sc-report

Generate a CVSS-aligned SECURITY-REPORT.md from verified findings and architecture.

56|5|Updated Apr 8, 2026
One-click install
npx skills add https://github.com/ersinkoc/security-check --skill sc-report
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sc-report
Source: https://github.com/ersinkoc/security-check/tree/main/skills/sc-report
Command: npx skills add https://github.com/ersinkoc/security-check --skill sc-report

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates the creation of a comprehensive security assessment report by consolidating verified findings, architecture context, and dependency data into a CVSS-style document.

Core Features & Use Cases

  • Aggregates verified findings, architecture overview, and dependency audit into a single executive report.
  • Maps findings to CVSS-like severities and produces a remediation roadmap for stakeholders.
  • Generates an executive summary, detailed findings, scan statistics, and a prioritized action plan for security reviews.

Quick Start

Ask the AI to generate the final SECURITY-REPORT.md from verified findings, architecture, and dependency data.

Frequently Asked Questions about sc-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a CVSS security report from verified findings and architecture data?

To generate a CVSS security report, consolidate verified findings, architecture context, and dependency data into a CVSS-aligned SECURITY-REPORT.md file containing an executive summary, risk scoring, and a remediation roadmap.

What should be included in a security assessment report for stakeholders?

A security assessment report for stakeholders should include an executive summary, scan statistics, detailed findings categorized by severity, and a prioritized remediation plan mapping vulnerabilities to CVSS risk scores.

Can I automate remediation roadmap generation from dependency audit results?

Yes, you can automate remediation roadmap generation by aggregating dependency audit data and verified findings into a consolidated document that produces a prioritized action plan mapping vulnerabilities to CVSS-like severities.

Does security report generation require inputs from a specific scanning pipeline?

Security report generation requires verified findings and architecture inputs, and applies specifically to projects scanned by the security-check sc-* pipeline to produce the final CVSS-aligned assessment document.

What is the best way to map security findings to CVSS severities in an automated report?

The best way to map security findings to CVSS severities is by consolidating verified vulnerabilities and architecture context into a structured report that categorizes findings into critical, high, medium, and low risk levels.

Why does my security report need architecture and dependency data alongside findings?

Your security report needs architecture and dependency data alongside findings to provide full contextual awareness for risk scoring, enabling the generation of an accurate executive summary and a realistic remediation roadmap.