redteam-report-template

Standardize red-team findings into a six-section DOCX/PDF report format.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill redteam-report-template-sseshachala
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-report-template
Source: https://github.com/sseshachala/Claude-BugHunter-archive/tree/main/skills/redteam-report-template
Command: npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill redteam-report-template-sseshachala

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Client-facing red-team deliverables require a consistent, audience-aware structure to communicate findings, risk, and remediation for external engagements using a standardized Subject / Observations / Description / Impact / Recommendation / PoC format.

Core Features & Use Cases

  • The template codifies the canonical 6-section finding format (Subject, Observations, Description, Impact, Recommendation, PoC) for enterprise engagements.
  • It supports packaging findings into DOCX/PDF and aligning with enterprise red-team conventions, including sample corpora and formatting guidelines.
  • It is designed for engagements that demand client-facing documentation accessible to both technical and non-technical stakeholders; it references an authorized engagement deliverable with documented real-world usage (14 findings packaged into a 52KB MD + 2.2MB DOCX with 16 embedded screenshots).

Quick Start

Use when the engagement is "external red team for an enterprise client" (not H1/Bugcrowd/Intigriti), when generating the final report, when the client has specified a custom report format, or when packaging findings into DOCX/PDF.

Frequently Asked Questions about redteam-report-template

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the standard structure for client-facing red-team report deliverables?

Standard red-team report deliverables structure findings into a canonical six-section format: Subject, Observations, Description, Impact, Recommendation, and Proof of Concept (PoC). This ensures audience-aware communication of risk and remediation for enterprise engagements.

How do I package red-team findings into a DOCX report for enterprise clients?

Package red-team findings into DOCX reports by applying the standardized Subject/Observations/Description/Impact/Recommendation/PoC format and embedding screenshots. This approach yields client-facing documentation accessible to both technical and non-technical stakeholders.

Does this red-team report template work for bug bounty submissions on HackerOne or Bugcrowd?

No, this red-team report template is explicitly designed for external enterprise red-team engagements. It is not intended for bug bounty platforms like HackerOne, Bugcrowd, or Intigriti, which typically require different submission formats.

What is the best way to format red-team PoC documentation for non-technical stakeholders?

The best way to format red-team PoC documentation for non-technical stakeholders is using a standardized six-section structure. It separates technical Proof of Concept details from clear Impact and Recommendation sections, ensuring enterprise clients understand the risks.

Can I include embedded screenshots in a standardized red-team engagement report?

Yes, you can include embedded screenshots in standardized red-team engagement reports. The template supports packaging findings into DOCX outputs, with documented real-world usage packaging 14 findings with 16 embedded screenshots into a 2.2MB document.

When should I use a custom report format instead of the standard red-team deliverable template?

Use a custom report format when the enterprise client has explicitly specified their own reporting requirements for the engagement. Otherwise, apply this canonical Subject/Observations/Description/Impact/Recommendation/PoC template to ensure consistent deliverables.