Agent skill

Hackerone Report

by forefy in forefy/.context

Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes.

MITAuto-check passedSecurity

Install Hackerone Report

skills CLI
$ npx skills add forefy/.context --skill hackerone-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forefy/.context hackerone-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunter-utils/hackerone-report .claude/skills/hackerone-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hackerone-report
GitHub stars
152
Token cost
~2.1k tokens
SKILL.md length
1,139 words
Files
3 (incl. references)
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes.

  • Works in 6 steps: Dedup pre-flight (do this FIRST, every… → Write the report (concise) → PoC package + video-ready README → …
  • Prepare a bug-bounty report
  • SKILL.md covers Non-negotiable safety rules, Phase 0 - Dedup pre-flight (do…, Phase 1 - Write the report… and Phase 2 - PoC package +…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hackerone Report is an agent skill from forefy/.context. Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes. Use to submit or prepare a bug-bounty report.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/poc-readme-template.md` and `references/report-template.md`). Compatibility notes: Requires an automation-capable browser (in-app Browser or Claude-in-Chrome) to file; drafting/PoC work needs none

It sits in Security, covering Bug bounty. The repository describes itself as: AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Research. The licence is MIT.

When your agent uses it

  • Prepare a bug-bounty report
  • Tasks that involve Bug bounty

Example prompts

  • “/hackerone-report”

Requirements

  • Compatibility (from SKILL.md): Requires an automation-capable browser (in-app Browser or Claude-in-Chrome) to file; drafting/PoC work needs none

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Dedup pre-flight (do this FIRST, every time)
  2. Write the report (concise)
  3. PoC package + video-ready README
  4. Browser: reach the submission form
  5. Fill the form
  6. Hand off

What it can do on your machine

Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires an automation-capable browser (in-app Browser or Claude-in-Chrome) to file; drafting/PoC work needs none

    From compatibility in the SKILL.md frontmatter.

Context cost

Hackerone Report loads about 2.1k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 42 tokens; SKILL.md has 1,139 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 1,139 words, ~2,060 tokens.

Download SKILL.mdSave it as .claude/skills/hackerone-report/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
hackerone-report
description
Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes. Use to submit or prepare a bug-bounty report.
compatibility
Requires an automation-capable browser (in-app Browser or Claude-in-Chrome) to file; drafting/PoC work needs none

Filing a HackerOne report

Drive a HackerOne vulnerability submission end to end: verify it's worth filing, write it up concisely, build a reproducible PoC with a video-ready README, fill the submission form in the browser, and hand the irreversible steps back to the user.

Non-negotiable safety rules

These are hard stops. They protect the user's account and their Signal.

  1. Never enter credentials or 2FA codes. When the form gates on login, take a screenshot, tell the user to sign in themselves, and wait. Suggest they tick "Remember me for 2 weeks" (HackerOne sessions drop mid-flow otherwise).
  2. Never click the final "Submit Report". It is an irreversible publish and it spends one of the user's reports. Fill everything, then hand off: the user reviews and submits. State this explicitly up front.
  3. Never attach files the user didn't ask you to, and don't fabricate PoC output. The in-app browser can't drive the native file picker anyway - the user attaches the zip and the video.
  4. Filing is per-user consent. Draft freely; the act of submitting is the user's.

Phase 0 - Dedup pre-flight (do this FIRST, every time)

The most expensive mistake is re-filing a finding the program already closed. It wastes a report and dents Signal. Before drafting anything:

  • Search the local findings tree for prior work on the same root cause / sinks / code paths. Look especially in any duplicates/ folder and for filenames encoding a resolution: Informative-*, Duplicate-*, NA-*, Resolved-*. A file named Informative-1-<x>.md means the program already closed <x> as Informative.
  • Compare code locations, not just titles. Grep both the candidate writeup and prior reports for the exact files/functions/sinks cited. If they overlap, it's the same finding regardless of new framing. (A "new vector" that strengthens the entry but reaches the same sink the program already judged is still a duplicate.)
  • Offer to check the live program state: open HackerOne → My Reports, search a keyword from the finding, read the actual close reason/comment.
  • If it's a dup: say so plainly and recommend not filing. Options: don't file; comment/appeal on the existing report instead of opening a new one; hold reports for something novel. Only proceed on the user's explicit go-ahead.
  • Also surface program constraints visible on the submit page: "Trial Reports Remaining: N" and any Signal Requirement - a low Signal can block future submissions, so accuracy matters more than volume.

