What problem does it solve?
Penetration testers and red team operators often produce technically strong findings that get lost in poorly structured reports, leading to misunderstood risk, unactionable remediation, and wasted engagement value. This Skill provides a complete methodology for authoring professional security assessment deliverables that executives can read and developers can act on.
Core Features & Use Cases
- Structured Report Authoring: Standard report skeleton covering executive summary, engagement overview, risk summary heatmap, technical findings, attack chain narratives, strategic recommendations, and appendices.
- Severity Scoring Discipline: CVSS v3.1/v4.0 vector justification, OWASP risk rating, business impact adjustments, and a reference table of typical vectors for common vulnerability classes.
- Evidence Hygiene & Chain of Custody: Timestamped evidence logging, credential redaction, PII hashing, EXIF stripping, encrypted storage, and retest/closeout tracking.
- Use Case: At the end of a web application penetration test, use this Skill to convert raw findings into a client-ready report with an executive summary written for non-technical readers, per-finding reproduction steps, and a JSON export for the client's DefectDojo instance.
Quick Start
Ask Claude to draft a penetration test finding for a critical SQL injection vulnerability including CVSS 3.1 scoring, reproduction steps, impact, and remediation.