Report Writing

SkillSecurity

Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Report Writing skill

What this skill tells your AI

The instructions your AI receives, as published by h-mmer/pentest-agents in skills/report-writing/SKILL.md and read by ahel’s review.

Title Formula

[Vulnerability] in [Component] Enables [Impact]

Under 15 words. Title Case. Impact-forward. No URLs.

BadGood
XSS in searchStored XSS in Comment Renderer Executes JavaScript in Admin Context
IDOR foundIDOR in User API Exposes PII of All Platform Users
SQL injectionBlind SQL Injection in Search Filter Enables Full Database Extraction

Structure

  1. Summary (2-3 sentences): What's broken, what attacker can do, who's affected.
  2. Steps to Reproduce: Numbered. ONE action per step. Exact URL, method, headers, body.
  3. Impact: What attacker walks away with. How many users. Business impact.
  4. PoC: Self-contained file. Screenshots at each step. Video if multi-step.
  5. CVSS 4.0: Full vector string with justification per metric.
  6. Remediation: 1-2 sentences. Developer-actionable. Specific fix.

Style Rules

  • Human tone, technical but triager-accessible
  • Lead with impact, not process
  • No padding ("I discovered...", "During my testing...")
  • Every sentence adds information
  • Never submit without PoC + evidence

Common Mistakes

  • Theoretical bugs ("could allow...")
  • Screenshots of Burp instead of clear steps
  • CVSS overclaiming
  • Same bug class on multiple endpoints as one report (should be separate)
  • Missing evidence attachment

Signals

GitHub stars
908
Forks
169
Last commit
Jun 2026
Advanced
Catalog kind
skill
Gateway key
report-writing-h-mmer
Source
github.com/h-mmer/pentest-agents