Report bugs to Bugcrowd with severity strategy

bugcrowd-reportingskillsetup L11,791
elementalsouls/Claude-BugHunter
What it does

Map vulnerability findings to Bugcrowd VRT categories and override severity

Best for

Bug bounty submissions when VRT defaults misalign with actual impact severity.

Inputs
  • · vulnerability class
  • · affected version range
  • · impact data category
Outputs
  • · VRT taxonomy node
  • · manual severity override with justification
  • · OOS rebuttal templates
Preconditions

Vulnerability mapped to generic class; VRT dropdown needed

Failure modes

Over-claiming severity loses triager trust; under-claiming leaves valid findings as P4

Trust signals
  • · CVE-to-VRT mapping table
  • · Historical Bugcrowd triage patterns cited
  • · OOS-clause rebuttal templates from real closures