What problem does it solve?
This Skill turns a confirmed vulnerability into a client-deliverable finding that is precise, defensible, and ready for reporting. It prevents vague write-ups, inflated severity claims, and incomplete evidence from weakening the final report.
Core Features & Use Cases
- Client-ready finding drafting: Produces a polished finding with title, severity band, CVSS v3.1 vector, affected asset, reproduction steps, impact, remediation, and evidence references.
- Severity and chain reasoning: Validates whether a finding should be Low, Medium, High, or Critical, and can write separate chain findings when multiple low-severity issues combine into a higher-impact path.
- Defensible remediation guidance: Recommends specific, code-level fixes and explains why superficial mitigations are insufficient.
- Use case: A tester confirms admin-context stored XSS and needs a report entry that a customer engineer can replay, verify, and act on without back-and-forth.
Quick Start
Ask this Skill to write up a confirmed vulnerability into a client-deliverable finding with severity, CVSS, reproduction, impact, remediation, and evidence.