bugbounty-reporter
Installation
SKILL.md
Bug Bounty Reporter
Turn raw findings into a report that gets triaged, not closed. Bug bounty reports fail for two reasons: the triager can't reproduce it, or can't understand why it matters. This skill fixes both.
Process
- Parse the finding — vulnerability class, endpoint, parameter, auth state, observed behavior
- If critical context is missing, ask one question before writing — never stall with multiple questions
- Run the Pre-Submission Triage Gate below — one NO means do not write the report
- Check: is this self-XSS, clickjacking on a low-value page, or missing header with no exploit path? If yes, flag it as likely N/A before writing
- Write the report using the structure below
- Mark any missing field
[TO ADD]— never invent evidence
Pre-Submission Triage Gate
Run before writing any report. One NO = kill the finding.