finding

Document security findings with severity, evidence, impact, and remediation.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill finding-jassics
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: finding
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/security-reporting/skills/finding
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill finding-jassics

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill provides a standardized approach to document security findings, ensuring clarity and actionable information for reporting or ticketing.

Core Features & Use Cases

  • Consistent Format: Standardizes the structure of security findings for consistency.
  • Actionable Information: Includes all necessary details for immediate action by engineers and verification by reviewers.
  • Use Case: After identifying a security vulnerability, use this Skill to create a detailed finding that includes severity, evidence, impact, and remediation steps.

Quick Start

Use the finding skill to document a security finding with the ID '001', titled 'SQL Injection in User Login', severity 'High', and affected assets 'All User Accounts'.

Frequently Asked Questions about finding

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I document a security vulnerability in a consistent format for reporting?

To document a security vulnerability, you need a structured format that includes severity, affected assets, evidence, impact, reproduction steps, and remediation. This approach ensures clarity and provides actionable information for ticketing or engineering reports.

What is the best way to structure a security finding for engineering teams?

The best way to structure a security finding is to standardize the report with severity levels, affected assets, evidence, impact analysis, and reproduction steps. This ensures engineers receive actionable details and reviewers can verify the remediation effectively.

Do I need prior security knowledge to document a vulnerability finding?

Yes, documenting a vulnerability finding requires knowledge of security vulnerability identification and remediation strategies. This prerequisite knowledge is necessary to accurately assess severity, impact, and define appropriate remediation steps for the affected assets.

Can I use a standardized finding format for both ticketing and security reporting?

Yes, you can use a standardized finding format for both ticketing and security reporting. By including severity, evidence, impact, and remediation in a consistent structure, the documentation provides immediate actionable information suitable for both engineering action and reviewer verification.

What specific details should be included when documenting a security finding?

When documenting a security finding, you should include the ID, title, severity, affected assets, evidence, impact, reproduction steps, and remediation. Capturing these specific details ensures the vulnerability report is comprehensive and actionable for resolving the issue.