Report Writing
sickn33/agentic-awesome-skills
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity…
$ npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elementalsouls/Claude-BugHunter report-writing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/report-writing .claude/skills/report-writing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "report-writing" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/report-writing into .claude/skills/report-writing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "report-writing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/report-writingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elementalsouls/Claude-BugHunter report-writing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/report-writing .agents/skills/report-writing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "report-writing" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/report-writing into .agents/skills/report-writing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "report-writing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elementalsouls/Claude-BugHunter report-writing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/report-writing .cursor/skills/report-writing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "report-writing" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/report-writing into .cursor/skills/report-writing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "report-writing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elementalsouls/Claude-BugHunter.git --path skills/report-writing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elementalsouls/Claude-BugHunter report-writing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/report-writing .gemini/skills/report-writing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "report-writing" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/report-writing into .gemini/skills/report-writing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "report-writing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elementalsouls/Claude-BugHunter report-writingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/report-writing .github/skills/report-writing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "report-writing" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/report-writing into .github/skills/report-writing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "report-writing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elementalsouls/Claude-BugHunter report-writing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elementalsouls/Claude-BugHunter.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/report-writing .opencode/skills/report-writing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "report-writing" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/report-writing into .opencode/skills/report-writing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "report-writing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
report-writingBug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity…
Report Writing is an agent skill from elementalsouls/Claude-BugHunter. Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Validation gates and the submittability/always-rejected decision are owned by triage-validation; this skill owns the written report itself (templates, tone, formulas). Use after validating a finding and before submitting. Never use "could potentially" — prove it or…
Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Bug bounty and Report writing. The repository describes itself as: A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a04bb83. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
first.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ATTACKER_TOKENACCOUNT_A_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Report Writing loads about 5.2k tokens when it runs. Until then it costs about 137 tokens; SKILL.md has 1,284 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elementalsouls/Claude-BugHunter at commit a04bb83, republished under its MIT licence (© elementalsouls). 1,284 words, ~5,238 tokens.
.claude/skills/report-writing/SKILL.md (or your agent's skills folder).Impact-first. Human tone. No theoretical language. Triagers are people.
Never use "could potentially" or "could be used to" or "may allow". Either it does the thing or it doesn't. If you haven't proved it, don't claim it.
BAD: "This vulnerability could potentially allow an attacker to access user data."
GOOD: "An attacker can access any user's order history by changing the user_id
parameter to the target user's ID. I confirmed this using two test accounts:
attacker@test.com (ID 123) successfully retrieved victim@test.com (ID 456)
orders, including their shipping address and payment method last 4 digits."[Bug Class] in [Exact Endpoint/Feature] allows [attacker role] to [impact] [victim scope]Good titles (specific, impact-first):
IDOR in /api/v2/invoices/{id} allows authenticated user to read any customer's invoice data
Missing auth on POST /api/admin/users allows unauthenticated attacker to create admin accounts
Stored XSS in profile bio field executes in admin panel — allows privilege escalation
SSRF via image import URL parameter reaches AWS EC2 metadata service
Race condition in coupon redemption allows same code to be used unlimited timesBad titles (vague, useless to triager):
IDOR vulnerability found
Broken access control
XSS in user input
Security issue in API
Unauthorized access to user data## Summary
[One paragraph: what the bug is, where it is, what an attacker can do. Be specific.
Include: endpoint, method, parameter, data exposed, required access level.]
Example: "The `/api/users/{user_id}/orders` endpoint does not verify that the
authenticated user owns the requested user_id. An attacker can enumerate any
user's order history, including PII (email, address, phone) and purchase history,
by incrementing the user_id parameter. No privileges beyond a standard free
account are required."
## Vulnerability Details
**Vulnerability Type:** IDOR / Broken Object Level Authorization
**CVSS 3.1 Score:** 6.5 (Medium) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
**Affected Endpoint:** GET /api/users/{user_id}/orders
## Steps to Reproduce
**Environment:**
- Attacker account: attacker@test.com, user_id = 123
- Victim account: victim@test.com, user_id = 456
- Target: https://target.com
**Steps:**
1. Log in as attacker@test.com, obtain Bearer token
2. Send the following request:
GET /api/users/456/orders HTTP/1.1 Host: target.com Authorization: Bearer ATTACKER_TOKEN_HERE
3. Observe response:
```json
{
"orders": [
{"id": 789, "items": [...], "email": "victim@test.com", "address": "123 Main St..."}
]
}The response contains victim's full order history and PII despite being requested by a different user.
An authenticated attacker can enumerate all user orders by iterating user_id values. This exposes: full name, email, shipping address, purchase history, and payment method (last 4). With ~100K users, this represents a mass PII breach affecting all registered users. Exploitation requires only a free account and takes minutes with a simple loop.
Add server-side ownership verification:
if order.user_id != current_user.id:
raise Forbidden()[Screenshot showing attacker's session returning victim's order data] [Video walkthrough if available]
---
## BUGCROWD REPORT TEMPLATE
```markdown
# [IDOR] User order history accessible without authorization via /api/users/{id}/orders
**VRT Category:** Broken Access Control > IDOR > P2
## Description
[Same impact-first paragraph as HackerOne summary]
## Steps to Reproduce
[Same structured steps — exact HTTP requests, exact responses]
## Proof of Concept
[Screenshot/video showing the actual impact]
## Expected vs Actual Behavior
**Expected:** 403 Forbidden when user_id does not match authenticated user
**Actual:** 200 OK with victim's full order data
## Severity Justification
P2 (High) — Direct read access to other users' PII. Affects all user accounts.
No user interaction required. Exploitable by any authenticated user.
Automated enumeration could exfil all [N] user records in minutes.
## Remediation
Add ownership verification: `if order.user_id != current_user.id: raise 403`# [Bug Class]: [Exact Impact] in [Endpoint/Feature]
## Description
[Impact-first paragraph. Start with what an attacker can do, not with how you found it.
Include: endpoint, method, parameter, data exposed, required privileges.]
## Steps to Reproduce
**Environment:**
- Attacker: email=attacker@test.com (standard account, no special role)
- Victim: email=victim@test.com
- Tested: [date]
**Reproduction steps:**
1. [Login as attacker / visit URL / send request]
2. Send the following HTTP request:
\```http
METHOD /endpoint HTTP/1.1
Host: target.com
Authorization: Bearer ATTACKER_TOKEN
Content-Type: application/json
{"param": "victim_id_here"}
\```
3. Observe response contains victim's private data:
\```json
{"email": "victim@test.com", "address": "123 Main St", ...}
\```
## Impact
[Specific, quantified impact. What data, how many users, what can attacker do.]
CVSS 3.1 Score: X.X ([Severity]) — AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
## Remediation
[1-3 sentence concrete fix. Include code if helpful.]
## Attachments
[Screenshot or Loom video showing the impact — Intigriti triagers prefer video for complex bugs]Intigriti-specific notes:
[Bug Class]: [One-line impact] (no formula required, but keep it specific)# [Bug Class] — [Protocol Name] — [Severity]
## Summary
[One paragraph with: root cause, affected function, economic impact, attack cost.
Include numbers where possible: "attacker can drain $X in Y transactions."]
## Vulnerability Details
**Contract:** `VulnerableContract.sol`
**Function:** `claimRedemption()`
**Bug Class:** Accounting State Desynchronization
**Severity:** Critical
### Root Cause
[Exact code snippet showing the vulnerable code with comments]
## Proof of Concept
```solidity
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
// Foundry PoC — run: forge test --match-test test_exploit -vvvv
contract ExploitTest is Test {
// ... full working exploit
}[Quantified: "Attacker can drain X% of TVL = $Y at current rates. Requires $Z gas. Attack is repeatable."]
[Specific code change with before/after]
---
## CVSS 3.1 QUICK SCORING
### FormulaCVSS = f(AV, AC, PR, UI, S, C, I, A)
### Metric Quick Picks
| Metric | Value | Weight | When |
|---|---|---|---|
| **Attack Vector (AV)** | Network | +0.85 | Via internet |
| | Local | +0.55 | Local access needed |
| **Attack Complexity (AC)** | Low | +0.77 | Repeatable |
| | High | +0.44 | Race/timing needed |
| **Privileges Required (PR)** | None | +0.85 | No login |
| | Low | +0.62 | Regular user account |
| | High | +0.27 | Admin account |
| **User Interaction (UI)** | None | +0.85 | No victim action |
| | Required | +0.62 | Victim must click |
| **Scope (S)** | Changed | higher | Affects browser/OS/other |
| | Unchanged | lower | Stays in app |
| **Confidentiality (C)** | High | +0.56 | All data exposed |
| | Low | +0.22 | Limited data |
| **Integrity (I)** | High | +0.56 | Can modify any data |
| **Availability (A)** | High | +0.56 | Crashes service |
### Typical Scores by Bug Class
| Bug | Typical CVSS | Severity |
|---|---|---|
| IDOR (read PII) | 6.5 | Medium |
| IDOR (write/delete) | 7.5 | High |
| Auth bypass → admin | 9.8 | Critical |
| Stored XSS (any user) | 5.4–8.8 | Med–High |
| SQLi (data exfil) | 8.6 | High |
| SSRF (cloud metadata) | 9.1 | Critical |
| Race condition (double spend) | 7.5 | High |
| GraphQL auth bypass | 8.7 | High |
| JWT none algorithm | 9.1 | Critical |
---
## SEVERITY DECISION GUIDE
### Critical (P1)
- Full account takeover of any user without interaction
- Remote code execution
- SQLi with ability to dump/modify entire DB
- Auth bypass to admin panel
- SSRF to cloud metadata → IAM credentials exfil
### High (P2)
- Mass PII exposure (email, phone, SSN, payment data)
- Privilege escalation from user to admin
- SSRF reaching internal services (data returned)
- Stored XSS executing for all users of sensitive feature
- Payment bypass / financial loss without limit
### Medium (P3)
- IDOR on specific user's non-critical data
- XSS on low-sensitivity page requiring victim interaction
- CSRF on important but non-critical action
- Rate limit bypass on OTP (with effort demonstrated)
### Low (P4)
- Information disclosure (non-sensitive, no PII)
- Clickjacking on sensitive action WITH working PoC
- CORS on limited data
---
## SEVERITY SELF-ASSESSMENT
Each YES raises severity:
---
## DOWNGRADE COUNTERS
| Program Says | Counter With |
|---|---|
| "Requires authentication" | "Attacker needs only a free account — no special role or permission" |
| "Limited impact" | "Affects [N] users / exposes [PII type] / $[amount] at risk" |
| "Already known" | "Show me the report number — I searched hacktivity and found none" |
| "By design" | "Show me the documentation stating this is intended behavior" |
| "Low CVSS" | "CVSS doesn't capture business impact — attacker can extract [X] in [Y] minutes" |
| "Not exploitable" | "Here is the exact response showing victim's data returned to attacker session" |
---
## THE 60-SECOND PRE-SUBMIT CHECKLIST
[ ] Title follows formula: [Class] in [endpoint] allows [actor] to [impact] [ ] First sentence states exact impact in plain English [ ] Steps to Reproduce has exact HTTP request (copy-paste ready) [ ] Response showing the bug is included (screenshot or JSON body) [ ] Two test accounts used — not just one account testing itself [ ] CVSS score calculated and included [ ] Recommended fix is 1-2 sentences (not a lecture) [ ] No typos in endpoint paths or parameter names [ ] Report is < 600 words — triagers skim long reports [ ] Severity claimed matches impact described — don't overclaim [ ] Never used "could potentially" or "may allow" [ ] PoC is reproducible by triager from a fresh state
---
## CVSS 4.0 QUICK REFERENCE (newer programs)
CVSS 4.0 replaced CVSS 3.1 in November 2023. Some newer programs require it.
### Key Differences from CVSS 3.1
| Metric | CVSS 3.1 | CVSS 4.0 |
|---|---|---|
| Attack Vector | Network/Adjacent/Local/Physical | Same |
| Attack Complexity | Low/High | Low/High |
| **NEW**: Attack Requirements | (didn't exist) | None/Present (replaces some PR/UI) |
| Privileges Required | None/Low/High | Same |
| User Interaction | None/Required | None/Passive/Active |
| Scope | Unchanged/Changed | REMOVED |
| **NEW**: Sub-Impact metrics | (didn't exist) | Vulnerable/Subsequent system impact |
### CVSS 4.0 Score Examples
| Finding | CVSS 4.0 Score | Vector |
|---|---|---|
| Unauthenticated RCE | 10.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| IDOR read PII, auth required | 6.9 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| Stored XSS, admin views it | 8.2 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
| SSRF → cloud metadata | 8.7 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
### Quick CVSS 4.0 CalculatorUse: https://www.first.org/cvss/calculator/4.0 Key fields: VC/VI/VA = Vulnerable System Confidentiality/Integrity/Availability SC/SI/SA = Subsequent System (downstream impact) AT = None (no special condition) | Present (race/specific config needed) UI = None | Passive (victim visits URL) | Active (victim takes explicit action)
**Practical rule**: If program uses CVSS 4.0 and you don't know the vector, use the calculator and include the full string starting with `CVSS:4.0/AV:...`. Programs cannot dispute a valid vector string.
