CtrlK
BlogDocsLog inGet started
Tessl Logo

report-writing

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Validation gates and the submittability/always-rejected decision are owned by triage-validation; this skill owns the written report itself (templates, tone, formulas). Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.

68

Quality

83%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable, template-driven content with a solid validation checklist, but it is a long monolithic file with no reference bundle and some narrative redundancy plus a duplicated, contradictory title formula in the Operator Notes.

Suggestions

Split the four per-platform templates and the CVSS 3.1/4.0 tables into reference files (e.g. references/h1-template.md, references/cvss-scoring.md) and link them one level deep from SKILL.md to reduce the monolithic body and raise progressive_disclosure.

Tighten Operator Notes: cut the motivational prose ('The bad titles get opened last... different payout speed') and reconcile the two conflicting title-formula definitions into one canonical formula to improve conciseness.

DimensionReasoningScore

Conciseness

Templates are concrete and avoid explaining basics Claude already knows, but the Operator Notes section adds narrative padding ('The bad titles get opened last. The good titles get opened first... different payout speed') and the title formula is restated twice in contradictory forms ('[Bug Class] in [endpoint] allows...' vs '<asset> | <bug class> | <impact>'), so it is mostly efficient but could be tightened.

2 / 3

Actionability

Copy-paste-ready per-platform templates with exact HTTP requests, JSON responses, CVSS vector strings, and code fixes, plus severity tables, downgrade counters, and a pre-submit checklist — fully executable, specific guidance.

3 / 3

Workflow Clarity

The single task (write the report) is made unambiguous via per-platform templates, with an explicit 60-second pre-submit checklist as the validation gate and downgrade counters as a triager-pushback feedback loop; not a destructive/batch operation so no cap applies.

3 / 3

Progressive Disclosure

Well-sectioned but monolithic ~560-line SKILL.md with no bundle files (references/, scripts/, assets/ are absent); the four platform templates, CVSS tables, and Operator Notes are inline content that could be split into one-level-deep references, matching the anchor-2 example of inline content that belongs in a separate file.

2 / 3

Total

10

/

12

Passed

Description

90%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with explicit use-when guidance and a clear boundary against triage-validation. The only weakness is a second-person imperative clause that triggers the voice penalty on specificity, capping that dimension at 2.

DimensionReasoningScore

Specificity

Lists nine concrete capabilities ('report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist'), matching the 'multiple specific concrete actions' anchor; penalized one level because 'Never use "could potentially" — prove it or don't report' is an imperative with implied second-person voice, which the voice guideline reduces specificity by 1 for.

2 / 3

Completeness

Explicitly answers what (templates, tone, formulas) and when via the explicit trigger 'Use after validating a finding and before submitting', satisfying the explicit-trigger requirement so it is not capped at 2.

3 / 3

Trigger Term Quality

Natural domain terms a user would actually say are present ('bug bounty report writing', 'Bugcrowd/Intigriti/Immunefi', 'CVSS 3.1 scoring', 'pre-submit checklist'), giving good coverage rather than technical jargon.

3 / 3

Distinctiveness Conflict Risk

Explicitly carves its niche from a sibling skill ('Validation gates and the submittability/always-rejected decision are owned by triage-validation; this skill owns the written report itself'), making wrong-skill triggering unlikely.

3 / 3

Total

11

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (568 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.