What problem does it solve? Penetration test findings lose value when reports are poorly structured, over-scored, or unreadable by executives. This Skill provides a complete methodology for authoring professional pentest and red team deliverables that clients can act on. ## Core Features & Use Cases - Structured Report Templates: Standard report skeleton covering executive summary, scope, risk summary, technical findings, attack chains, and strategic recommendations, plus a per-finding template with reproduction steps, impact, remediation, and retest notes. - Severity Scoring Discipline: CVSS v3.1/v4.0 vector justification, OWASP risk rating, and guidance on business impact adjustments when CVSS understates real risk. - Evidence Hygiene: Timestamped evidence logs, credential redaction rules, PII hashing, EXIF stripping, and chain-of-custody practices for engagement artifacts. - Use Case: At the end of a web app engagement, draft each finding as a numbered Markdown file with a justified CVSS vector, build a risk heatmap and attack-chain narrative, then generate PDF and JSON deliverables via Pandoc for the client and their SIEM. ## Quick Start Use the offensive-reporting skill to turn my engagement notes into a full penetration test report with an executive summary, scored findings, and a retest plan.