
Whitehub Tools
- Updated June 23, 2026
- mihaimacarie98/whitehub-report
whitehub-tools is a Claude Code marketplace that ships the whitehub-report skill so developers can write WhiteHub vulnerability reports aligned to CyStack form fields and taxonomies.
About
whitehub-tools packages the whitehub-report Claude Code plugin for CyStack's WhiteHub bug bounty platform. Use it when you have a valid finding and need a report that matches WhiteHub's fixed form and taxonomy instead of generic HackerOne-style writeups.
- Exact WhiteHub submit form field schema
- Bugcrowd VRT P1–P5 severity model
- Constrained CWE and OWASP dropdown mapping
- Template plus pre-submit checklist
Whitehub Tools by the numbers
- Data as of Jul 7, 2026 (Skillselion catalog sync)
/plugin marketplace add mihaimacarie98/whitehub-reportAdd your badge
Show developers this marketplace is listed on Skillselion. Paste this into your README.
| Last updated | June 23, 2026 |
|---|---|
| Repository | mihaimacarie98/whitehub-report ↗ |
How do you format a bug bounty report so every WhiteHub dropdown and VRT severity field is correct on first submit?
Draft WhiteHub (CyStack) bug bounty reports that map 1:1 to platform form fields, VRT severity, and dropdown taxonomies.
Who is it for?
Security researchers submitting to whitehub.net who need VRT, WSTG, OWASP, and CWE selections encoded in the skill.
Skip if: Researchers reporting only to HackerOne, Bugcrowd, or Intigriti without WhiteHub's constrained schema.
What you get
You get a submission-ready report, quick-map selections, and a checklist matching WhiteHub platform rules.
Plugins in this marketplace
1 plugin - install individually after you add the marketplace.
Recommended Marketplaces
FAQ
Does WhiteHub use CVSS for severity?
No; the skill uses Bugcrowd VRT P1–P5 as WhiteHub's severity model.
How do I install via marketplace?
Run marketplace add mihaimacarie98/whitehub-report then install whitehub-report@Whitehub Tools.
Where must PoC media be hosted?
Platform rules require PoC media hosted on WhiteHub only, as encoded in the skill guidance.