CtrlK
BlogDocsLog inGet started
Tessl Logo

report-writing

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with excellent templates, checklists, and concrete examples, but it is long and largely monolithic — four overlapping platform templates and CVSS reference tables inflate the token budget and sit inline with no progressive disclosure into separate files.

Suggestions

Consolidate the four platform templates into one canonical template plus a short per-platform diff table (title format, severity field, PoC preference), removing the ~70% shared structure.

Split the CVSS 3.1/4.0 scoring tables and the severity decision guide into a references/ file (e.g. cvss-scoring.md) and link to it from the body, moving the skill toward one-level-deep progressive disclosure.

Tighten redundant reproduce-step sections (the standalone "STEPS TO REPRODUCE FORMAT" repeats what the HackerOne/Intigriti templates already demonstrate).

DimensionReasoningScore

Conciseness

The body is ~500 lines and includes four near-duplicate platform report templates (HackerOne/Bugcrowd/Intigriti/Immunefi) that share most structure, plus overlapping reproduce-step sections — efficient per section but could be tightened/DRY'd. Not 3 because not every token earns its place; not 1 because it largely avoids explaining concepts Claude already knows and stays impact-first.

2 / 3

Actionability

Fully concrete and copy-paste ready: exact HTTP requests, JSON response bodies, CVSS vector strings, a title formula, a downgrade-counter table, code fixes, and a pre-submit checklist. Not 2 because the guidance is executable rather than pseudocode or abstract.

3 / 3

Workflow Clarity

Clear checkpoints and sequencing: a persistence rule (save findings folder), triager-optimized Steps-to-Reproduce format with Expected/Actual, a severity self-assessment, and the 60-second pre-submit checklist acting as a validation gate before submit. Not 2 because explicit validation/checklist steps are present; report writing is not a destructive batch op requiring a validate->fix->retry loop.

3 / 3

Progressive Disclosure

All content lives inline in a single monolithic SKILL.md with no external reference files (no references/scripts/assets bundle exists); the four platform templates and CVSS tables are reference material that could be split out. Not 3 because there is no one-level-deep file split or navigation; not 1 because section headers keep it well-organized rather than a poorly-organized wall.

2 / 3

Total

10

/

12

Passed

Description

100%Weight 40%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is specific, trigger-rich, and gives an explicit use-when clause plus a memorable anti-pattern rule ("Never use 'could potentially'"). It is a strong, concise skill description with no real weaknesses.

DimensionReasoningScore

Specificity

Lists many concrete capabilities — "report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist" — matching the multiple-specific-actions anchor. It uses third-person/gerund voice ("Bug bounty report writing") so no voice penalty applies; not below 3 because nothing is vague.

3 / 3

Completeness

Explicitly answers both what (templates, tone, scoring, formulas, counters) and when ("Use after validating a finding and before submitting"). Not 2 because the when-clause is explicit rather than merely implied.

3 / 3

Trigger Term Quality

Natural terms a hunter would actually say are well covered: "bug bounty report writing", "H1", "Bugcrowd", "Intigriti", "Immunefi", "CVSS 3.1 scoring", "submitting". Not 2 because the coverage spans platform names and core concepts users voice directly.

3 / 3

Distinctiveness Conflict Risk

A clear, narrow niche (bug bounty report writing for four named platforms) with platform-specific triggers unlikely to fire for unrelated skills. Not 2 because it is far more specific than "Works with document files".

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (502 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
shuvonsec/claude-bug-bounty
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.