writing-security-reports

Document security findings into formal reports with CVSS scoring and remediation guidance.

6|1|Updated Mar 1, 2026
One-click install
npx skills add https://github.com/narlyseorg/superhackers --skill writing-security-reports
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: writing-security-reports
Source: https://github.com/narlyseorg/superhackers/tree/main/skills/writing-security-reports
Command: npx skills add https://github.com/narlyseorg/superhackers --skill writing-security-reports

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security findings often remain scattered and hard to understand. This skill provides a standardized workflow to document, organize, and communicate vulnerabilities, risk, and remediation in clear, auditable security reports.

Core Features & Use Cases

  • Standardized finding documentation using templates (Finding Template, CVSS Reference, Report Template).
  • CVSS scoring and justification integrated into reports.
  • Executive summaries and remediation roadmaps tailored for management and engineers.
  • Evidence assembly (requests/responses, screenshots, code snippets) aligned to final deliverables.

Quick Start

Draft the final report by documenting each confirmed finding using the Finding Template and CVSS references, then assemble the executive summary and remediation roadmap.

Frequently Asked Questions about writing-security-reports

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a pentest report for both engineers and management?

A pentest report is structured by documenting confirmed findings with evidence and CVSS scores, then assembling an executive summary and remediation roadmap to deliver management-friendly security reports.

What is the best way to document security vulnerabilities with consistent metadata?

Documenting security vulnerabilities requires a standardized workflow using finding templates to ensure repeatable, auditable deliverables with strict verification and consistent metadata fields across all reports.

How do I include CVSS scoring and remediation guidance in a vulnerability assessment report?

CVSS scoring and remediation guidance are integrated into vulnerability assessment reports by referencing CVSS templates during finding documentation and aligning evidence collection with final deliverables.

What do I need to assemble professional security reports from scattered findings?

To assemble professional security reports from scattered findings, you need to apply finding templates, CVSS references, and report templates to document discovery, evidence, and remediation consistently.

Does this approach work for security code reviews and vulnerability assessments?

Yes, this standardized reporting workflow applies to security code reviews, vulnerability assessments, and pentest engagements, ensuring all security findings are organized into formal, auditable deliverables.

When do I need a standardized template for security reporting?

You need a standardized template for security reporting when findings remain scattered and hard to understand, ensuring clear communication of vulnerabilities, risk, and remediation in formal reports.