Phase 1 - Write the report (concise)

Use references/report-template.md. House style:

  • Plain, direct, first person ("we found this field is forgeable"), not marketing prose.
  • State each fact once. The same "new vector / defeated mitigation" point tends to sprawl across Summary, Component, Steps, and Impact - keep it in Summary + the Steps variant, and don't re-litigate it in Impact.
  • No em dashes if the user prefers plain hyphens; use spaced hyphens - and split run-ons into sentences.
  • Sections: Summary → Version/Affected → Component (vulnerable code paths) → Steps To Reproduce → Supporting Material → Impact → Suggested Fix.
  • Title goes in its own field (max ~150 chars): <vuln type> via <mechanism> (<feature/component>, <version/context>). Don't repeat the title as the first line of the Description body.

Phase 2 - PoC package + video-ready README

Goal: a self-contained folder the triager can run and the user can film. Use references/poc-readme-template.md.

  • One command per step, copy-paste, in order: prerequisites check → environment setup → baseline (the thing that is denied) → exploit → the money-shot success → a control that proves the mechanism → teardown.
  • The money shot is a before/after: the same request denied, then succeeding, with only the exploited variable changed. That's what the video should capture.
  • Actually run the exact README blocks on a clean environment before shipping. Repro commands that work in your head often fail copy-paste (auth/credential precedence, working-directory resets, tool flags that don't override config). Fix them until a fresh run reproduces.
  • Prefer a few transparent commands over a big opaque .sh. If shared shell state is the only reason for a script, capture it in a tiny helper function inside the README instead.
  • Ship: README.md (the walkthrough), the exploit inputs, an annotated pointer to the vulnerable source lines, a non-interactive runner, and any plumbing clearly labeled "not part of the vulnerability". Zip it; reference it in the report as poc.zip. The user records poc.mov and attaches both.
Show full SKILL.md (443 more words)Show less

Phase 3 - Browser: reach the submission form

Use the in-app Browser (mcp__Claude_Browser__*) or Claude-in-Chrome. Gotchas learned:

  • Navigate to hackerone.com/<program>. The submit entry is "Submit without Report Assistant" (full manual form). Its href looks like /<program>/reports/new?type=team&report_type=vulnerability.
  • Do NOT deep-link that URL - it's a client-side SPA route and returns "Page not found" on direct navigation. Click the link on the program page instead.
  • Expect a login/2FA gate → hand off to the user (safety rule 1). After they sign in, the program page may need a reload.
  • Sessions expire mid-flow; if the form empties or bounces to sign-in, have the user re-auth with "Remember me".

Phase 4 - Fill the form

The manual form is a numbered flow. Prefer read_page refs over pixel coordinates (the pane rescales screenshots and raw-coordinate clicks miss). Use form_input for text fields - it's reliable.

#FieldHow
1AssetType in the asset search box to filter, then click the match. For a source-code asset, search its repo slug (e.g. an <org>/<repo> GitHub asset tagged "Eligible for bounty") and pick the exact program-listed entry - don't assume a specific project. If the inline list stays open and eats scroll, clear the search text / press Escape to collapse it.
2Weakness (CWE)Type a keyword (e.g. authorization) to filter, pick the CWE (e.g. Improper Authorization CWE-285). Then set the cluster/subcategory dropdown next to it (e.g. Access Control). Selecting the CWE is preserved even if the list then filters empty.
3Severity (CVSS)"Submit report with severity" → CVSS 3.0 calculator. Set each metric button by ref. Set the clearly-correct metrics yourself; leave a genuinely judgment-call metric (usually Scope) for the user, and show them both resulting scores (e.g. Scope:Unchanged→High vs Scope:Changed→Critical). Read the live "Score" readout back to them.
4Titleform_input the title string (≤150 chars).
4Descriptionform_input the report body (Summary → … → Suggested Fix), Markdown. Drop the leading # Title line - the Title field holds it.
4ImpactSeparate required field. form_input the Impact paragraph only.
4AttachmentsUser drags in poc.zip + poc.mov (you can't drive the native picker). Optionally suggest renaming the zip to match what the report references.

