CtrlK
BlogDocsLog inGet started
Tessl Logo

bounty-report-formatter

Bug bounty report formatting for HackerOne, Bugcrowd, Immunefi, and GitHub Security Advisories. Load after validate_finding succeeds and the finding needs to be submitted to a bounty program.

76

Quality

95%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

100%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a lean, highly actionable bounty-report skill: a concrete fill-in template, calibrated real-advisory title examples, a validation checklist, and concise per-platform notes. It assumes Claude's competence, avoids concept padding, and is well-organized with no nested references or bundle-file dependency.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — it never explains what a CVSS vector or bug bounty is — and every section (title convention, report template, checklist, platform notes) earns its place; the six real advisory titles serve a calibration purpose rather than padding, so it is not the verbose 'could be tightened' anchor.

3 / 3

Actionability

Provides a copy-paste-ready fill-in report template with a fully laid-out CVSS table, exact step/PoC command blocks, and a concrete remediation diff, plus specific platform instructions (CVSS calculator URL, VRT P1-P4 mapping, GHSA fields) — fully executable guidance rather than abstract direction.

3 / 3

Workflow Clarity

The process is clear (apply template → run the 14-item Quality Checklist → adapt to platform) with explicit validation checkpoints such as 'CVSS vector string is complete', 'Baseline/negative response is included', and the duplicate check 'kg_query(kind="finding")', matching the checklist-for-complex-processes anchor.

3 / 3

Progressive Disclosure

The skill is self-contained with no bundle files and no need for them; content is organized into clear, navigable sections (Title Convention, Report Template, Quality Checklist, Platform-Specific Notes per platform) with no nested-reference anti-pattern, and the short platform notes are appropriately kept inline rather than over-split into separate files.

3 / 3

Total

12

/

12

Passed

Description

90%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is concise, third-person, and clearly answers both what the skill does and when to load it, with strong natural platform trigger terms and low conflict risk. Its only weakness is that it states a single action ('formatting') rather than enumerating the concrete sub-actions the body actually performs.

Suggestions

Expand the description to list a few concrete actions (e.g., 'draft, score CVSS, and format reports for submission to ...') to lift specificity from one named action to several.

Consider adding a couple of plain-English trigger variations users might say (e.g., 'writeup', 'triage-ready report') so natural-language recall matches the metadata.when_to_use terms.

DimensionReasoningScore

Specificity

Names the domain and four concrete target platforms ('Bug bounty report formatting for HackerOne, Bugcrowd, Immunefi, and GitHub Security Advisories') but describes only a single action ('formatting') rather than enumerating multiple concrete actions like drafting, CVSS scoring, and submitting, so it is not comprehensive.

2 / 3

Completeness

Clearly answers both 'what' ('Bug bounty report formatting for ...') and 'when' via the explicit trigger clause 'Load after validate_finding succeeds and the finding needs to be submitted to a bounty program', which is equivalent to a 'Use when...' clause.

3 / 3

Trigger Term Quality

Covers natural terms a user would actually say — 'bug bounty report', 'HackerOne', 'Bugcrowd', 'Immunefi', and 'GitHub Security Advisories' — giving good coverage of the platform names that trigger this need.

3 / 3

Distinctiveness Conflict Risk

Occupies a clear niche (post-validation bounty report formatting for named platforms) with distinct platform-specific triggers, making it unlikely to fire for an unrelated skill.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.