report-writing
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a instructional guide and template repository for drafting security vulnerability reports for bug bounty platforms such as HackerOne, Bugcrowd, and Intigriti.
- [SAFE]: It contains no executable code, remote script downloads, or instructions for the agent to perform malicious actions.
- [SAFE]: Vulnerability examples (e.g., IDOR, SSRF, XSS) are used purely for illustrative purposes to demonstrate impact-first writing styles and correct CVSS scoring.
- [SAFE]: All placeholders for sensitive data (tokens, credentials, PII) are clearly labeled for manual population, and the skill includes explicit advice on redacting sensitive information from reports.
- [SAFE]: References to other skills like 'triage-validation' and 'evidence-hygiene' are internal workflow pointers and do not constitute external or unverifiable dependencies.
Audit Metadata