pentest-report

Generate professional penetration test reports from structured assessment data.

21|1|Updated Apr 12, 2026
One-click install
npx skills add https://github.com/woohyun212/security-skill --skill pentest-report-woohyun212
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-report
Source: https://github.com/woohyun212/security-skill/tree/main/pentest-report
Command: npx skills add https://github.com/woohyun212/security-skill --skill pentest-report-woohyun212

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Converts scattered penetration testing findings into a cohesive, client-ready report with a standardized structure and quality controls.

Core Features & Use Cases

  • Executive Summary: Generates a concise, business-friendly overview.
  • CVSS Scoring: Standardizes vulnerability severity using CVSS v3.1.
  • Attack Narrative: Documents exploitation chain and impact in narrative form.
  • Remediation Roadmap: Provides prioritized, actionable mitigations.
  • Quality Assurance: Includes consistency checks and appendices structure.

Quick Start

Compile your assessment data into the prescribed structure and execute the template workflow to generate the final pentest report.

Frequently Asked Questions about pentest-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a penetration test report with CVSS-scored findings and an executive summary?

Structure a penetration test report by automating the organization of scattered assessment data into a cohesive document. This workflow guides the generation of executive summaries, CVSS v3.1-scored findings, attack narratives, and remediation roadmaps.

What is the best way to document an attack narrative and remediation roadmap for security engagements?

Documenting an attack narrative and remediation roadmap involves converting raw exploitation chain data into a structured, client-ready format. The process standardizes vulnerability severity and provides prioritized, actionable mitigations for security engagements.

How do I generate a client-ready pentest report from scattered vulnerability findings?

Generate a client-ready pentest report by compiling your structured assessment data into a prescribed template workflow. This enforces quality assurance consistency checks and standardizes the formatting of vulnerabilities and appendices.

Does this reporting methodology standardize vulnerability severity using CVSS v3.1?

Yes, this reporting methodology standardizes vulnerability severity using CVSS v3.1 scoring. It applies quality assurance controls to ensure consistency across the documented findings and the final remediation roadmap.

Can I automate the production of professional pentest reports without manual formatting?

Yes, you can automate the production of professional pentest reports by executing a template workflow on structured assessment data. This eliminates manual formatting by guiding data organization, consistency checks, and appendices structure generation.

What are the limitations of using templates to automate pentest report generation?

The limitation of automating pentest report generation is the strict prerequisite of compiling scattered findings into a prescribed structured data format. Without properly structured input data, the template workflow cannot generate a cohesive, client-ready document.