Bug-bounty report & severity
SkillAI & modelsTurn a confirmed finding into a triage-friendly bug-bounty report (HackerOne/Bugcrowd) with correct severity and clean evidence. Load when a bug is validated and needs submitting, on "write the report", "CVSS", "severity", or before disclosure. Signals: a reproduced finding, a program's VRT/severity policy.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Bug-bounty report & severity skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/reporting/reporting-bug-bounty-writeup/SKILL.md and read by ahel’s review.
When it governs
After you've reproduced a finding and confirmed it's in scope. A great report gets triaged fast and paid fairly; a sloppy one gets closed as informational regardless of the bug.
Structure (what triagers want)
- Title —
[Vuln class] on <asset> allows <impact>(specific, no hype). - Summary — 2–3 sentences: what, where, why it matters.
- Severity — CVSS 3.1 vector + score, reconciled with the program's VRT/policy. Justify the Impact metrics from demonstrated impact, not theoretical maximum.
- Steps to reproduce — numbered, copy-pasteable, from a clean session. Include exact requests (method, URL, headers, body) and account roles used.
- Proof — minimal PoC that proves impact (a screenshot with the URL bar, a request/response
pair, a short video).
document.domainfor XSS;sts get-caller-identityfor cloud, etc. - Impact — the realistic business consequence, tied to what you proved.
- Remediation — the correct fix (allowlist, output encoding, object-level authz…).
Evidence hygiene (do before you submit)
- Redact real PII/secrets — prove the class with your own/test data, not customer records.
- Scrub cookies/tokens/authorization headers from pasted requests.
- Deduplicate: one report per root cause; note additional affected endpoints inside it.
- Stay within RoE: no data hoarding, no lateral movement beyond proof, no DoS.
Severity gotchas
- Don't claim Critical for a self-XSS or a bug needing implausible preconditions — inflated severity gets you closed as N/A.
- Chain low bugs into a higher-impact narrative when they genuinely combine (and show the chain).
- Map to the program's own scale; CVSS is the starting point, the program policy is the ruling.
Verify before sending
A colleague (or you, from a fresh session) can reproduce it from your steps alone, the PoC proves impact, and nothing sensitive is exposed in the report.
References
FIRST CVSS 3.1 calculator; Bugcrowd VRT; HackerOne report best-practices.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
reporting-bug-bounty-writeup- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)lark-markdown
Skill · larksuite
The pick for Markdownmarkdown-mermaid-writing
Skill · k-dense-ai
The pick for Markdownskill-creator
Skill · anthropics
More in AI & modelswayfinder
Skill · mattpocock
More in AI & models