redteam-report-template

Generate standardized red team reports with 6-section findings and DOCX export.

1.1k|191|Updated Jun 24, 2026
One-click install
npx skills add https://github.com/uphiago/recon-skills --skill redteam-report-template-uphiago
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-report-template
Source: https://github.com/uphiago/recon-skills/tree/main/redteam/redteam-report-template
Command: npx skills add https://github.com/uphiago/recon-skills --skill redteam-report-template-uphiago

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates the hassle of creating inconsistent, non-standard red team reports that fail to meet enterprise client expectations, replacing ad-hoc bug bounty style writeups with professional, stakeholder-aligned deliverables for authorized external engagements.

Core Features & Use Cases

  • Standardized 6-section per-finding structure: Ensures every vulnerability is documented with Subject, Observations, Description, Impact, Recommendation, and PoC sections for clear communication to both technical and non-technical stakeholders.
  • DOCX/PDF export with embedded evidence: Automates conversion of markdown reports to formatted DOCX files with embedded screenshots, matching enterprise client deliverable requirements.
  • Client-specific severity calibration: Translates technical vulnerability severity into business impact terms relevant to the client's industry, regulatory requirements, and risk posture.
  • Use Case: For a 1-week external red team engagement for a mid-size healthcare client, package 14 validated findings with 16 screenshots into a compliant deliverable in ~6 hours post-engagement close.

Quick Start

Use the redteam-report-template skill to convert your validated red team findings into a client-ready markdown report following the standard 6-section per-finding structure, then generate a formatted DOCX with embedded screenshots for enterprise client delivery.

Frequently Asked Questions about redteam-report-template

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I format red team engagement findings for enterprise client deliverables?

Red team engagement findings are formatted into client-ready deliverables using a standardized 6-section per-finding structure: Subject, Observations, Description, Impact, Recommendation, and PoC. This structure ensures clarity for both technical and non-technical enterprise stakeholders.

Can I export markdown pentest reports to DOCX with embedded screenshots?

Yes, you can export markdown pentest reports to formatted DOCX files with embedded screenshots. The skill automates this conversion to match enterprise client deliverable requirements, producing ready-to-distribute documents with visual evidence.

What is the best way to calibrate vulnerability severity for client business impact?

The best way to calibrate vulnerability severity for client business impact is to translate technical severity into terms relevant to the client's specific industry, regulatory requirements, and risk posture. This ensures the red team report aligns with enterprise stakeholder expectations.

How do I document mid-engagement events during an external red team assessment?

You document mid-engagement events during an external red team assessment by logging them within the standardized report structure. This ensures all activities and findings are captured chronologically and validated before final client delivery.

Does this red team reporting template support signed statements of work?

Yes, this red team reporting template is designed for external red team engagements with signed statements of work. It packages validated findings into compliant deliverables suitable for CISO and IT security team review.

What sections are required for each vulnerability finding in a professional pentest report?

Each vulnerability finding in a professional pentest report requires six sections: Subject, Observations, Description, Impact, Recommendation, and PoC. This standardized structure replaces ad-hoc bug bounty writeups with client-aligned documentation.