CtrlK
BlogDocsLog inGet started
Tessl Logo

bugcrowd-reporting

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints, debug-info framing, user-enumeration with sensitive PII, theoretical-issue counter), chained-finding cross-reference patterns, target selection for QA-vs-prod programs, researcher-side hygiene (Bugcrowdninja email alias, account state restoration, friendly-tester posture). Use when filing a Bugcrowd submission, when VRT default seems wrong, when triager closes as OOS or downgrades severity, when chaining linked submissions, or when scope distinguishes production from QA. Pairs with report-writing and triage-validation.

73

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-organized, highly actionable tactics skill built around concrete copy-paste templates and clearly sequenced multi-step workflows. Its main gaps are minor: a little trimmable prose and implicit rather than explicit verify-checkpoints in the filing workflows.

Suggestions

Tighten or remove the 'Notes on usage' section, which restates the §9 pairing table and the intro's skill-boundary point.

Make the validation gates in §5.1 and §8.1 explicit verify-then-proceed steps (e.g., 'Confirm each primitive has a UUID before drafting the consumer body') rather than leaving them implicit.

Consider moving the OOS rebuttal templates (§4) or the VRT mapping table (§1.3) into a reference file so SKILL.md reads as an overview that points one level deeper.

DimensionReasoningScore

Conciseness

The body is tactical and largely assumes Claude's competence — it does not pad with concepts Claude already knows — but a few prose sections (the intro paragraph, the 'Notes on usage' block that partly restates the §9 pairing table) could be trimmed.

4 / 5

Actionability

Provides copy-paste-ready markdown templates (severity-request paragraph, four OOS rebuttals, chain cross-reference, QA-disclaimer) plus a concrete VRT mapping table and numbered procedures, fully covering the common filing cases.

5 / 5

Workflow Clarity

Multi-step processes (§5.1 chain filing, §8.1 submission order) are clearly sequenced with guardrail sections ('What NOT to do') and an explicit validation gate ('Don't file theoretical findings'), though a couple of checkpoints are implicit rather than stated as verify-then-proceed steps.

4 / 5

Progressive Disclosure

No bundle files exist, so all content lives inline in a single well-sectioned SKILL.md with a §9 navigation table and clear headers; structure is good and self-containment is appropriate for a tactics skill, but there is no progressive file-splitting to push detail one level deeper.

4 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A dense, concrete description that names the niche, enumerates specific capabilities, and provides multiple natural trigger phrases for when to invoke it. Its only weakness is density — the single long sentence packs in a lot, but every clause earns its place and nothing is vague.

DimensionReasoningScore

Specificity

Lists multiple concrete tactics — VRT search-and-fallback, manual severity override, severity-request paragraph, OOS-clause rebuttal templates, chained-finding cross-reference, QA-vs-prod target selection, researcher hygiene — giving comprehensive coverage rather than vague abstraction.

5 / 5

Completeness

Explicitly answers both what (enumerated program-specific tactics) and when (a concrete multi-trigger 'Use when...' clause), matching the anchor-5 pattern of clear what-and-when with concrete trigger phrases.

5 / 5

Trigger Term Quality

The 'Use when filing a Bugcrowd submission, when VRT default seems wrong, when triager closes as OOS or downgrades severity, when chaining linked submissions, or when scope distinguishes production from QA' clause supplies several natural trigger phrases a researcher would actually say.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear Bugcrowd-specific niche with distinct triggers (VRT, OOS, triager, Bugcrowd submission) and explicitly delineates boundaries by stating it pairs with report-writing and triage-validation rather than duplicating them.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.