bug-bounty-report-writing

v2026.09.25

Write bug bounty reports that get triaged quickly and rated accurately — clear impact statements, minimal reproduction steps, and professional tone. Use before submitting any vulnerability report.

GitHub
安装命令
npx skhub add securityskills/bug-bounty-report-writing
Markdown
SKILL.md

Bug Bounty Report Writing

Turn findings into reports that triagers accept quickly and rate fairly.

Report Structure

  1. Title — vulnerability class + affected asset. Stored XSS in ticket comment field on support.example.com
  2. Severity & CVSS — your suggested rating with vector string
  3. Summary — 2–3 sentences: what, where, impact
  4. Steps to Reproduce — numbered, copy-pasteable, no assumptions
  5. Impact — what an attacker gains, concretely
  6. Supporting Material — HTTP requests/responses, screenshots with sensitive data redacted
  7. Remediation — specific fix recommendation

Rules

  • One vulnerability per report. Chains go in one report only when each step is meaningless alone.
  • Impact must be demonstrated or rigorously argued, not speculated. "Could lead to RCE" without a path gets downgraded.
  • Redact personal data in evidence. Blur user PII; never include other users' data you accessed — report the access, delete the data.
  • No markdown-breaking formatting in pasted logs; use fenced code blocks.
  • Write for a triager seeing the asset for the first time.

Common Downgrade Causes to Avoid

  • Self-XSS or XSS requiring victim-installed software presented as high severity
  • Missing Content-Security-Policy or verbose headers with no demonstrated exploit
  • Theoretical IDOR without showing two distinct accounts affected
  • Automated scanner output pasted without manual verification

After Submission

  • Respond to triager questions within the program's SLA
  • Request re-review only after substantive new information
  • Do not disclose publicly until the program's disclosure policy allows
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.25

发布时间

2026年9月25日

分类

未分类

许可证

未指定

源路径

bug-bounty/bug-bounty-report-writing

默认分支

main

最新提交

b2b6b52

Tree SHA

8db485b