write Report

What does Write Report do?

Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus. Write Report is an agent skill from bugbountywithmarco/bugbounty-disclosed-reports. Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus.

When should I use Write Report?

Write Report fits situations like: the user has a vulnerability and wants it written up — write a report for this; draft a HackerOne submission; turn this finding into a report.

How do I install Write Report in Claude Code?

Run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill write-report -a claude-code`. Or copy the skill folder (.claude/skills/write-report in bugbountywithmarco/bugbounty-disclosed-reports) into .claude/skills/write-report in your project. Claude Code loads it when a task matches its description.

How do I install Write Report in Codex?

Run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill write-report -a codex`. Or copy the skill folder (.claude/skills/write-report in bugbountywithmarco/bugbounty-disclosed-reports) into .agents/skills/write-report in your project. Codex loads it when a task matches its description.

Can I use Write Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bugbountywithmarco/bugbounty-disclosed-reports --skill write-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/write-report, .gemini/skills/write-report, .github/skills/write-report and .opencode/skills/write-report in your project.

What does Write Report need to run?

Going by SKILL.md and its folder, Write Report needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Write Report access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Write Report safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Write Report use?

No licence was found for Write Report or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Write Report use?

About 585 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Write Report?

Skills that share tags, products or a category with Write Report: Web3 Triage and Report Examples (tradecatlabs/vibe-coding-cn, 17k stars), Bug Bounty Report Writing (awarexone/Agentic-Bug-Hunter, 5.3k stars), Report Writing (sickn33/agentic-awesome-skills, 47k stars) and Bugcrowd Reporting (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Write Report?

bugbountywithmarco (a GitHub user) maintains it in bugbountywithmarco/bugbounty-disclosed-reports, which has 122 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on July 14, 2026.

Source: bugbountywithmarco/bugbounty-disclosed-reports on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.