{"repo":"v-yun/vuln-report-skill","free":true,"listed":false,"github":"https://github.com/v-yun/vuln-report-skill","clone":"git clone https://github.com/v-yun/vuln-report-skill.git","description":"Claude Code skill: turn confirmed vulnerabilities into submission-ready DOCX reports | 漏洞报告成稿 skill（SRC/0day 提交稿、分层验证门、Step 式 PoC、截图铁律）","language":null,"stars":38,"topics":["bug-bounty","claude-code","claude-skill","docx","security-reporting","src","vulnerability-disclosure"],"license":"MIT","category":"security-tools","readme_excerpt":"report — Submission-Ready Vulnerability Reports (Claude Code Skill) English 中文 --- 工作流程 / Workflow 效果预览 / Demo 演示对象为虚构靶标 demo-shop.example ，仅展示生成报告的版式与结构；第 3 张为公共靶场（AltoroJ / demo.testfire.net）实拍，演示真实浏览器渲染页的嵌入效果。 Demo uses a fictional target to showcase the layout of generated reports; page 3 is a real browser capture from a public practice target, showing how rendered pages are embedded. 报告首页（章节骨架） PoC 步骤页（Step + 请求块 + JSON 截图） PoC 步骤页（真实浏览器渲染截图） --- --- --- --- English A Claude Code skill that turns confirmed vulnerabilities into submission-ready DOCX reports for SRC (Security Response Center) and 0day platforms. It doesn't find vulnerabilities — it makes sure the report is good enough to survive review. What it enforces - Layered verification gates : hard gates (reproducible PoC / impact driven to the final harm / server-side confirmation / falsification tests) + per-type criteria (data leak, IDOR, RCE, SSRF, injection — each has its own minimum bar) + 0day acceptance gates (latest-version check / case count / submission discipline). No gate, no report — this filters out \"signal ≠ vulnerability\" garbage at the source. - Dual readability standard : a product manager can reproduce it step by step; a security engineer finds it technically solid. Both or rework. - Fixed DOCX layout : template.docx ships all styles (Heading 2 sections, uniform black, linear plain document), generated section by section with python-docx. - Step-style PoC spec : every step = one-line title + cont","default_branch":null,"files":null,"tree":[],"storefront":"/r/v-yun","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/v-yun/vuln-report-skill/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}