---
## HUMAN TONE GUIDELINES
**Write to a person, not a system:**
- Triagers are tired. Get to the impact in sentence 1.
- Use "I" not "the researcher" — you found it, own it
- Short paragraphs, bullet points for steps
- Hyperlink relevant docs if needed
**Escalation language (when payout is being downgraded):**"This vulnerability does not require any special privileges — only a free account." "The exposed data includes [PII type], which is subject to GDPR requirements." "An attacker can automate this with a simple loop — all [N] records in minutes." "This is exploitable externally without network access to any internal system." "The impact is equivalent to a full data breach of [feature/data type]."
**Avoid:**
- Jargon the triager might not know
- 5-paragraph explanations of what IDOR is (they know)
- Theoretical chains ("could be combined with X to...")
- Passive voice ("it was observed that...")
- Qualifying language ("seems to," "appears to")
---
## STEPS TO REPRODUCE FORMAT (triager-optimized)
```markdown
**Setup:**
- Account A (attacker): email=attacker@test.com, ID=111
- Account B (victim): email=victim@test.com, ID=222
- Both created via normal registration — no special access
**Steps:**
1. Log in as Account A
2. Send this request (replace `111` with victim ID `222`):
\```
GET /api/v2/resource/222 HTTP/1.1
Host: target.com
Authorization: Bearer ACCOUNT_A_TOKEN
\```
3. Response contains Account B's private data:
\```json
{"id": 222, "email": "victim@test.com", "name": "Victim User", "address": "..."}
\```
**Expected:** 403 Forbidden
**Actual:** 200 OK with victim's private datatriage-validation — When deciding whether to write a report at all. Workflow primitive: NEVER open this skill before triage-validation's 7-Question Gate passes; a finding that fails the gate should be killed, not written up.bugcrowd-reporting — When the target is a Bugcrowd program. Workflow primitive: this skill's body template is the foundation; bugcrowd-reporting overlays VRT selection, severity-request paragraph, OOS-clause rebuttals on top.evidence-hygiene — When PoC screenshots / HARs are being attached to the report. Workflow primitive: every artifact referenced in the "Supporting Materials" / "Proof of Concept" section gets routed through evidence-hygiene for cookie + PII redaction before attachment.redteam-report-template — When the engagement is an external red team (NOT bug bounty). Workflow primitive: confirm engagement mode via bb-methodology PART 0; if red-team, swap this skill out for redteam-report-template (different audience, different structure: Subject / Observations / Description / Impact / Recommendation / PoC).Engagement-derived additions to the vendored foundation. Wisdom from real authorized engagements + Phase 2 verification across this repo's 31+ skill-area live tests. The upstream methodology covers the WHAT; this layer covers the WHEN-IT-ACTUALLY-WORKS and the FAILURE-MODES.
<asset> | <bug class> | <impact> — three components, no fluff. Triagers read titles in roughly three seconds and use them to order the queue.
The bad titles get opened last. The good titles get opened first. Same finding, different queue position, different triage day, different payout speed.
Their reading sequence on a fresh report:
Optimize the top of the report ruthlessly. Save narrative for the middle. Triagers who are convinced by step 3 will rubber-stamp the rest; triagers who aren't convinced by step 3 won't read step 5.
These three systems disagree about 30% of the time. The most common gap: a finding that scores CVSS 7.x (High) maps to Bugcrowd P4 (Low) or H1 Medium-default. When the platform default rates lower than CVSS:
bugcrowd-reporting for the canonical template.)An authorized bug-bounty engagement saw P4-default findings escalated to P3 via the severity-request paragraph. The escalation isn't automatic — you have to ask, with grounded reasoning, in the first body section.
Everything in the submission body is logged forever by the platform. Operate accordingly:
Cross-link evidence-hygiene for the full capture-and-redact protocol.
| Platform | Tone | Required Structure | Severity Mechanism |
|---|---|---|---|
| HackerOne | Narrative | Summary -> Steps -> Impact -> Suggested fix | Triager-set, contestable |
| Bugcrowd | Structured | Severity request -> VRT category -> Title -> Body -> Remediation | VRT-default + manual override paragraph |
| Intigriti | Between | Summary -> PoC -> Impact -> Recommendation | Researcher-proposed, triager-confirmed |
| Immunefi | PoC-first | Working PoC code -> Walkthrough -> Impact -> Severity | Foundry/Hardhat code is the primary deliverable |
Picking the wrong template style costs validity. A narrative-heavy Bugcrowd report misses the VRT mapping the triager needs; a structured H1 report reads as terse and gets follow-up questions that delay payout.
