blue-report

Generate redacted incident reports from findings, IOC ledgers, and timelines.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill blue-report
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: blue-report
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/blue-report
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill blue-report

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the complexity and risk of manual incident reporting by providing a structured, policy-compliant framework to draft defensive and incident reports while ensuring sensitive data is redacted.

Core Features & Use Cases

  • Audience-Specific Variants: Automatically generates tailored reports for executive leadership, technical engineering teams, legal/compliance, and post-incident reviews.
  • Safety-First Redaction: Includes built-in scanning to identify and remove PII, credentials, and sensitive infrastructure details before finalization.
  • Use Case: After a security incident, use this skill to synthesize raw findings, IOCs, and timelines into a professional technical report for the IR team and a high-level executive summary for the CISO.

Quick Start

Use the blue-report skill to draft a technical incident report based on the findings and evidence currently loaded in the active engagement session.

Frequently Asked Questions about blue-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate incident reports from raw findings and IOC ledgers?

To generate incident reports from raw findings and IOC ledgers, use a skill that synthesizes existing incident timelines and evidence into structured, audience-specific technical deep-dives or executive summaries.

How do I redact PII and credentials before finalizing an incident report?

To redact PII and credentials before finalizing an incident report, use a safety-first reporting tool that scans for sensitive infrastructure details and enforces strict data handling policies during the rendering process.

Can I create audience-specific variants for executive summaries and regulatory notifications?

Yes, you can create audience-specific variants for executive summaries and regulatory notifications by automatically tailoring the initial incident findings into distinct reports for executive leadership, technical engineering, and legal compliance teams.

What is the best way to structure a post-incident review for the IR team?

The best way to structure a post-incident review for the IR team is to synthesize raw defensive findings, IOCs, and incident timelines into a professional technical deep-dive that details the incident response sequence.

Do I need pre-compiled findings to draft a security compliance report?

Yes, you need pre-compiled findings and evidence loaded in an active engagement session, because this reporting framework synthesizes existing incident timelines and IOC ledgers rather than generating new forensic discoveries.

Why should I use automated redaction for incident response reporting?

You should use automated redaction for incident response reporting to reduce the risk of manual error, enforcing strict data handling policies by scanning and removing PII, credentials, and sensitive infrastructure details before finalization.