bug-bounty-reportinglisted
Install: claude install-skill Lu1sDV/skillsmd
# Bug Bounty Reporting
## Paramount Points
Verbatim; keep internal:
> 1. **Concise** - Triagers need simple language, no mince words. Straight to the point reports. Every word create cognitive burden
> 2. **Triagers are dumb and lazy** - They need ELI5 steps and easy to understand reports; reproduction must be done for the fastest and easiest to understand triaging possible.
> 3. **Do not talk like a Robot** - LLM written report patterns discourages triagers. Write reprots like a human would do.
## Status Rules
| Status | Required evidence |
|---|---|
| `draft` | Exact final PoC lacks full-live evidence |
| `full-live` | Exact final PoC produced uncut end-to-end evidence |
| `submission-ready` | Frozen full-live snapshot passed independent review |
## Workflow
0. Verify current terms: scope, eligibility, safe harbor, prohibited methods,
limits, disclosure. Record source/date; unconfirmed = `blocked`, failed =
`ineligible`.
1. Read [references/report-standard.md](references/report-standard.md).
2. Inventory version/config, roles, PoC, evidence, control, cleanup. Track
report, PoC, manifest, review as `pending`, `complete`, or `blocked`; never
invent.
3. Map claims to evidence; remove, narrow, or qualify unsupported claims.
4. Draft one linear repro with decisive outputs, pinned root cause, combined
impact-and-severity, and concrete fix.
5. Require central config, preflight, collision refusal, assertions, evidence
capture, secret-safe logs, and exact cl