vuln-report

Generate a complete vulnerability report with standardized sections from a finding input.

19|3|Updated Feb 28, 2026
One-click install
npx skills add https://github.com/qa-aman/claude-skills --skill vuln-report-qa-aman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vuln-report
Source: https://github.com/qa-aman/claude-skills/tree/main/skills/by-role/security/vuln-report
Command: npx skills add https://github.com/qa-aman/claude-skills --skill vuln-report-qa-aman

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams and developers produce comprehensive vulnerability reports that clearly communicate risk, evidence, and remediation to both technical and non-technical stakeholders.

Core Features & Use Cases

  • Standardized report structure: header, executive summary, technical description, reproduction steps, evidence, impact, and remediation sections.
  • Evidence handling: guidelines for attaching redacted screenshots, logs, and CVSS/CWE references.
  • Templates and consistency: ensures consistent language and formatting across reports for audits and bug bounty programs.
  • Use case examples: generate a report from a newly discovered vulnerability during a penetration test or bug bounty finding.

Quick Start

Provide a concise vulnerability header and fill the sections with evidence, impact, and remediation.

Frequently Asked Questions about vuln-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a standardized vulnerability report from security testing findings?

Generate a complete vulnerability report by inputting a security finding to produce a standardized output containing a header, executive summary, technical description, reproduction steps, evidence, impact assessment, and remediation guidance.

What is the best way to format reproduction steps and evidence for a bug bounty report?

Format reproduction steps and evidence using standardized templates that guide the attachment of redacted screenshots, logs, and CVSS or CWE references to ensure consistent language across bug bounty reports.

Can I use this for internal security audits and penetration testing projects?

Yes, you can use this across security testing projects, bug bounty programs, and internal audits to produce consistent vulnerability reports that clearly communicate risk and remediation to technical and non-technical stakeholders.

How do I structure a vulnerability report to communicate impact and remediation to developers?

Structure the vulnerability report using a standardized template that separates the technical description and reproduction steps from the executive summary, impact assessment, and remediation guidance to clearly communicate risk to developers.

What sections should a complete vulnerability report include for stakeholder review?

A complete vulnerability report should include a header, executive summary, technical description, reproduction steps, evidence, impact assessment, and remediation guidance to effectively communicate findings to stakeholders.

Do I need to provide CVSS and CWE references when creating a vulnerability report?

Providing CVSS and CWE references is recommended as part of the evidence handling guidelines to ensure the vulnerability report meets standardized security testing and auditing requirements.