After filling, offer to click Preview on the Markdown fields so the user can eyeball rendering. Verify the "Review and Submit" panel shows the right Title/Asset.

Phase 5 - Hand off

Summarize the filled state as a table (Asset / Weakness / Severity / Title / Description / Impact = done). List what remains and that it's the user's: attach zip, record+attach video, decide any judgment-call CVSS metric, review, click Submit. Re-state that you won't click Submit and won't loop on the blocked login.

References

  • references/report-template.md - the concise finding writeup skeleton with all section headings.
  • references/poc-readme-template.md - the video-ready copy-paste reproduction README pattern.

© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/hunter-utils/hackerone-report of forefy/.context.

  • SKILL.md
  • references/poc-readme-template.md
  • references/report-template.md

Open the folder on GitHubat commit c8ff161

Compare with similar skills

Hackerone Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hackerone Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hackerone Report this skillforefy/.context152—~2.1kAutomated safety check: PassMIT
Web3 Smart Contract Auditawarexone/Agentic-Bug-Hunter5.3k3 repos~4.5kAutomated safety check: PassMIT
Bug Bounty Hunting Methodologyawarexone/Agentic-Bug-Hunter5.3k2 repos~4.7kAutomated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Web3 Smart Contract Audit

    awarexone/Agentic-Bug-Hunter

    Guides smart contract audits and bounty target selection with ten DeFi bug classes, kill signals, a Foundry PoC template and grep patterns.

    5.3k GitHub starsUsed in 3 repos~4.5k tokens
    SecurityAuto-check passed
  • Bug Bounty Hunting Methodology

    awarexone/Agentic-Bug-Hunter

    Orchestrates a bug bounty session with a 5-phase workflow and a critical-thinking framework covering developer psychology, anomaly detection and What-If experiments.

    5.3k GitHub starsUsed in 2 repos~4.7k tokens
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.8k GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Web3 Bug Bounty AI Tools

    tradecatlabs/vibe-coding-cn

    A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

    17k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check: warnings

More from forefy/.context

All 20 skills in this repo
  • Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

    152 GitHub stars~951 tokensUpdated 2 days ago
    Auto-check passed
  • Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.

    152 GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

    152 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed

Categories

Questions about Hackerone Report

What does Hackerone Report do?

Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes. context. Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes.

When should I use Hackerone Report?

Hackerone Report fits situations like: prepare a bug-bounty report; tasks that involve Bug bounty.

How do I install Hackerone Report in Claude Code?

Run `npx skills add forefy/.context --skill hackerone-report -a claude-code`. Or copy the skill folder (skills/hunter-utils/hackerone-report in forefy/.context) into .claude/skills/hackerone-report in your project. Claude Code loads it when a task matches its description.

How do I install Hackerone Report in Codex?

Run `npx skills add forefy/.context --skill hackerone-report -a codex`. Or copy the skill folder (skills/hunter-utils/hackerone-report in forefy/.context) into .agents/skills/hackerone-report in your project. Codex loads it when a task matches its description.

Can I use Hackerone Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill hackerone-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hackerone-report, .gemini/skills/hackerone-report, .github/skills/hackerone-report and .opencode/skills/hackerone-report in your project.

What does Hackerone Report need to run?

SKILL.md names no scripts, command-line tools or credentials: Hackerone Report is instructions for the agent only. Compatibility (from SKILL.md): Requires an automation-capable browser (in-app Browser or Claude-in-Chrome) to file; drafting/PoC work needs none.

Does Hackerone Report access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hackerone Report safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hackerone Report use?

Hackerone Report is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hackerone Report use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Hackerone Report?

Skills that share tags, products or a category with Hackerone Report: Web3 Smart Contract Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars), Bug Bounty Hunting Methodology (awarexone/Agentic-Bug-Hunter, 5.3k stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars) and Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hackerone Report?

forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.

Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.