report-writing

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a instructional guide and template repository for drafting security vulnerability reports for bug bounty platforms such as HackerOne, Bugcrowd, and Intigriti.
  • [SAFE]: It contains no executable code, remote script downloads, or instructions for the agent to perform malicious actions.
  • [SAFE]: Vulnerability examples (e.g., IDOR, SSRF, XSS) are used purely for illustrative purposes to demonstrate impact-first writing styles and correct CVSS scoring.
  • [SAFE]: All placeholders for sensitive data (tokens, credentials, PII) are clearly labeled for manual population, and the skill includes explicit advice on redacting sensitive information from reports.
  • [SAFE]: References to other skills like 'triage-validation' and 'evidence-hygiene' are internal workflow pointers and do not constitute external or unverifiable dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:02 PM
Security Audit — agent-trust-hub — report-writing