Claiming an attack works "in theory" or "could be chained to [bigger impact]" without demonstrating it. Triage-validation Q6 (impact beyond technically possible) kills these on the validation side; report-writing has to mirror it on the writing side.
Two valid paths:
Pick one. Never split the difference with "could potentially" or "may allow" — those phrases are the triager's signal that the report is theoretical, and theoretical reports get N/A.
bb-methodology — When Phase 5's report-writing step starts. Workflow primitive: Phase 5 calls /report which loads this skill for the platform-specific template (H1 / Bugcrowd / Intigriti / Immunefi).© elementalsouls, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/report-writing of elementalsouls/Claude-BugHunter.
Open the folder on GitHubat commit a04bb83
Report Writing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Report Writing this skillelementalsouls/Claude-BugHunter | 4.8k | — | ~5.2k | Automated safety check: Pass | MIT | |
| Report Writingsickn33/agentic-awesome-skills | 47k | 1 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Web3 Triage and Report Examplestradecatlabs/vibe-coding-cn | 17k | 2 repos | ~7.7k | Automated safety check: Pass | MIT | |
| Bug Bounty Report Writingawarexone/Agentic-Bug-Hunter | 5.3k | 2 repos | ~3.9k | Automated safety check: Pass | MIT | |
| Write Reportbugbountywithmarco/bugbounty-disclosed-reports | 122 | — | ~585 | Automated safety check: Pass | None | |
| Bugcrowd Reportingsickn33/agentic-awesome-skills | 47k | 1 repos | ~5.9k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi
tradecatlabs/vibe-coding-cn
Seven-question triage gate, Immunefi report format and dissected paid bounty examples for deciding whether a smart contract finding is worth submitting.
awarexone/Agentic-Bug-Hunter
Guides writing bug bounty reports for HackerOne, Bugcrowd, Intigriti and Immunefi: impact-first titles, proven claims, CVSS 3.1 scoring and a pre-submit checklist.
bugbountywithmarco/bugbounty-disclosed-reports
Write a disclosure-quality bug bounty report for a finding, matching the HackerOne report format used in this repo's corpus.
sickn33/agentic-awesome-skills
Bugcrowd-specific reporting tactics complementing report-writing
SnailSploit/Claude-Red
Penetration test and red team report writing methodology. An agent skill from SnailSploit/Claude-Red.
elementalsouls/Claude-BugHunter
Hunt API security misconfiguration — mass assignment, prototype pollution, HTTP verb tampering.
elementalsouls/Claude-BugHunter
Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains.
elementalsouls/Claude-BugHunter
Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…
elementalsouls/Claude-BugHunter
Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). An agent skill from elementalsouls/Claude-BugHunter.
elementalsouls/Claude-BugHunter
Hunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g.
elementalsouls/Claude-BugHunter
Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…
Categories
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity…. Report Writing is an agent skill from elementalsouls/Claude-BugHunter.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist.
Report Writing fits situations like: tasks that involve Bug bounty; tasks that involve Report writing.
Run `npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a claude-code`. Or copy the skill folder (skills/report-writing in elementalsouls/Claude-BugHunter) into .claude/skills/report-writing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a codex`. Or copy the skill folder (skills/report-writing in elementalsouls/Claude-BugHunter) into .agents/skills/report-writing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elementalsouls/Claude-BugHunter --skill report-writing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/report-writing, .gemini/skills/report-writing, .github/skills/report-writing and .opencode/skills/report-writing in your project.
Going by SKILL.md and its folder, Report Writing needs credentials named ATTACKER_TOKEN and ACCOUNT_A_TOKEN. Our summary lists: Python 3; A credential in ATTACKER_TOKEN.
SKILL.md names 1 domain. As links in the text: first.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Report Writing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Report Writing: Report Writing (sickn33/agentic-awesome-skills, 47k stars), Web3 Triage and Report Examples (tradecatlabs/vibe-coding-cn, 17k stars), Bug Bounty Report Writing (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Write Report (bugbountywithmarco/bugbounty-disclosed-reports, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elementalsouls (a GitHub user) maintains it in elementalsouls/Claude-BugHunter, which has 4,791 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.
Source: elementalsouls/Claude-BugHunter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.