finding-draft

Draft structured security findings from vulnerability observations using the standard template.

63|8|Updated Feb 16, 2026
One-click install
npx skills add https://github.com/JoranHonig/grimoire --skill finding-draft
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: finding-draft
Source: https://github.com/JoranHonig/grimoire/tree/main/skills/finding-draft
Command: npx skills add https://github.com/JoranHonig/grimoire --skill finding-draft

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Drafting structured security findings from vulnerability observations to enable clear remediation planning and audit traceability.

Core Features & Use Cases

  • Standardized findings: Ensure consistency across reports with a repeatable frontmatter and section structure.
  • Guided workflow: From context gathering to final draft, including title construction, severity estimation, and recommendations.
  • Use Case: When a vulnerability is identified, generate a complete draft finding ready for review and PoC references.

Quick Start

Draft a structured finding for the observed vulnerability using the standard template.

Frequently Asked Questions about finding-draft

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I draft a structured security finding from a vulnerability observation?

Drafting a security finding requires structuring vulnerability observations into a standard format with frontmatter, severity estimation, and remediation recommendations. A guided workflow gathers context to produce a complete finding draft ready for review and audit traceability.

What is the standard format for writing security vulnerability reports?

Standard security vulnerability reports use a structured format enforcing frontmatter schema, severity scale conventions, and dedicated sections. This structure ensures consistency across reports, enables clear remediation planning, and provides audit traceability for identified risks.

Can I use this drafting workflow to review or deduplicate existing security findings?

No, the drafting workflow cannot review or deduplicate existing security findings. It specifically applies to authoring new findings based on vulnerability observations, guiding the end-to-end process from initial context gathering through title construction to the final draft.

What is the best way to ensure consistency across security findings?

Ensuring consistency across security findings requires applying a repeatable frontmatter schema and section structure during report generation. Standardizing title construction and severity estimation through a guided workflow maintains uniform quality for remediation planning.

How do I estimate severity when authoring a new vulnerability finding?

Estimating severity when authoring a vulnerability finding involves applying the defined severity scale and conventions from the standard format. The guided workflow integrates severity estimation alongside context gathering and recommendation generation to produce an accurate risk assessment.