← ClaudeAtlas

bug-bounty-reportinglisted

Use when an agent drafts, revises, freezes, or independently verifies a bug bounty vulnerability report, executable PoC, evidence bundle, CVSS rationale, or cleanup proof for HackerOne, Bugcrowd, Intigriti, or a vendor-managed program. The skill maps material claims to exact final-run artifacts.
Lu1sDV/skillsmd · ★ 1 · Data & Documents · score 60
Install: claude install-skill Lu1sDV/skillsmd
# Bug Bounty Reporting ## Paramount Points Verbatim; keep internal: > 1. **Concise** - Triagers need simple language, no mince words. Straight to the point reports. Every word create cognitive burden > 2. **Triagers are dumb and lazy** - They need ELI5 steps and easy to understand reports; reproduction must be done for the fastest and easiest to understand triaging possible. > 3. **Do not talk like a Robot** - LLM written report patterns discourages triagers. Write reprots like a human would do. ## Status Rules | Status | Required evidence | |---|---| | `draft` | Exact final PoC lacks full-live evidence | | `full-live` | Exact final PoC produced uncut end-to-end evidence | | `submission-ready` | Frozen full-live snapshot passed independent review | ## Workflow 0. Verify current terms: scope, eligibility, safe harbor, prohibited methods, limits, disclosure. Record source/date; unconfirmed = `blocked`, failed = `ineligible`. 1. Read [references/report-standard.md](references/report-standard.md). 2. Inventory version/config, roles, PoC, evidence, control, cleanup. Track report, PoC, manifest, review as `pending`, `complete`, or `blocked`; never invent. 3. Map claims to evidence; remove, narrow, or qualify unsupported claims. 4. Draft one linear repro with decisive outputs, pinned root cause, combined impact-and-severity, and concrete fix. 5. Require central config, preflight, collision refusal, assertions, evidence capture, secret-safe logs, and exact cl