pentest-report

GitHub

用于将授权渗透测试的发现转化为清晰、可执行的专业报告。生成包含高管摘要、范围与方法论、按严重性排序的详细发现(含复现步骤与修复建议)及风险优先级计划,确保技术团队与管理层均能采取行动。

skills/pentest-report/SKILL.md mohitagw15856/pm-claude-skills

Trigger Scenarios

撰写渗透测试报告 安全评估结果文档化 授权红队行动总结

Install

npx skills add mohitagw15856/pm-claude-skills --skill pentest-report -g -y
More Options

Use without installing

npx skills use mohitagw15856/pm-claude-skills@pentest-report

指定 Agent (Claude Code)

npx skills add mohitagw15856/pm-claude-skills --skill pentest-report -a claude-code -g -y

安装 repo 全部 skill

npx skills add mohitagw15856/pm-claude-skills --all -g -y

预览 repo 内 skill

npx skills add mohitagw15856/pm-claude-skills --list

SKILL.md

Frontmatter
{
    "name": "pentest-report",
    "description": "Write a clear penetration-test report from findings of an authorized engagement. Use when documenting a pentest, security assessment, or authorized red-team engagement — turning findings into a report clients act on. Produces an executive summary, scope & methodology, findings with severity\/evidence\/reproduction\/remediation, and a risk-ranked remediation plan. For authorized testing only."
}

Penetration Test Report Skill

A pentest is only as valuable as the report — findings that aren't clearly explained, evidenced, and prioritized don't get fixed. This skill turns the findings of an authorized engagement into a report that both executives and engineers can act on: risk up top, reproducible technical detail below, remediation throughout.

For authorized security testing only (signed scope / rules of engagement). This documents results; it is not a guide to attacking systems you don't have written permission to test.

Required Inputs

Ask for these only if they aren't already provided:

  • Engagement scope — what was in scope (targets, environments), the authorization/rules of engagement, and the testing window.
  • Methodology — approach (black/grey/white-box), standards followed (e.g. OWASP, PTES), tools.
  • Findings — each issue found: what it is, affected asset, how it was exploited, evidence, and impact.
  • Audience — client's technical team, leadership, or both.

Output Format

Penetration Test Report: [client / engagement]

1. Executive summary — for leadership: the overall risk posture, the count of findings by severity, the 2–3 most important takeaways, and the headline recommendation. No jargon.

2. Scope & authorization — what was tested, what wasn't, the authorization basis and testing window. (Establishes this was authorized and bounds the results.)

3. Methodology — approach, standards, phases, and tools — enough for the client to understand coverage and limits.

4. Findings — one entry per issue, ordered by severity:

[FINDING TITLE] — Severity: 🔴 Critical / 🟠 High / 🟡 Medium / 🔵 Low (CVSS if used)

  • Affected: asset/endpoint/component
  • Description: what the weakness is
  • Reproduction: the steps to reproduce (responsibly detailed — enough to verify and fix)
  • Evidence: request/response, screenshot ref, or output (sensitive data redacted)
  • Impact: what an attacker gains; business consequence
  • Remediation: the specific fix, and any interim mitigation

5. Risk-ranked remediation plan — a table of all findings with severity, effort, and priority order, so the client knows what to fix first.

# Finding Severity Fix effort Priority

6. Positive observations & retest — controls that held up, and the offer/plan to retest fixes.

Quality Checks

  • The executive summary conveys overall risk and top actions without jargon
  • Scope, authorization, and methodology are stated (results are bounded and clearly authorized)
  • Each finding has severity, affected asset, reproduction, evidence, impact, and remediation
  • Findings are ordered by severity and rolled into a risk-ranked remediation plan
  • Sensitive data in evidence is redacted; positive findings and a retest path are included

Anti-Patterns

  • Do not omit the authorization/scope — an unbounded, unauthorized-looking report is unusable and unsafe
  • Do not give a severity without impact and remediation — clients fix what they understand and can prioritize
  • Do not write findings only engineers can read (or only execs) — serve both audiences in their sections
  • Do not leave evidence unredacted — protect the very data you're helping secure
  • Do not produce this for testing that wasn't authorized in writing

Based On

Penetration-testing reporting standards (PTES, OWASP Testing Guide): exec + technical layers, evidenced reproducible findings, risk-ranked remediation.

Version History

  • a38bc30 Current 2026-07-05 11:40

Same Skill Collection

exports/openclaw/360-feedback-template/SKILL.md
exports/openclaw/401k-plan-decoder/SKILL.md
exports/openclaw/ab-test-planner/SKILL.md
exports/openclaw/ab-test-readout/SKILL.md
exports/openclaw/accessibility-audit/SKILL.md
exports/openclaw/account-plan/SKILL.md
exports/openclaw/acquirer-red-team/SKILL.md
exports/openclaw/ad-copy/SKILL.md
exports/openclaw/aeo-optimizer/SKILL.md
exports/openclaw/agenda-or-cancel/SKILL.md
exports/openclaw/agent-design-review/SKILL.md
exports/openclaw/agent-observability-spec/SKILL.md
exports/openclaw/agent-spec/SKILL.md
exports/openclaw/ai-ethics-review/SKILL.md
exports/openclaw/ai-eval-plan/SKILL.md
exports/openclaw/ai-feature-prd/SKILL.md
exports/openclaw/ai-product-canvas/SKILL.md
exports/openclaw/air-quality/SKILL.md
exports/openclaw/altitude-shifter/SKILL.md
exports/openclaw/ambiguity-resolver/SKILL.md
exports/openclaw/analyst-relations-brief/SKILL.md
exports/openclaw/announcement-card/SKILL.md
exports/openclaw/api-docs-writer/SKILL.md
exports/openclaw/api-test-plan/SKILL.md
exports/openclaw/api-versioning-strategy/SKILL.md
exports/openclaw/apology-letter/SKILL.md
exports/openclaw/architecture-decision-record/SKILL.md
exports/openclaw/architecture-diagram/SKILL.md
exports/openclaw/archive-strategy/SKILL.md
exports/openclaw/assumption-bounty/SKILL.md
exports/openclaw/assumption-mapper/SKILL.md
exports/openclaw/async-update-format/SKILL.md
exports/openclaw/auto-repair-estimate-decoder/SKILL.md
exports/openclaw/autopilot-charter/SKILL.md
exports/openclaw/benefits-decoder/SKILL.md
exports/openclaw/bid-tender-review/SKILL.md
exports/openclaw/board-deck-narrative/SKILL.md
exports/openclaw/board-minutes/SKILL.md
exports/openclaw/board-pre-read/SKILL.md
exports/openclaw/bom-cost-review/SKILL.md
exports/openclaw/bookkeeping-categorization/SKILL.md
exports/openclaw/boolean-search-builder/SKILL.md
exports/openclaw/brag-doc/SKILL.md
exports/openclaw/brainstorming/SKILL.md
exports/openclaw/brief-builder/SKILL.md
exports/openclaw/briefing-note/SKILL.md
exports/openclaw/budget-builder/SKILL.md
exports/openclaw/budget-variance-analysis/SKILL.md
exports/openclaw/bug-diagnosis/SKILL.md
exports/openclaw/bug-report/SKILL.md

Metadata

Files
0
Version
471c606
Hash
62326b1b
Indexed
2026-07-05 11:40

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-07-29 14:16
浙ICP备14020137号-1 $방문자$