CtrlK
BlogDocsLog inGet started
Tessl Logo

report-writing

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Validation gates and the submittability/always-rejected decision are owned by triage-validation; this skill owns the written report itself (templates, tone, formulas). Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.

65

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/report-writing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

67%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content with strong concrete templates and examples, hampered by significant cross-section duplication and a monolithic single-file structure that should be split across referenced bundle files.

Suggestions

Split the per-platform report templates (H1/Bugcrowd/Intigriti/Immunefi) and the CVSS 3.1/4.0 reference into separate files under references/, leaving SKILL.md as a concise overview with one-level-deep links — this directly lifts progressive_disclosure.

De-duplicate the title formula (currently in TITLE FORMULA, the Operator Notes 'Title formula in practice', and re-implied inside each template) into a single canonical section that the templates reference, to improve conciseness.

Consolidate the repeated 'never use could potentially / may allow' guidance from 'THE MOST IMPORTANT RULE' and 'the single biggest report-writing mistake' into one place to remove the duplication dragging down conciseness.

DimensionReasoningScore

Conciseness

Mostly efficient dense reference material, but the ~560-line body repeats the title formula in three places and re-states the 'never use could potentially' rule in both 'THE MOST IMPORTANT RULE' and 'the single biggest report-writing mistake', adding notable redundancy.

3 / 5

Actionability

Fully executable throughout — copy-paste-ready HTTP requests, complete per-platform report templates, runnable Python/Solidity fix snippets, CVSS tables, and concrete downgrade-counter scripts that cover the common cases.

5 / 5

Workflow Clarity

Provides a sequenced '60-Second Pre-Submit Checklist' validation gate and explicit ordering primitives against sibling skills, but lacks an explicit validate→fix→retry feedback loop within the report-writing process itself.

4 / 5

Progressive Disclosure

A monolithic single-file SKILL.md with no references/scripts/assets bundle, where clearly separable material (per-platform templates, CVSS reference, operator notes) is all inlined rather than split into one-level-deep referenced files.

2 / 5

Total

14

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that comprehensively lists capabilities, gives explicit use-when guidance, and cleanly scopes itself against a sibling skill. The only gap is a few missing natural trigger phrasings a user might actually say.

DimensionReasoningScore

Specificity

Comprehensively enumerates concrete capabilities — 'report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist' — going well beyond naming the domain.

5 / 5

Completeness

Explicitly answers both 'what' (templates, tone, formulas) and 'when' ('Use after validating a finding and before submitting') with concrete trigger phrases, plus an explicit boundary against triage-validation.

5 / 5

Trigger Term Quality

Names the platforms (H1/Bugcrowd/Intigriti/Immunefi) and explicit triggers ('Use after validating a finding and before submitting', 'Bug bounty report writing'), but is missing common natural variations a user might say such as 'write up a finding' or 'submit a bug report'.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche ('this skill owns the written report itself') and explicitly disambiguates from triage-validation ('Validation gates... are owned by triage-validation'), giving minimal conflict risk.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (569 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.