finding-workflow

Automates capture, documentation, and reporting of offensive security findings with CVSE severity scoring and notifications.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/noname300989/Security-Claw --skill finding-workflow
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: finding-workflow
Source: https://github.com/noname300989/Security-Claw/tree/main/skills/finding-workflow
Command: npx skills add https://github.com/noname300989/Security-Claw --skill finding-workflow

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill streamlines the process of documenting security findings in real-time, reducing the manual overhead of capturing evidence, assessing severity, and drafting reports.

Core Features & Use Cases

  • Instant Logging: Immediately record a finding the moment it's discovered.
  • Evidence Capture: Guides users through capturing HTTP requests, responses, and screenshots.
  • Automated Severity Assessment: Interactively helps determine the CVSS score based on impact.
  • Report Drafting: Assists in writing detailed vulnerability reports.
  • Multi-Channel Notifications: Alerts all configured communication channels about new findings.
  • Use Case: While performing a penetration test, you discover an SQL injection. You can instantly tell the agent, and it will guide you to capture the request, response, and screenshot, then help you score it and draft the report, all while notifying your team.

Quick Start

Tell the agent "Found! SQL injection in /api/search?q= on example.com — unauthenticated, returns DB version".

Frequently Asked Questions about finding-workflow

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security findings documentation during penetration testing?

Automating security findings documentation involves capturing HTTP requests, responses, and screenshots in real-time. This Skill guides you through instantly logging vulnerabilities, interactively assessing CVSS severity scores, and drafting detailed reports while alerting your team.

What is the best way to capture evidence for vulnerability reports in real-time?

Capturing evidence for vulnerability reports requires recording HTTP requests, responses, and screenshots immediately upon discovery. This Skill facilitates real-time logging and guides you through evidence collection to ensure all proof is documented accurately during offensive security engagements.

Can I automatically calculate CVSS scores for security findings as I discover them?

Automatically calculating CVSS scores for security findings is supported through interactive severity assessment. The Skill helps determine the CVSS score based on impact, allowing you to assess vulnerability severity immediately while performing red teaming or penetration tests.

How do I notify my team instantly when a new vulnerability is found?

Notifying your team when a vulnerability is found is handled through multi-channel notifications. Upon capturing a new security finding, the Skill immediately alerts all configured communication channels, ensuring team members receive instant updates during offensive security engagements.

Does this Skill support drafting vulnerability reports directly from captured penetration testing evidence?

Drafting vulnerability reports directly from captured evidence is fully supported. The Skill assists in writing detailed vulnerability reports by utilizing the real-time logs, HTTP requests, responses, and screenshots captured instantly during your penetration testing or red teaming engagements.

What limitations exist when logging security findings during red teaming engagements?

Logging security findings during red teaming relies on interactive guidance for evidence capture, CVSS scoring, and report drafting. Limitations include dependency on user input for capturing accurate HTTP requests and screenshots, and the need for pre-configured channels for multi-channel notifications.