CtrlK
BlogDocsLog inGet started
Tessl Logo

report-writing

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced reference with strong validation checkpoints and concrete copy-paste examples. The main weakness is progressive disclosure: with no bundle files, ~500 lines of inlined templates and CVSS material could be split into one-level-deep references.

Suggestions

Move the four per-platform report templates (HackerOne/Bugcrowd/Intigriti/Immunefi) into separate reference files under references/ and keep SKILL.md as an overview that links to each, reducing the inlined bulk.

Extract the CVSS 3.1/4.0 quick-scoring tables and severity decision guide into a dedicated references/cvss-scoring.md linked from the main file, since it is reference material rather than core workflow.

Consolidate the duplicated "Steps to Reproduce" formatting across templates into a single shared block referenced by each platform template to reduce redundancy.

DimensionReasoningScore

Conciseness

The body assumes Claude's competence ("5-paragraph explanations of what IDOR is (they know)") and stays dense, but four near-parallel per-platform report templates and repeated CVSS material introduce minor padding that could be trimmed or consolidated.

4 / 5

Actionability

Provides copy-paste-ready templates, exact HTTP requests with tokens, concrete CVSS 3.1/4.0 vector strings, a title formula with good/bad examples, and a checkable pre-submit checklist covering the common report cases.

5 / 5

Workflow Clarity

Sequences the work with an explicit validation gate (the "60-SECOND PRE-SUBMIT CHECKLIST") and a persistence/submission-notes loop ("append/update it instead of creating a duplicate"), giving clear checkpoints and error-recovery guidance.

5 / 5

Progressive Disclosure

No bundle files exist, so all content — including the four platform templates and the CVSS 4.0 quick reference — is inlined into a single ~500-line file with section headers; it is organized but content that could live in separate reference files is kept inline.

3 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that clearly states what the skill does and when to use it, with concrete capabilities and a niche focus. The only mild gap is trigger-term naturalness, where platform acronyms and procedural phrasing could be broadened.

DimensionReasoningScore

Specificity

Lists multiple concrete capabilities — "report templates", "CVSS 3.1 scoring", "title formula", "impact statement formula", "severity decision guide", "downgrade counters", "pre-submit checklist" — giving comprehensive coverage of what the skill does.

5 / 5

Completeness

Explicitly answers both "what" (the enumerated capabilities) and "when" ("Use after validating a finding and before submitting") with concrete trigger guidance.

5 / 5

Trigger Term Quality

Includes natural terms ("bug bounty report writing", "finding", "submitting") and platform names (H1/Bugcrowd/Intigriti/Immunefi), but relies on platform acronyms and procedural triggers rather than the full set of phrases a user might naturally say, leaving a few natural terms missing.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche — bug bounty report writing for named platforms — with distinct triggers and minimal risk of firing for an unrelated skill.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (502 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
shuvonsec/claude-bug-bounty
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.