CtrlK
BlogDocsLog inGet started
Tessl Logo

bugcrowd-reporting

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints, debug-info framing, user-enumeration with sensitive PII, theoretical-issue counter), chained-finding cross-reference patterns, target selection for QA-vs-prod programs, researcher-side hygiene (Bugcrowdninja email alias, account state restoration, friendly-tester posture). Use when filing a Bugcrowd submission, when VRT default seems wrong, when triager closes as OOS or downgrades severity, when chaining linked submissions, or when scope distinguishes production from QA. Pairs with report-writing and triage-validation.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable and its workflows are well-sequenced with explicit guard checks, but it is monolithic with no bundle-file split and carries some redundancy (chain-ordering repeated in §5/§8, severity-request template duplicated by a worked example). Tightening the duplication and offloading the template/mapping library to a reference file would lift the two 2-scored dimensions.

Suggestions

Consolidate the chain-filing guidance: §8.1 repeats the primitive-before-consumer ordering already detailed in §5.1 — reference §5.1 from §8.1 instead of restating the steps, and drop one of the two severity-request examples in §3 (keep either the template or the worked example, not both).

Move the reusable template library (§3.1, §4.1-§4.4, §5.2, §6.2) and the VRT mapping table (§1.3) into a single `references/templates.md` referenced one level deep from SKILL.md, so the body becomes a lean overview and progressive disclosure reaches the well-split anchor.

Trim the verbosity of the §3.2 worked example and the §7.1 alias steps to short imperative lists; the current phrasing reads slightly padded relative to the lean anchor.

DimensionReasoningScore

Conciseness

The ~320-line body assumes Claude's competence (no 'what is Bugcrowd' padding), but it could be tightened: chain-filing ordering is repeated across §5.1 and §8.1, and §3.1's severity-request template is duplicated by a long worked example in §3.2, fitting the 'mostly efficient but could be tightened' anchor rather than the lean anchor.

2 / 3

Actionability

Copy-paste-ready templates (severity-request paragraph, four OOS rebuttals, cross-reference blocks, QA-disclaimer), concrete VRT mapping tables, and numbered step lists with fill-in placeholders give fully executable guidance, satisfying the 'copy-paste ready' anchor for an instruction-only skill.

3 / 3

Workflow Clarity

Multi-step workflows are clearly sequenced with rationale (§5.1 chain filing explains the UUID-dependency ordering; §8.1 submission order) and backed by explicit guard checkpoints (§4.5 evidence gate, §2.3 over-claim cap, §1.2 misrepresentation guard) plus 'What NOT to do' checklists; the destructive/batch feedback-loop cap does not apply to a reporting skill.

3 / 3

Progressive Disclosure

No bundle files exist and the skill is a monolithic ~320-line SKILL.md; it is well-sectioned internally but reference material (the template library in §3-§4, the VRT mapping tables) that could be split into one-level-deep reference files is inline, matching the 'content that should be separate is inline' anchor rather than the well-split anchor.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is dense but information-rich: it enumerates the skill's concrete capabilities, provides an explicit multi-condition 'Use when...' trigger clause, and carves out a distinct Bugcrowd-only niche against sibling skills. Third-person voice is maintained throughout, so no voice penalty applies.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'VRT category search-and-fallback strategy', 'manual severity override', 'severity-request paragraph as first body section', 'OOS-clause rebuttal templates', 'chained-finding cross-reference patterns', 'target selection for QA-vs-prod programs', 'researcher-side hygiene' — matching the 'lists multiple specific concrete actions' anchor.

3 / 3

Completeness

Explicitly answers both 'what' (the enumerated tactics) and 'when' via an explicit 'Use when...' clause, satisfying the anchor that requires both with explicit triggers; the trigger clause is present so completeness is not capped at 2.

3 / 3

Trigger Term Quality

The 'Use when filing a Bugcrowd submission, when VRT default seems wrong, when triager closes as OOS or downgrades severity, when chaining linked submissions, or when scope distinguishes production from QA' clause gives good coverage of natural trigger phrasings a bug-bounty researcher would actually say, with several variations.

3 / 3

Distinctiveness Conflict Risk

Scoped tightly to Bugcrowd-specific submission flow and explicitly distinguished from sibling skills ('Pairs with report-writing and triage-validation'), giving a clear niche unlikely to trigger for the wrong skill.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.