finding-writer

Convert unstructured pentest notes into formal audit findings.

30|6|Updated May 13, 2026
One-click install
npx skills add https://github.com/Rifteo/skills --skill finding-writer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: finding-writer
Source: https://github.com/Rifteo/skills/tree/main/finding-writer
Command: npx skills add https://github.com/Rifteo/skills --skill finding-writer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

The Finding Writer Skill addresses the challenge of converting unstructured pentest notes into structured audit findings that are ready for security reports.

Core Features & Use Cases

  • Convert Pentest Notes: Transform raw notes, logs, or observations into report-ready audit findings.
  • Use Case: When a pentester gathers notes during a security assessment, the Finding Writer can quickly structure these notes into a formal vulnerability report.

Quick Start

To create a finding for a SQL injection vulnerability, use the command: "generate finding for SQL injection from notes."

Frequently Asked Questions about finding-writer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I convert raw pentest notes into structured security vulnerability reports?

To convert raw pentest notes into structured security vulnerability reports, use a finding generation tool to transform unstructured observations, logs, and notes into formal, report-ready audit findings during or after a security assessment.

What is the best way to structure unstructured security assessment notes for an audit?

The best way to structure unstructured security assessment notes for an audit is to process raw observations through a finding generation mechanism, which formats them into actionable, report-ready vulnerability findings.

Can I generate a finding for a specific vulnerability like SQL injection from my notes?

Yes, you can generate a finding for a specific vulnerability like SQL injection from your notes by using a targeted command like "generate finding for SQL injection from notes" to structure the output.

Do I need structured logs to create report-ready audit findings?

No, you do not need structured logs to create report-ready audit findings. This process is designed to take unstructured pentest notes, raw logs, or direct observations and convert them into formal documentation.

When should I use an automated finding generator during a pentest?

You should use an automated finding generator during a pentest when you need to quickly structure gathered notes into formal vulnerability reports, enhancing documentation and communication of security issues as you work.