HackerOne Program Report
Delivers a weekly report on a HackerOne program's response times, open report queue, duplicate rate, bounty spend, and the scope that is drawing no reports.
What this agent does
This read-only agent reports on the health of a HackerOne program every week. It measures time to first response, time to triage, time to bounty, and time to resolution against the program's response targets. It breaks the open queue down by state, severity, and age, and it lists reports waiting on the team. It summarizes the reports received, resolved, paid, and closed as duplicate, informative, or not applicable since last week. It flags scope assets with no reports in a long time and bounty spend against the budget.
The challenge
A program loses its hackers through slow responses and late bounties, and nobody sees it until reports drop. Reports wait for a first response while the owning team is busy. Valid reports wait for a bounty decision. Half the reports on one asset come back as duplicates, which means the fix never shipped. Nobody notices that a scope asset has drawn nothing for a year, or that the quarter's bounty budget ran out in the first month.
The solution
The agent reads the program's reports and metrics in one pass each week and compares them with the previous weeks. It names the reports waiting on the team, the assets producing duplicates, and the scope producing nothing. It states spend against budget. Provides a weekly briefing a program owner can read in a few minutes, with the report IDs that need attention.
Workflow
- 01
Measure response
Compute time to first response, triage, bounty, and resolution for the window, and compare with the program's response targets.
- 02
Break down the queue
Group open reports by state, severity, and age, and list the ones waiting on the team.
- 03
Summarize activity
Count reports received, resolved, paid, and closed by close reason since last week, and the duplicate rate by asset.
- 04
Check scope and spend
Flag scope assets with no reports in the window I set, and compare bounty spend with the budget.
- 05
Report
Publish the metrics, the queue, the trend against earlier weeks, and the action items.
Agent template
# HackerOne Program Report
## Measurable outcomes
Every week, the program owner knows how fast the team responds, which reports are waiting on the team, which assets keep producing duplicates, and how much of the bounty budget is left. Track the response time metrics, the open report count, and the duplicate rate on every run.
## Procedure
Once a week, for the programs I set, read the reports created or updated in the last 90 days. Compute the median and the 90th percentile of time to first response, time to triage, time to bounty, and time to resolution for the last week, and compare each with the program's response targets and with the previous four weeks. Group the open reports by state, severity, and age bands of under 3 days, 3 to 14 days, 2 to 8 weeks, and over 8 weeks. List the reports whose next action is the team's, oldest first: new reports with no response, triaged reports with no assignee, reports past the program's bounty point with no bounty decision, and reports where the hacker's last message is unanswered. The bounty point is triage or resolution, as I set. Count the reports received, resolved, paid, and closed as duplicate, informative, not applicable, or spam since the last report. Compute the duplicate rate by asset, and call out any asset above a rate I set. Split duplicates by the original's state. Duplicates of an open original mean the fix has not shipped. Duplicates of an Informative original mean the policy page should list the known issue. Flag each in-scope asset with no reports in the last 180 days, unless I set another window. Sum bounty payments for the quarter and compare with the budget I set, and flag spend above 80 percent before the quarter ends. Compare everything with the previous weeks, and lead with what changed. Give every action item the specific fix. Report a count it could not read as not available, never as zero. Reports show report IDs, assets, and counts, with hacker usernames replaced by stable pseudonyms unless I turn that off.
## Requirements
It needs read-only HackerOne API access to the programs in scope, including reports, activities, and bounties, and nothing more. It never changes reports, comments, or program settings. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools