report-generate

Generate structured penetration testing reports with CVSS risk ratings and remediation guidance.

1.6k|234|Updated Dec 7, 2019
One-click install
npx skills add https://github.com/wgpsec/AboutSecurity --skill report-generate-wgpsec
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-generate
Source: https://github.com/wgpsec/AboutSecurity/tree/main/skills/general/report-generate
Command: npx skills add https://github.com/wgpsec/AboutSecurity --skill report-generate-wgpsec

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill turns raw assessment data into a structured, professional penetration testing report that management and technical teams can understand and act on, eliminating inconsistent findings and unclear remediation guidance.

Core Features & Use Cases

  • Report Structure Template: Provides an executive summary, scope & methodology, findings overview, detailed vulnerability entries, risk ratings, remediation prioritization, and appendices.
  • Risk Rating & Mapping: Standardizes severity using CVSS guidance and pragmatic severity categories to align technical impact with business risk.
  • Vulnerability Details & Remediation: Emphasizes reproducible steps, business impact explanations for executives, and concrete remediation suggestions for engineers.
  • Use Case: Produce a client-ready report after a web application assessment or red team engagement summarizing counts by severity and recommended fixes.

Quick Start

Use the report-generate skill to draft a complete penetration test report by summarizing findings, mapping CVSS scores, and providing prioritized remediation recommendations.

Frequently Asked Questions about report-generate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a penetration testing report from raw assessment data?

To generate a penetration testing report, input your raw assessment data to automatically structure findings into reproducible vulnerability descriptions, CVSS mappings, and prioritized remediation recommendations for technical teams and executives.

What should be included in an executive summary for a vulnerability report?

An executive summary for a vulnerability report should include business impact explanations, counts of findings by severity, and prioritized remediation guidance to help management quickly understand risks and required actions.

How do you map CVSS scores to risk ratings in a vulnerability report?

Mapping CVSS scores to risk ratings in a vulnerability report standardizes severity by aligning technical impact with business risk using CVSS guidance and pragmatic severity categories for consistent remediation prioritization.

Can I use this approach for both web application assessments and red team evaluations?

Yes, this report generation approach is applicable to both formal penetration tests and red team evaluations, covering scope, methodology, detailed findings, and remediation guidance for client-ready delivery.

What is the best way to structure remediation recommendations for engineers and executives?

The best way to structure remediation recommendations is to provide concrete, actionable suggestions for engineers alongside business impact explanations for executives, ensuring both audiences can act on the findings effectively.

Why does my penetration test report lack consistent findings and clear remediation guidance?

Penetration test reports often lack consistency and clear guidance when raw data is unstructured; standardizing vulnerability entries with reproducible steps and CVSS-based risk ratings eliminates this problem for technical and executive readers.