Skip to main content

hunt-report-writing

Bug bounty report writing — structure, evidence, severity, reproduction steps for hackerone-style reports. Use when writing vulnerability reports.

跳到安装

来源信息

仓库
Kur1sulab/blackbox
最近来源活动
2026年8月12日 15:05
检测到的 SKILL.md 语言
英语
星标
3
分支
1

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
hunt-report-writing
description
Bug bounty report writing — structure, evidence, severity, reproduction steps for hackerone-style reports. Use when writing vulnerability reports.
# Report Writing ## Title Formula `[Vulnerability] in [Component] Enables [Impact]` Under 15 words. Title Case. Impact-forward. No URLs. | Bad | Good | |---|---| | XSS in search | Stored XSS in Comment Renderer Executes JavaScript in Admin Context | | IDOR found | IDOR in User API Exposes PII of All Platform Users | | SQL injection | Blind SQL Injection in Search Filter Enables Full Database Extraction | ## Structure 1. **Summary** (2-3 sentences): What's broken, what attacker can do, who's affected. 2. **Steps to Reproduce**: Numbered. ONE action per step. Exact URL, method, headers, body. 3. **Impact**: What attacker walks away with. How many users. Business impact. 4. **PoC**: Self-contained file. Screenshots at each step. Video if multi-step. 5. **CVSS 4.0**: Full vector string with justification per metric. 6. **Remediation**: 1-2 sentences. Developer-actionable. Specific fix. ## Style Rules - Human tone, technical but triager-accessible - Lead with impact, not process - No padding ("I discovered...", "During my testing...") - Every sentence adds information - Never submit without PoC + evidence ## Common Mistakes - Theoretical bugs ("could allow...") - Screenshots of Burp instead of clear steps - CVSS overclaiming - Same bug class on multiple endpoints as one report (should be separate) - Missing evidence attachment
在 GitHub 查看