Bugbounty Triage

Strict bug bounty triager that reviews web2 vulnerability reports like a human who's read 50 reports today. Replays the PoC end-to-end (not just reads it), challenges scope, impact, and fix-worthiness before rendering a verdict. Built for HackerOne, YesWeHack, Bugcrowd, Intigriti, and self-hosted programs. Outputs a triage-<vuln>.md file with a captured replay log, weaknesses panel, verdict, and (for valid findings) an acceptance/duplicate-risk read with a SUBMIT/HOLD/REVISE call. Use this skill when the user says "triage this", "review this report", "is this valid", "should I submit this", "validate this finding", or wants a second opinion on a vulnerability report before submission. ALSO use proactively, without being asked, whenever a bug bounty report draft has just been written or completed in this session — run the gates against the draft before the user submits it.

gobelinor 1cbf501 2 files · 33.8 KB Updated

File contents

gobelinor/bugbounty-triage/tree/main/skills/bugbounty-triage commit 1cbf50191c

Frequently asked questions

npx skillmds@latest add gobelinor/bugbounty-triage