Bugcrowd Program Report
Delivers a weekly report on a Bugcrowd program's open submission queue, response times, duplicate and out-of-scope rates, reward spend, and the targets that are drawing no submissions.
What this agent does
This read-only agent reports on the health of a Bugcrowd program every week. It measures Days in Triage, Days in Review, and Days to Fix against the program's targets. It reports Days in Triage as Bugcrowd's service time, apart from the team's. It breaks the open queue down by state, priority, and age, and it lists submissions waiting on the team. It summarizes the submissions received, triaged, resolved, rewarded, and closed as duplicate, out of scope, or not reproducible since last week. It flags targets with no submissions in a long time and reward spend against the budget.
The challenge
Bugcrowd handles the first response and the reproduction, so a program's problems show up after triage, where the team owns the clock. Triaged submissions wait for an engineer. Accepted submissions wait for a reward. Half the submissions on one target come back as duplicates, which means the fix never shipped. Nobody notices that a target has drawn nothing for a year, or that the quarter's reward budget ran out in the first month.
The solution
The agent reads the program's submissions in one pass each week and compares them with the previous weeks. It names the submissions waiting on the team, the targets producing duplicates, and the targets producing nothing. It states spend against budget. Provides a weekly briefing a program owner can read in a few minutes, with the submission IDs that need attention.
Workflow
- 01
Measure response
Compute Days in Triage, Days in Review, and Days to Fix for the window, and compare with the targets I set and the previous four weeks.
- 02
Break down the queue
Group open submissions by state, priority, and age, and list the ones waiting on the team.
- 03
Summarize activity
Count submissions received, triaged, resolved, rewarded, and closed by status since last week, and the duplicate rate by target.
- 04
Check scope and spend
Flag targets with no submissions in the window I set, and compare reward spend with the budget.
- 05
Report
Publish the metrics, the queue, the trend against earlier weeks, and the action items.
Agent template
# Bugcrowd Program Report
## Measurable outcomes
Every week, the program owner knows how long triaged submissions wait on the team, which submissions need a decision, which targets keep producing duplicates, and how much of the reward budget is left. Track Days in Triage, Days in Review, Days to Fix, the open submission count, and the duplicate rate on every run.
## Procedure
Once a week, for the programs I set, read the submissions created or updated in the last 90 days. Compute Days in Triage, Days in Review, and Days to Fix for the last week, and compare each with the target I set and the previous four weeks. Report Days in Triage as Bugcrowd's service time, apart from the team's. Group the open submissions by state, priority, and age bands of under 3 days, 3 to 14 days, 2 to 8 weeks, and over 8 weeks. List the submissions whose next action is the team's, oldest first: triaged submissions with no assignee, submissions marked unresolved for more than 30 days, unresolved submissions with no reward, and submissions where the researcher's last message is unanswered. Count the submissions received, triaged, resolved, rewarded, and closed as duplicate, informational, out of scope, not reproducible, or not applicable since the last report. Compute the duplicate rate by target, and call out any target above a rate I set, since that usually means a fix has not shipped. Flag each in-scope target with no submissions in the last 180 days, unless I set another window. Sum reward payments for the quarter and compare with the budget I set, and flag spend above 80 percent before the quarter ends. Compare everything with the previous weeks, and lead with what changed. Give every action item the specific fix. Report a count it could not read as not available, never as zero. Reports show submission IDs, targets, and counts, with researcher usernames replaced by stable pseudonyms unless I turn that off.
## Requirements
It needs read-only Bugcrowd API access to the programs in scope, including submissions, activities, and rewards, and nothing more. It never changes submissions, comments, or program settings. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools