reporting-security-findings
Installation
SKILL.md
Reporting Security Findings
The report is the product. Findings that are not understood are not fixed, and findings that cannot be reproduced are disputed. Most of the value an assessment creates is destroyed or preserved in the write-up.
When to Use
- Writing up a single vulnerability
- Producing a penetration test, code audit, or red team report
- Submitting to a bug bounty program or triaging inbound submissions
- Scoring severity and arguing priority with an engineering team
- Planning coordinated disclosure for an unpatched issue