submit
Installation
SKILL.md
Prepare and submit a report for finding: $ARGUMENTS
Workflow:
0. Read rules/identities.md to learn which env vars hold the researcher handle, email alias, and API token for the platform identified in step 1. NEVER hardcode a username or email; always reference the env-var symbol. If a required var is unset, abort with error: <VAR> is not set; refusing to guess and surface it to the user.
- Read
scope.yamlto determine the platform and program handle. - Read the finding details from brain/findings/poc directory matching "$ARGUMENTS".
- Use MCP tool
draft_reportto create a platform-formatted draft:- Format title as:
[Vuln Type] in [Component] allows [Impact] via [Vector] - Include CVSS vector string (CVSS 3.1 for HackerOne, CVSS 4.0 for all others)
- Map vulnerability type to platform-specific taxonomy (H1 weakness IDs, Bugcrowd VRT)
- Include all reproduction steps, impact, and remediation
- Format title as:
- Show the draft to the user and ASK FOR CONFIRMATION before submitting.
- ONLY after explicit user approval, use MCP tool
submit_reportto submit. - After submission, update the brain:
uv run python3 $CLAUDE_PROJECT_DIR/tools/brain.py record <target> confirmed <technique> "Submitted as report #<id> on <platform>" - Update findings.json status to "reported".
IMPORTANT: NEVER submit without showing the draft and getting explicit user confirmation.